admin attack surface

The administrative attack surface

A few days after sending an application to the Dutch Ministry of Defence for a senior cyber and information security advisory role, I read an NRC article about publicly accessible details of Dutch military infrastructure. Not leaked documents. Not espionage. Not shadowy dead drops in rainy parking garages. Public websi…

May 6, 2026 · 5 min

Post-incident reviews that miss the point

This is not incompetence. It is the system behaving exactly as it did before, including in the room where the review takes place. Describing the incident instead of explaining it Most incident post-mortems or retrospectives reconstruct the sequence of events. What happened, in what order, and what could have been done …

April 7, 2026 · 3 min

Ghost hunting

Most organisations are aware of this. Very few act on it. The result is a detection posture that looks busy, looks measured, and quietly fails in the places that matter. This is where breaches tend to settle in and make themselves comfortable. A library of yesterday’s attacks Detection engineering is usually reactive. …

April 5, 2026 · 5 min

The future will surprise us. Be prepared.

When scenario planning practitioners and others speak of “looking forward”, they don’t mean prediction. Forecasting implies we know where we’re going, while scenario planning admits we do not. Looking forward is not clairvoyance, nor is it the worship of trend graphs. It is not about guessing which shiny technology or …

October 29, 2025 · 3 min

The relational firewall

A developer pushes a feature. Security flags a missing TLS configuration. Operations scrambles to patch the database. Alerts multiply while emails ping insistently and no one knows who owns what. Technical pipelines are fine. The human side stutters. Miscommunication, conflicting priorities, and unspoken assumptions sl…

October 21, 2025 · 4 min

Muscle memory for incident stress

Introduction A SOC alert does not knock politely. It arrives like a crowd of people shouting different instructions in a language only half understood. One alert maybe says “ransomware detected,” another could flag “unusual login,” and the logs you trust most are blank. Analysts glance at dashboards, shrug, and whisper…

October 21, 2025 · 4 min

The question now is: what can we do?

The internet is fundamentally broken. The question now is: what can we do? The answer is messy, expensive, and occasionally involves telling very powerful people that their business model is morally questionable. Accepting the obvious First, acknowledge the unpleasant truth: there is no quick fix. Security is not a fea…

October 1, 2025 · 3 min
A chaotic swarm of robotic spiders constructed from old IoT devices, their metallic bodies glinting dully, crawls over a fragile, intricate network of servers and cables. Sparks of electricity fly from their joints and the damaged infrastructure.

Why are we not making a defendable internet?

Once upon a time, the internet was described as an “information superhighway”. In truth, it more closely resembles the back alley behind a funfair: noisy, sticky underfoot, and populated by people selling things you probably do not want but will end up buying anyway. It is not defendable in any serious sense, and the e…

October 1, 2025 · 8 min

Defendable Internet?

David Clark remembers the moment the Internet’s Pandora’s box creaked open and said, “Hello, world.” It was 2 November 1988, and the Morris Worm was slithering its way through cyberspace like a python on speed. Designed with the innocence of a curious grad student and the destruction of a cyber sledgehammer, it crashed…

February 1, 2023 · 4 min