Research, Readiness and the Valley of Death
When people talk about "research" in cyber security, there is a tendency to reach for a fairly narrow set of examples: vulnerabili
The Left Hand Scientist
A space for personal projects, half-baked ideas, and occasional overengineering. Mostly cybersecurity, transport, and 3D printing—with detours.
When people talk about "research" in cyber security, there is a tendency to reach for a fairly narrow set of examples: vulnerabili
Take your leave is the recycling of the workplace: the last tier, the cheapest fix, and the only one you can hand to one person. The tiers that would actually work, scoping and real cover, sit above it and belong to somebody else.
Every engineer ends up with a stack that’s part necessity, part indulgence. Mine started as a way to keep remote work, backups and research
Getting Windows-only CNC software running under Wine, teaching Claude to drive it through a nested X server, and cutting a coin set — plus a D&D treasure hoard in three cheap metals.
Corporate DEI became a kind of spell. It was repeated in annual reports and all-hands meetings, pinned to office walls, and whispered as pr
Threat modelling is frequently discussed as if it were a singular, monolithic exercise. In reality, applying a one-size-fits-all methodology
A brief logging event to mark a significant professional milestone. I was incredibly honored to be shortlisted as a finalist for the Outstan
When a supplier delivers a component implementing complex cryptographic functions, a standard black-box penetration test is entirely insuffi
While the Euro 7 standard is widely discussed in the media as a final tightening of automotive tailpipe emissions, its implications for soft
There is a strange role that trans people often get handed whether we asked for it or not. The walking symbol. The living lesson. The person
I’ve published a new article for NCC Group’s Research Blog titled “Legacy Technology in Transport: More Than ‘Old Tech’”. You can read it he
I’ve written a new piece for NCC Group’s Research Blog on how goal-based regulation is changing the way we think about cybersecurity assuran