An in-progress record
Twenty years in tech.
Zero days in security.
I’m a creative technologist — twenty years of it. Video editing, camera work, visual effects and CGI, then mobile games, VR, AR, WebGL and mobile dev, and the last seven agency‑side at R/GA on Nike, Samsung and McDonald’s‑scale work. I am adding offensive security to that. Another string to the bow, not a career change: expanding, not quitting anything.
This is the public record of the expansion. Learning to break things, written up as it happens, including the parts where it doesn’t work.
The counter
Every piece here carries the same line: day 1, still zero. The first number is days since I started. The second half is a feeling, not a transaction — whether I can call myself a security professional, and I don’t get to fudge that just because it would be convenient.
It is a deliberately unflattering device. It goes up on its own, every day, whether or not I have done anything worth reading, and it only stops for one reason.
Breaks the zero
Knowing I have crossed the line — doing the work at a standard I would stand behind with no caveat attached. Nobody else can trip it for me, and I will know when it happens.
Does not break it
A certificate. A bug bounty. A CVE. A job offer. An invoice. A kind word from someone on the internet.
Receive before transmit.
Literally true in radio: listen, decode, understand, and only then key up. Not a vow of silence — it is about the band, the power and the proof. Where an allocation is open to anyone and the power is a fraction of what the toy itself puts out, I’ll transmit, and I’ll show you the spectrum afterwards so you can see exactly what went into the air. The amateur bands wait for the licence. And nothing here is demonstrated on anything I don’t own or have written permission to test, with observation never quietly upgraded into something active.
What gets written about
The Journey
The origin, the progress, the licensing, the reflection, and the counter itself.
Signals
RF and SDR. Receive, decode, understand — and transmit only where the band allows it, at power you can prove.
Systems & Software
Web, mobile, networks and cloud. Pentesting practice, CTFs, and the machines that get attacked.
Builds & Hardware
Teardowns, soldering, scopes, logic analysers, and tools built for a few pounds.
Physical
Locks, bypass, observation-led physical assessment, and social engineering.
Real Engagements
Client work and the reports that come out of it.
Empty until it is genuinely true.
Interludes
Climbing, F1, flight sim, side builds. Texture rather than filler.
Where this actually stands
True today
- A bench of kit — SDRs, a HackRF, a Flipper, a logic analyser, a scope.
- Real captures: a £5 RC car remote decoded off 27 MHz — and the car driven without it afterwards, waterfalls to prove both halves.
- A $6 BadUSB built and working, on my own hardware.
- A UK amateur radio licence in progress — before, not after, anything touches an amateur band.
- A music-and-technology BSc underneath all of it: audio, signals, and the maths that turns out to be most of the way to RF.
- Years of turning up to film at galleries and offices where nobody had told security we were coming — and talking or sneaking our way in anyway. Authorised, just not communicated.
- Twenty years of production craft: documentation, client delivery, and telling the story afterwards.
- Self-taught, deliberately — bench hours on my own kit rather than a certification track.
Not yet true
- Not yet the thing the counter is waiting on. Money isn’t the bar; I’ll know when I’ve crossed it.
- No steady client work. No practice to speak of yet.
- No security certifications.