Stop reusing passwords
Password managers and passkeys
One breached site becomes ten breached accounts when passwords repeat. Use a password manager to generate a different password everywhere, and switch to passkeys wherever a site offers them.
> cybersecurity for all
Control. Adapt. Protect.
Security guidance written for people, not just for enterprise teams. Plain language, current threats, and steps you can actually take today.
> about
I am Mark Blair, a cybersecurity professional with more than fifteen years spent on the defending side. My day to day has covered vulnerability management, incident response, threat detection, risk assessment, governance and compliance, and running security awareness programs for people who never asked to think about security.
CTRL-ALT-Security is my personal project. It exists because most security advice is either written for large security teams or watered down until it stops being useful. This site sits in the middle: real threats, current sources, and specific things you can do.
The attacks that hit families, small businesses and volunteers are usually the same techniques that hit large organizations, minus the budget to respond. Phishing, reused passwords, unpatched devices and account takeover do not care how big you are.
Sharing what works, in language people actually use, is the highest leverage security work I know of.
> news
Headlines pulled from public feeds run by government agencies, research teams and independent reporters. Each one links straight to the source.
> awareness
Short, practical habits that block most of what actually happens to normal people.
Password managers and passkeys
One breached site becomes ten breached accounts when passwords repeat. Use a password manager to generate a different password everywhere, and switch to passkeys wherever a site offers them.
App codes and security keys beat SMS
Multifactor authentication stops most account takeover attempts outright. An authenticator app or a hardware security key is far stronger than text message codes, which can be intercepted or redirected.
Recognizing phishing and smishing
Urgency is the tell. A message that pressures you to act right now, pay immediately, or confirm your account is worth a pause. Go to the site or app directly rather than tapping the link you were sent.
Patching is the quiet win
Most successful attacks use vulnerabilities that were already fixed. Turn on automatic updates for your phone, computer, browser and router, and replace hardware once it stops receiving security updates.
Three copies, two formats, one offsite
Ransomware and dead hard drives both end the same way without backups. Keep at least one copy that is not permanently connected to the machine it protects, and test a restore once in a while.
Protecting relatives and kids
Grandparent scams, fake job offers, romance scams and gift card requests all rely on isolation and embarrassment. Agree in advance that anyone can call you to sanity check a strange request, no judgment.
> projects
Side projects that came out of real security problems.
Substack
Regular writing on current threats, breach lessons and practical defenses, aimed at readers who are not full time security professionals.
PHP, MySQL, no frameworks
A growing set of personal web applications built and hosted from scratch, with a shared security pattern across all of them: passwords hashed with bcrypt, signed cookies, CSRF protection, rate limiting, and sensitive files stored outside the web root.
Static and dynamic analysis, one dashboard
A vulnerability scanning setup for my own applications, combining static analysis, secret scanning, dependency checks, TLS testing and dynamic scanning, with results collected in one dashboard.
> training
Where to start, and where to go next. Everything listed here is free or has a free tier.
Government resources for individuals and small organizations
Advisories, guidance and no cost tools published by the United States Cybersecurity and Infrastructure Security Agency.
National Cybersecurity Alliance
Awareness campaign materials you can hand to family, a classroom or a small team without editing anything.
Learn by doing
Guided browser based labs that teach attacking and defending concepts. Good next step once the basics feel comfortable.
Structure for organizations
The reference most security programs are measured against. Useful even for a small business trying to decide what to do first.
Have I Been Pwned
Find out which breaches included your email address, then change those passwords and enable multifactor on the accounts involved.
Password is "homecourse"
> connect
Same handle everywhere: @ctrlaltsecurity
> contact
Questions, speaking requests, or a topic you want covered. Messages come straight to me.