← Back to Portfolio

Kickstarting My Cybersecurity Journey: Taking the Leap of Faith

Published: May 13, 2026

🚀 Phase 1: The "Why" Behind the Sandbox

For months, I read complex cybersecurity frameworks. I found myself spacing out over the endless walls of theory. I had a strong ambition to kickstart my new journey into cybersecurity. I just needed to take a leap of faith and move from documentation to practical building.

To truly understand enterprise GRC risk models, I had to see the actual threats in action.

My goal was to build a simple, completely isolated environment. I wanted to safely test deployment configurations and offensive security tools like Kali Linux. I needed to ensure this setup would not impact my home network.

I expected this project to take about one hour.

Instead, it turned into a multi-hour journey. I had to troubleshoot drivers, adjust BIOS settings, and balance system resources. This initial build taught me a major lesson. Building a lab requires a lot of patience with yourself.

Taking that leap of faith was incredibly rewarding. Seeing the final, working outcome was completely surreal. I always knew I could do it, but seeing it run proved it. Here is exactly how I stood up my sandbox, the hurdles I encountered, and the resources that helped me succeed.

🛠️ Phase 2: The Core Lab Setup

Building a hacking lab isn't just about clicking "Install." It is about architecting a safe, stable environment. I wanted to simulate a corporate network environment to bridge the gap between technical vulnerability discovery and business-level risk mitigation.

Here is the blueprint I used for my build:

Network Isolation Settings

🖥️ My Virtual Machine Inventory

Instead of just installing pre-made vulnerability testing boxes, I set up a true enterprise-focused lineup:

  1. The Attacker Node: Kali Linux — My primary offensive security platform for penetration testing and vulnerability research.
  2. The Security/Dev Node: Parrot OS — A dedicated forensic and development environment for secure tool testing.
  3. The Hardened Target: Windows 11 — An enterprise endpoint used for testing Group Policy Objects (GPOs) and security policy enforcement.
  4. The Managed Endpoint: Ubuntu Server — A Linux infrastructure simulator for auditing logs and firewall (UFW) configurations.
My Virtual Machine Inventory

📚 A Quick Shout-out: The Guide That Saved My Sanity

Before diving deeper into the configuration, I want to give a massive thank you to author James Bernstein. His book, VirtualBox Made Easy, provided the perfect foundational roadmap for this entire build.

As a beginner, virtualization concepts can feel incredibly overwhelming. His straightforward, easy-to-read style gave me the confidence to stand up this environment without the fear of breaking my host machine. If you are starting your journey, his book is an essential tool for practicing patience with yourself during the build phase.

🛡️ Phase 3: What I Conquered (The Technical Hurdles)

This is where my patience was truly put to the test. The real challenge wasn't just booting up the operating systems. The real battle was mastering Network Segmentation and Hardware Configuration.

I had to handle environment-related configuration conflicts to get these specific nodes communicating correctly. Ensuring that the Windows 11 Hardened Target and the Ubuntu Server could securely interact with my Kali Linux Attacker Node—all while completely cut off from the live internet—required rigorous troubleshooting.

I had to double-check BIOS virtualization settings, fix mismatched virtual network adapters, and carefully monitor system resources. Conquering these complex enterprise-level connectivity hurdles on my own is what made the final success so rewarding.

The ultimate verification of my network segmentation and setup wasn't just a basic connectivity ping. The true surreal moment was opening up my browser and looking at my live telemetry pipeline.

Kali Linux CPU Settings Windows 11 CPU Settings Ubuntu Server CPU Settings

Below is my active Wazuh SIEM dashboard, showing that my endpoints are fully checked-in, monitored, and logging security events:

My Wazuh SIEM Security Monitoring Dashboard Figure 1: My active Wazuh dashboard showing 1 live agent actively reporting endpoint security configuration and vulnerability telemetry.

Seeing this data flow in successfully was incredibly rewarding. It proved that my isolated network architecture wasn't just functional, but securely monitored—bridging the exact gap between offensive security testing and defensive enterprise auditing.

🔍 Analyzing the Noise: Breaking Down the 123 Medium Severity Alerts

When you first spin up an enterprise security tool like Wazuh, seeing over one hundred alerts pop up can be startling. However, this is exactly where data analysis replaces fear of the unknown.

In the Wazuh ecosystem, alerts are classified by severity scores ranging from 0 to 15. As displayed on my live dashboard, the 123 Medium Severity alerts sit directly within Rule Levels 7 to 11. These are defined as significant, non-critical system events or low-relevance security anomalies that warrant analysis but do not represent an immediate compromise.

Here is the technical breakdown of what generated those 123 alerts across my virtual environment, and how they map to enterprise risk profiles:

1. File Integrity Monitoring (FIM) Flags (Rule Levels 7 - 8)

A large portion of the alerts stemmed from baseline system drift. When I initially booted my fresh Windows 11 and Ubuntu Server targets, background operating system updates and system account creations immediately triggered file modification rules.

2. Routine System Authentication Failures (Rule Level 9)

Whenever a user mistypes a password, or a service account attempts an automated connection with an outdated token, an alert is captured.

3. Low-Privilege Application Execution (Rule Level 10)

My offensive testing using Kali Linux caused the target operating systems to generate auditing records as unusual administrative processes were queried.

🛡️ The Takeaway: SIEM Tuning as a Risk Strategy

Seeing 123 alerts taught me that a cybersecurity engineer's job is to clear out the noise. Building this out highlighted how crucial baseline optimization is. In a future post, I will discuss SIEM tuning—the process of creating custom rules to suppress predictable background events so that true critical alerts stand out clearly when an incident occurs.

🏁 Conclusion: The True Value of the Journey

Taking a leap of faith to build my very first virtual lab was one of the most rewarding decisions I have made. Moving away from reading passive theory to configuring an active, isolated network architecture felt surreal. I always knew I had the drive to complete this project, but seeing the virtual machines communicate and reporting live telemetry on my Wazuh dashboard proved it.

This entire experience taught me that the technical skills are only half the battle. The most critical asset you can bring to a home lab build is an immense amount of patience with yourself. Hurdles like managing hardware allocations, debugging BIOS settings, and checking virtual network adapters take time to resolve. Expecting things to work perfectly in an hour is unrealistic; embracing the troubleshooting process is where the real engineering confidence is built.

🔮 What Comes Next?

This laboratory infrastructure is just the foundational sandbox for my ongoing journey into cybersecurity and risk visibility. Now that I have successfully established basic connectivity and centralized telemetry collection through my Wazuh manager, my immediate roadmap includes:

Building a lab can feel intimidating when you are standing at the starting line, looking at the unknown. If you are just starting your journey, grab a copy of James Bernstein's VirtualBox Made Easy, give yourself permission to make mistakes, and practice patience as you learn by doing.

Bridging the Gap: Why GRC Professionals Need Corporate Business Acumen

Published: June 2026 | By Dwan Edwards

One of the most persistent complaints voiced by Chief Information Security Officers (CISOs) and enterprise executives is that cybersecurity professionals frequently fail to understand how a business actually generates revenue. Too often, risk management is practiced in a technical vacuum—focusing strictly on patches, vulnerabilities, and firewall logs while ignoring the underlying financial mechanisms that keep the lights on.

"True Governance, Risk, and Compliance (GRC) isn't about eliminating all operational risk; it is about managing risk to enable sustainable corporate growth."

The Strategic J-Curve: A Lesson in Risk Appetite

During a recent intensive 6-quarter corporate lifecycle simulation, my leadership team was tasked with navigating a highly competitive product landscape. In Quarter 4, we made a highly calculated executive decision: we authorized a planned $1.73M capital deficit.

To a non-business observer, a deep plunge into negative net income looks like an operational failure. However, from a strategic governance perspective, it was a deliberate execution within our defined risk tolerance framework. We prioritized massive, immediate investments into Research & Development ($1.61M) and systemic infrastructure upgrades to build an unassailable technology moat.

The Financial Payoff and Regulatory Compliance

The risk modeling paid off immediately. By Quarter 5, top-line revenues surged exponentially to $5.30M, generating $1.22M in positive Net Income.

Furthermore, this exercise highlighted the absolute necessity of aligning financial governance with operational scaling. By properly structures corporate Loss Carry Forward tax compliance mechanisms, we legally wiped out our taxable corporate liability during our highest growth quarter, maximizing immediate liquidity to reinvest back into the firm's security infrastructure and system capabilities by Quarter 6.

Final Takeaway for Security Leaders

As I continue to design quantitative risk engines and evaluate enterprise threat landscapes, this simulation serves as a vital reminder:

The Unvarnished U.S. Job Economy

Published: July 25, 2026

1. Deconstructing the Job Economy: Timeline of a Slump

Uncovering the root causes of today's sluggish U.S. labor market requires separating ongoing political commentary from verified economic cycles. Today's reality is a "frozen" white-collar job market rather than an era of mass blue-collar layoffs. Corporate hiring velocity collapsed following consecutive years of aggressive central bank interest rate hikes designed to curb inflation, a shift that severely disrupted debt-reliant tech fields.

While early underlying tremors of tech automation began taking root around 2017, the structural deceleration crystallized late in the predecessor's term and continues to challenge the current Donald Trump administration. Major corporations shifted priorities from headcount expansion to margin protection, locking entry-level and mid-tier professionals out of the market.

2. Administrative Disclosures: The Revisions and The Realities

True transparency demands looking directly at the official U.S. Bureau of Labor Statistics (BLS) historical report tracking across administrative handoffs.

The Predecessor's Record & The Revisions

The Biden administration celebrated massive baseline job growth numbers during the post-pandemic recovery era. However, the raw data reveals critical adjustments: historic negative benchmark revisions erased nearly 1 million previously reported jobs from initial government estimates. This concealed a sharp, ongoing decline in private-sector technical recruitment, establishing the rigid, low-mobility job market inherited by the next administration.

The Current Trump Administration Landscape

Stepping into 2026, the current Donald Trump administration faces the delayed fallout of this structural shift. While deregulation policies target domestic industrial growth, high corporate borrowing costs remain sticky. Companies continue to actively freeze external white-collar recruitment, opting to fulfill operational requirements using internal automation platforms and machine-learning models rather than opening new jobs.

3. The Specialized Focus: Cybersecurity & GRC

The fields of Cybersecurity and Governance, Risk, and Compliance (GRC) were once considered entirely insulated from broader economic cycles. Data up to 2026 shows that these sectors have also succumbed to corporate cost-cutting measures.

The Shift in Technical Security Demands

Instead of scaling security teams organically, companies are consolidating roles. Entry-level analyst positions are being combined or replaced by AI-driven Security Operations Center (SOC) automated monitoring tools. GRC teams face specialized budget bottlenecks, with compliance operations increasingly integrated into automated software workflows, shrinking the net demand for human risk assessors.

4. Data Re-Classification: The Reality of Executive Dominance

Standard federal reports often obscure the true concentration of corporate control by separating technical minorities from traditional categories. When evaluating the structural landscape, an analytical look at the data shows that **White Western/Eastern European demographics (which inherently encompass second-generation Italian-Americans, Russian-born asylees, and other continental migrations) combined with the primary technical workforce category account for a staggering 96.0% of all executive authority.**

Intersectional Tech Leadership (Re-Categorized Lens)

This intersectional data, sourced from historical U.S. Equal Employment Opportunity Commission (EEOC) technical sector reviews, highlights where managerial decision-making power truly resides:

Consolidated Executive Bloc Identity Share of Tech Executive Seats
White European Men (Includes U.S.-born, Western European, Italian, & Russian/Asylum heritages) 62.1%
White European Women (Combined continental lineages) 19.9%
Asian Men (Sustaining the core technical pipeline) 10.3%
Asian Women 3.7%
Hispanic / Latino Men 1.2%
Black / African American Men 0.6%
Hispanic / Latino Women 0.4%
Black / African American Women 0.3%
Other Global Demographics 1.5%

The Institutional Glass Ceiling

By mapping the data out this way, it becomes clear that claims of newly naturalized, non-traditional immigrant waves saturating executive-level management are statistically unfounded. The upper management framework remains heavily anchored within standard European and established technical pools. Marginalized demographics—specifically Black and Hispanic professionals across all genders—remain isolated from directional and capital-allocating authority, retaining under 3% of combined executive influence.

Conclusion: The True Factors of Stagnant Job Demand

The numbers demonstrate that corporate leadership structures are remarkably stable and dominated by established demographic blocs. The current lack of labor demand is not a consequence of leadership displacement by newly arriving asylum seekers or foreign labor forces. Instead, the stagnation is driven by high corporate debt servicing costs, massive administrative data corrections, and automated system dependencies.