Blog
Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
Security
Personal data: map the flows before adding controls
Why protecting personal data starts not with encryption or policies, but with understanding what data the company actually collects and why.
Read
Security
Patching industrial control systems is hard, but no update regime is worse
How to bring operations engineers and security teams to a shared testing and maintenance scheme - without illusions and without paralysis.
Read
Security
Logs as a data source, not garbage: what you can see before you have a SIEM
How to treat logs as operational material - for diagnostics, audit, and analytics - even without a specialised platform.
Read
Security
After Stuxnet: ICS segmentation is no longer optional
How to ground industrial control system security in real assets, contractors, maintenance windows, and a minimum isolation baseline.
Read