The five questions I ask before any VAPT engagement
Vulnerability testing that skips scoping is theatre. The questions that separate a useful engagement from a paid PDF.
Vulnerability assessments and penetration tests are only as useful as the scoping conversation that precedes them. When clients ask why one VAPT engagement produces action and another produces a shelved PDF, the answer is almost always the questions we asked in week one.
The five questions
- What decision will this report inform? Regulatory sign-off, board risk appetite, insurance renewal, and pre-acquisition due diligence each demand different depth and framing.
- What is in scope, in writing? Domains, IP ranges, applications, third-party integrations, and — critically — what is explicitly out.
- Who owns remediation? A finding without an owner is a finding that will still be open at the next audit.
- What are the blast-radius rules? When we discover exploitable access, how far do we pivot before pausing and escalating?
- How will we hand this over? A workshop with the remediation team beats a 200-page PDF every time.
Answer these before the first packet is sent, and the engagement produces decisions instead of anxiety. *** End Patch *** Add File: src/content/journal/eprocurement-people-use.mdx
title: "Building eProcurement that people actually use" date: "2026-05-12" tag: "Public Sector" blurb: "Lessons from delivering procurement systems in the public sector — from workflow design to change management."
Most public-sector eProcurement projects fail the same way: the software works, the users don't adopt it, and eighteen months later the department is running parallel spreadsheets. The technology is rarely the problem.
What actually moves adoption
- Design the workflow with the buyers, not the auditors. Compliance is a constraint, not a starting point. Start with the person raising the requisition and design outward.
- Reduce the number of screens before you add features. Every extra screen is an adoption tax.
- Ship reporting on day one. Managers who cannot see spend in real time will not champion the system.
- Train in cohorts, not seminars. Small groups, live data, and a named facilitator inside each department.
Procurement is a people problem wearing a software costume. Treat it that way and the platform becomes invisible in the best sense. *** End Patch *** Add File: src/content/journal/floppy-disk-to-autonomy.mdx
title: "From floppy disk to autonomy — a working draft" date: "2026-04-03" tag: "Book" blurb: "An early excerpt from Ultimate Journey. On origins, obsession, and the systems that changed a country."
This is an early excerpt from Ultimate Journey, releasing 1 September 2026.
I remember the weight of the floppy disk more than its contents. Three and a half inches of beige plastic, a metal shutter that clicked when you loaded it, and — somewhere on the magnetic surface — the first program I ever wrote that another human being used.
The country I grew up in was learning computers at the same time I was. There were no reference architectures for what a national telecommunications operator should look like in the early 2000s, no playbooks for building a road authority's information systems from scratch. We improvised, and the improvisation became infrastructure.
This book is about that improvisation — the systems, the people, and the long arc from a single floppy disk to the platforms that now run parts of a nation.