I did not invent CISSP As An Art. CISSP As An Art invented me.
How a set of handwritten notebooks, a failed exam and a habit of doodling turned into a different way of learning cybersecurity.
During COVID, I decided to study for the CISSP.
I had worked in cybersecurity for years, but studying cybersecurity was different.
I opened the books.
I read.
I stopped.
I started again.
And I struggled to get beyond Domain 1.
The material wasn’t the problem. The way I was trying to learn it was.
I’ve always been drawn to creativity. Writing, filmmaking, photography and storytelling have been part of my life outside cybersecurity. During the pandemic, I had also started experimenting with digital drawing.
Whenever I became tired of studying CISSP, I found myself doodling.
Then one day I had a simple thought:
Why am I separating the two? What if I could study cybersecurity by drawing it?
So I started taking handwritten CISSP notes differently.
Concepts became sketches.
Relationships became diagrams.
Technical ideas became analogies.
Sometimes a cybersecurity concept became a scene or a story.
For the first time, I wasn’t simply reading CISSP.
I could see it.
Then I failed.
I sat my first CISSP exam in October 2022 and failed.
It hurt.
But the result also showed me that I wasn’t starting again from zero. I had already developed proficiency across several domains.
So instead of abandoning the journey, I changed how I approached it.
I spent more time understanding why an answer was right or wrong. I continued writing by hand. I connected concepts with things I could picture and remember.
And I kept creating.
On my second attempt, I passed.
But something more important had happened along the way.
I had discovered how I learn.
I put my notebooks on the internet.
After passing CISSP, I could have closed the books and moved on.
Instead, I photographed and scanned my handwritten notes and shared them online.
I made them available for free.
I thought that was the end of the project.
It wasn’t.
People around the world downloaded the notes, according to the records I shared at the time. Some chose to pay for them, even though they could download them for $0.
That surprised me.
Something I had created simply to help myself learn was helping other people learn too.
So I kept experimenting. I posted cybersecurity sketches on LinkedIn. I used humour. I turned technical concepts into everyday situations.
Slowly, the drawings stopped being study notes.
They became a way of thinking.
In 2024, I gave it a name.
CISSP As An Art. Or CaaART.
I described it publicly in September 2024 as my way of blending CISSP with digital art, creativity and visual storytelling.
But CaaART has continued to evolve.
Today, I don’t think visual learning means simply adding a picture to a cybersecurity definition.
For me, it means starting somewhere else.
Four steps, in that order.
Imagine
Start with the problem, not the definition. What is actually going wrong, and for whom?
Decode
Work through it as a story or a visual. A scene you can picture is a scene you can remember.
Apply
Bring it back to cybersecurity. Map the story to the control, the concept or the domain.
Reflect
Ask where we encounter it in the real world, so the idea holds up beyond the exam.
Cybersecurity As An Art
Today, CaaART is becoming something larger than the notebooks that started it.
I’m building Dave On Cyber as a growing learning library covering CISSP, SaaS security, AI governance, application security and technical deep dives, drawing from professional experience, research, stories and visual thinking.
I’m still learning.
I’m still drawing.
I’m still experimenting with how difficult cybersecurity ideas can be made easier to see, understand, remember and apply.
Maybe that’s why one sentence from my original story still describes this journey better than anything else:
I started CISSP to complete it. CISSP ended up starting competing me.
Welcome to Dave On Cyber.
Learn visually. Think differently.
