Uses.
What I actually run
The tools I use often enough to have an opinion about, at work and at home. Included partly because the home lab is where I learned things no course covered.
Network and home lab
I have replaced my own firewall twice. pfSense first, then OPNsense, and now Unifi. Each move was for a real reason at the time and each one taught me something I would not have learned by reading about it. Running the thing yourself is how you find out what the documentation left out.
- Unifi for routing, switching and wireless, with its own controller and alerting. Ubiquiti gear is also what I ran across dealership sites, so the familiarity is not accidental.
- CrowdSec for detecting and blocking the traffic that turns up uninvited on anything exposed.
- Cloudflare Zero Trust in front of the services I host for myself, so nothing personal sits open on the public internet waiting to be found.
- UGREEN NAS for storage and backups.
- A Minecraft server I ran for ten years for a community of 100+ players. Keeping it up mattered to people, which made it my longest-running uptime responsibility anywhere, jobs included.
- Home Assistant automating most of the house: time-of-day events, lights that react to severe weather alerts, and rooms that notice whether anyone is actually in them.
- A 5G modem as a fallback path. Every site I have looked after needed an answer to the question of what happens when the line goes down, and the answer should not be discovered on the day.
Identity and endpoints
The tools I have reached for most, and the ones behind most of the case studies.
- Okta for single sign-on, groups and conditional access. The piece I have spent the most time inside.
- HiBob as the HR system of record, feeding the identity provider so that joining, leaving and returning are all triggered by HR rather than by a ticket.
- Google Workspace for mail, calendar and shared drives.
- YubiKey for hardware multi-factor, issued with the laptop, not after it. A code read out over the phone can be talked out of somebody. A key cannot.
- Miradore for device management across Windows, macOS, iOS and Android, and Kaseya for the Windows fleet before it.
- Snipe-IT for the asset and licence register, which is what makes an access review answerable rather than a guess.
- KnowBe4 Phish Alert Button, so anyone could report a suspicious email in one click.
Working
- Jira and Asana for tracking work, Salesforce where the work touched customers.
- Zapier for personal automation, the small connections not worth writing properly.
- MacBooks at Pathway to Hope, a deliberate choice for a small team with no dedicated support.
AI
I use large language models daily and I have built with them, which is a different thing from having opinions about them. The rule I hold to is that an assistant should never become a way around access control: if you could not open the document, the model should not read it to you. There is more on that in the case studies.
Where the data is regulated, the model runs locally rather than leaving the building.