Practical cybersecurity from Northern Ireland
About NI Cyber Guy

About Colin Manson

I'm Colin Manson, a cybersecurity practitioner, security leader and the person behind NI Cyber Guy.

I'm based in Northern Ireland and currently work as a Technical Security Manager, with a particular focus on Microsoft security, identity and access management, security operations and turning security strategy into controls that actually work.

That last part matters.

There is often a sizeable gap between what cybersecurity looks like on an architecture diagram and what happens when you try to deploy it across real users, legacy systems, competing priorities and overstretched IT teams.

I spend a lot of my working life in that gap.

And NI Cyber Guy is where I write about what I learn there.

I didn't take the traditional route into cybersecurity

My career didn't start behind a bank of SOC monitors.

Before cybersecurity, I worked in sport and coaching.

Moving from that world into IT meant starting again, learning the fundamentals and proving that many of the skills I'd developed elsewhere were transferable.

Communication. Problem solving. Staying calm when something goes wrong. Understanding how people learn. Breaking complicated ideas into manageable steps. Getting different personalities to work towards the same outcome.

Those skills turned out to be surprisingly useful in cybersecurity.

I eventually moved into Security Operations, then through security analyst, engineering and leadership roles.

Along the way I've worked across detection engineering, SIEM, endpoint security, identity, privileged access, DLP, Zero Trust, Microsoft security and security architecture.

That journey also shapes how I write about cyber careers.

I know what it feels like to look at a job description full of technologies you've never touched and wonder how you're ever supposed to get the experience required to get the job that would give you the experience.

I was that person.

I learned security from the operational end

Starting in Security Operations gave me one lesson that has stuck with me:

Buying security technology is much easier than building security capability.

You can own a SIEM and still have poor detection.

You can own Microsoft E5 and still have weak identity controls.

You can deploy a security product and discover six months later that nobody owns its alerts, nobody reviews its configuration and nobody knows what success looks like.

Technology matters.

But ownership, architecture, processes, people and operational discipline determine whether that technology actually reduces risk.

That principle runs through much of what you'll read on NI Cyber Guy.

What I work on today

My current work sits at the intersection of cybersecurity engineering, architecture and security management.

A lot of that involves Microsoft technology, including Entra ID, Microsoft Defender, Intune, Sentinel, Microsoft 365 security, Conditional Access and Privileged Identity Management.

But I'm deliberately Microsoft-first rather than Microsoft-only.

Security architecture should start with the problem you're trying to solve, the risk you're trying to reduce and the environment you actually have.

Not the logo on the product.

I spend a lot of time thinking about questions such as:

  • How do you modernise security in a hybrid environment without breaking everything?
  • How do you remove standing privilege without making administration impossible?
  • What should you deploy first when you already own Microsoft E5?
  • How do you move from collecting logs to actually detecting threats?
  • How do you introduce stronger authentication without creating a revolt at the service desk?
  • How do you make Zero Trust an engineering model rather than a collection of vendor slides?
  • How do small teams build security programmes that they can realistically operate?

Those are much more interesting questions to me than simply asking which product has the longest feature list.

Why I created NI Cyber Guy

There is no shortage of cybersecurity content on the internet.

There is, however, a shortage of content that tells you what happens after somebody says "just enable it".

That's what I want NI Cyber Guy to focus on.

I write about the practical side of cybersecurity: what controls do, why they matter, where implementations go wrong and how I'd approach the problem in a real environment.

Sometimes that means deep dives into Microsoft security and identity.

Sometimes it's explaining a basic cyber concept without requiring the reader to decode three paragraphs of acronyms first.

And sometimes it's talking about careers, certifications and the mistakes I've made along the way.

My aim is simple:

Make useful cybersecurity knowledge easier to find, understand and apply.

No fearmongering.

No pretending every problem can be fixed by buying another security platform.

And no passing off a vendor configuration guide as a security strategy.

Security has to work in the real world

One of the subjects I'm particularly interested in is the distance between security architecture and operational reality.

A security design can be technically perfect and still fail.

Maybe the organisation doesn't have the people to operate it.

Maybe the infrastructure is twenty years old.

Maybe another system has an undocumented dependency.

Maybe the help desk isn't ready for the support demand.

Maybe the control creates so much friction that people start looking for ways around it.

Good security architecture has to account for those things.

The objective isn't to design the most impressive security environment on paper.

It's to create controls that reduce risk, can be operated consistently and continue working after the person who designed them has moved on.

Coaching still influences how I approach security

My previous career in sports coaching probably influences my approach to cybersecurity more than I realised when I first entered the industry.

Good coaching isn't about standing at the side telling people everything they're doing wrong.

You establish the fundamentals, understand the problem, provide feedback, measure progress and improve over time.

Security is remarkably similar.

You don't transform an organisation by switching every control to block mode on Monday morning.

You establish visibility.

You understand the environment.

You prioritise the biggest risks.

You pilot changes.

You learn.

Then you improve.

It may not make for an exciting "digital transformation" slide, but it tends to produce systems people can actually live with.

Sharing what I learn

NI Cyber Guy has also given me an opportunity to contribute to the wider cybersecurity community.

I've spoken and participated in discussions around public-sector cybersecurity, AI, Zero Trust, security architecture and the operational challenges involved in modernising security.

But the blog remains the heart of what I'm trying to build.

I want it to become somewhere a security engineer can bookmark because an article helped solve a problem.

Somewhere a small business can understand what it should secure first.

Somewhere somebody trying to enter cybersecurity can get useful advice from someone who has actually made that transition.

And somewhere I can document the lessons I'm learning while continuing to develop as a security professional myself.

Practitioner first. Content creator second.

That's probably the simplest way to explain NI Cyber Guy.

I don't write about cybersecurity because content creation is my profession.

I write because cybersecurity is.

The articles here are shaped by problems I've encountered, technologies I've worked with, questions people have asked me and ideas I've wanted to test properly.

I'll occasionally get things wrong too.

Cybersecurity changes quickly, and I'd rather correct something than pretend to know everything.

Accuracy matters more than ego.

If a guide, article or opinion on this site helps you make one better security decision, saves you an hour of troubleshooting or helps you understand something that previously made no sense, then NI Cyber Guy has done its job.

Let's connect

If you're interested in Microsoft security, identity, Zero Trust, security operations, cybersecurity architecture or building a career in cyber, you'll find plenty of that here.

You can explore my latest articles, follow me on LinkedIn or get in touch if you'd like me to contribute to an event, podcast or cybersecurity discussion.

Security doesn't need more jargon. It needs more things that work.

NIBased
15+Core topics
100%Practical

I write NI Cyber Guy in a personal capacity. Opinions expressed here are my own and do not represent those of my employer.