Reading the procurement, not the press release

A policy speech says what an institution wants to be seen wanting. A procurement document records what it has agreed to pay for. The two are not the same, and the gap between them is usually the more interesting reading. A press release costs nothing to write and binds no one. A call for tender names a budget, a deadli…

June 6, 2026 · 9 min
A single weary civil servant at a cluttered government desk, buried under towering stacks of paper documents and redaction folders, frantically rubber-stamping and blacking out pages. In the background, an empty pristine filing system labelled 'intake' sits untouched and gathering dust.

Een transparantiewet die vindbaarheid eist

Er is een gewoonte in detection engineering die een organisatie tijd kost om af te leren. Een team kijkt naar de waarschuwingen, de dashboards en de dekkingsrapporten, en beschouwt die als de plek waar detectie gebeurt. Dat is niet zo. Het is de plek waar detectie zichtbaar wordt. Het werk dat bepaalt of er iets te zie…

June 6, 2026 · 7 min

The stability of dysfunction

The stability of dysfunction Many discussions of large systems quietly assume that a stable system is a healthy one, and an unstable system is a sick one. Complex systems tend to violate that intuition. They can remain operational for a very long time without becoming any healthier, and they possess several mechanisms …

June 5, 2026 · 11 min

What institutions do to successful ideas

Many critiques of Agile assume something went wrong. The story is usually told as a fall from grace: a practical response to software uncertainty that then disappeared beneath ceremonies, certifications, frameworks, and consultants. There is another way to read the same history. Perhaps Agile did not fail. Perhaps it s…

June 4, 2026 · 5 min
Quadrant mapping uncertainty against consequence, with adaptation favoured at high uncertainty and anticipation at high consequence

Agile, where it fits and where it doesn't

Most engineering disciplines accept that method follows from context. Nobody expects a bridge engineer, a documentary director, and a trauma surgeon to share a planning model, and nobody finds the difference remarkable. Software is one of the few fields where people go looking for a single methodology and then try to a…

June 4, 2026 · 5 min

How a rebellion became a bureaucracy

Few movements in software have been as successful as Agile. What began as a reaction against heavyweight process, exhaustive documentation, and centralised planning became the dominant way organisations talk about building software. And somewhere in that success it acquired certifications, prescribed ceremonies, maturi…

June 4, 2026 · 4 min
A figure at a small desk in a high-ceilinged reading room, reading with the quiet satisfaction of someone who has found exactly the book they wanted; through the tall windows, crowds of other figures drift past, half-dissolving into a cheerful drizzle, their attention already elsewhere. The reader is entirely unbothered.

Audience design

A friend asked whether the proof-of-concept I had sketched on a docs page was worth actually building. I said no, for the usual reasons, and also because the page in question had been written in the specific style of a document that does not want to be read. A four-layer architecture diagram without the diagram. Ingest…

May 14, 2026 · 5 min

DigiD and the rented engine room

The story is, on paper, narrow. Solvinity, the Dutch contractor that operates infrastructure underneath Logius and DigiD, looks set to be acquired by Kyndryl, an American spin-off of IBM’s managed-services arm. DigiD itself remains owned by the Dutch state via Logius, so technically the system is still Dutch. Political…

May 7, 2026 · 7 min
admin attack surface

The administrative attack surface

A few days after sending an application to the Dutch Ministry of Defence for a senior cyber and information security advisory role, I read an NRC article about publicly accessible details of Dutch military infrastructure. Not leaked documents. Not espionage. Not shadowy dead drops in rainy parking garages. Public websi…

May 6, 2026 · 5 min

How security failures learned to sound reasonable

The most useful phrases in a modern security programme are the ones that cannot be argued with. “The platform gives us coverage.”, “We have visibility.”, “The tool supports MFA.” Each one is calm, professional, and technically defensible. Each one can also be doing something quietly different from what the room hears. …

May 3, 2026 · 4 min