TODO: Your Name Security engineer writing about critical infrastructure, surveillance, and the people they fail.

What this site is

A security engineer's notebook on critical infrastructure, attribution, and digital rights — and what I'm using it for.

  • meta

I’ve spent years on the defending side of this: building and running infrastructure, reading advisories the morning they drop, arguing about whether a vendor’s attribution actually holds up. This is where I write that down in public.

Most reporting on critical infrastructure attacks has to take the technical claims on trust. I don’t, and that’s the whole reason for this site — a place to work through what an advisory says, what it carefully doesn’t say, and what a small utility with no security budget can realistically do about it.

Three kinds of things will end up here:

Advisory readings. When something lands in CISA’s Known Exploited Vulnerabilities catalog that touches water, power, health, or civil society, I go to the primary document and write up what it actually means for the people running the affected kit.

Explainers. Plain-language pieces on the machinery — what a PLC is, why some flaws can’t be patched, what “operating manually” costs a treatment plant in practice.

Method notes. How a particular piece of verification or attribution reasoning works, and where it’s weaker than it looks.

Longer reported work goes to outlets rather than here; when it does, it shows up on the clips page.

Corrections are welcome and get noted on the piece rather than quietly edited away. Contact details are here, including encrypted channels.

← All writing