About

About The person behind the practice.

Practical experience, clear guidance, and knowledge to carry forward.

Hi, I'm David with DomainSecurity.

DomainSecurity is where I share my work, experience, and practical security examples. At Swell Forward, we help small businesses with websites, security, and responsible AI. Two doors, one practice.

My background spans security, infrastructure, technology, and design—in established organizations and small businesses. I explain decisions in plain language and share what I know, so you can understand the risks and feel confident about what comes next.

Below, we share practical skills, educational scenarios, and articles—not client project reports. For help applying the ideas to your business, explore our services.

Skills at a glance

Skills that connect decisions to delivery.

Broad range, used together — build it, secure it, keep it running, and explain it clearly.

Build

Ships working products end to end.

  • React front ends
  • APIs & backend functions
  • Data modeling
  • Third-party integrations

Secure

Finds real risk and puts fixes in order.

  • Domain & host review
  • Vulnerability triage
  • Hardening guidance
  • Incident write-ups

Operate

Keeps systems steady day to day.

  • Networks & firewalls
  • Identity & access
  • Monitoring & alerts
  • Backup & recovery

AI, responsibly

Uses AI with limits people can see.

  • Practical AI features
  • Prompt & review design
  • Access boundaries
  • Framework alignment

Work with people

Easy to work with, on any team.

  • Plain-language updates
  • Cross-functional delivery
  • Documentation & handoff
  • Stakeholder framing

The skills above support the work. Explore practical learning examples and plain-language articles below; use them to ask better questions, not as reports about your own systems.

16 example prompts for learning

The Security Prompt Library

Example prompts for learning how to ask clearer security and AI questions. Choose a topic, read the example, and adapt it before using it. Never paste private business or customer information into an AI tool.

Featured examples

Featured

Log Anomaly Triage

Turn raw log excerpts into a prioritized list of suspicious events with reasoning.

Click for full prompt
Featured

Incident Timeline Reconstruction

Convert scattered evidence into a clean chronological incident timeline with gaps flagged.

Click for full prompt
Featured

CVE Impact Assessment

Translate a raw CVE into "does this actually affect us, and how fast must we patch?"

Click for full prompt
Featured

AI Agent Security Review

Audit an AI agent design for prompt injection, tool abuse, and data exfiltration risks.

Click for full prompt

Log Anomaly Triage

Turn raw log excerpts into a prioritized list of suspicious events with reasoning.

Click for full prompt

Phishing Email Header Analysis

Dissect full email headers to verify sender authenticity and spot spoofing.

Click for full prompt

IOC Extraction & Enrichment Plan

Pull every indicator of compromise from a threat report into a structured, actionable table.

Click for full prompt

Incident Timeline Reconstruction

Convert scattered evidence into a clean chronological incident timeline with gaps flagged.

Click for full prompt

Containment Decision Matrix

Weigh containment options (isolate, block, monitor) against business impact under pressure.

Click for full prompt

Blameless Post-Mortem Draft

Generate a structured, blameless post-mortem document from incident notes.

Click for full prompt

CVE Impact Assessment

Translate a raw CVE into "does this actually affect us, and how fast must we patch?"

Click for full prompt

Scan Result Prioritizer

Cut a noisy vulnerability scan report down to the 10 findings that actually matter.

Click for full prompt

AI Agent Security Review

Audit an AI agent design for prompt injection, tool abuse, and data exfiltration risks.

Click for full prompt

System Prompt Hardening

Stress-test and rewrite a system prompt to resist jailbreaks and instruction override.

Click for full prompt

RAG Poisoning Threat Model

Map how attackers could poison your retrieval pipeline and what to filter.

Click for full prompt

Detection Rule Builder

Turn a plain-language attack behavior into SIEM detection logic with tuning notes.

Click for full prompt

Security Automation Spec

Design a SOAR-style automation for a repetitive security task, with failure handling.

Click for full prompt

Server Hardening Checklist

Generate a prioritized, OS-specific hardening checklist scoped to a server's actual role.

Click for full prompt

Firewall Ruleset Audit

Find shadowed, overly-permissive, and stale rules in a firewall ruleset export.

Click for full prompt

Security Headers Fix Plan

Convert a security-headers scan into copy-ready header configs with rollout order.

Click for full prompt

Operational scenarios and lessons

Educational examples of diagnosis, safer changes, and knowledge transfer. Filter by area or search.

Category:

127 skills found

Note: These educational scenarios summarize common operational patterns. Validate commands, versions, dependencies, and rollback steps in a non-production environment before changing live systems.