Volunteer Cybersecurity & Technology Consultant
Independent · Remote · June 2026 – Present
I help small businesses improve their security posture, working with clients who have real exposure and no security function to speak of. I've assessed and hardened WordPress environments for four clients so far, focusing on the automated attacks that make up the majority of hostile traffic against small public sites. In practice that means closing off contact form abuse and password spraying against administrator login endpoints — rate limiting, CAPTCHA, login throttling, and IP allowlisting — and then building the visibility to know whether it worked. Most clients had no logging at all, so I centralized server log collection and delivered each of them a tailored monitoring dashboard. The part that lasts longest is the training. I work with non-technical owners and staff on MFA enrollment, secure secrets sharing, and credential management, so a one-time remediation turns into a practice they keep up after I'm gone.