Understand before securing
You cannot secure a system well if you do not understand how it works, where trust exists, and how its parts interact.
Expertise
I have spent my career learning how technology works from the physical layer upward. That started with microelectronics and moved through telecommunications, networks, enterprise infrastructure, security, identity, data, and now agentic systems.
I am less interested in becoming the person for a particular product than understanding the problem underneath it. Products change. The fundamentals around communication, identity, trust, authorization, execution, reliability, and observability change much more slowly.
01 // How I think
You cannot secure a system well if you do not understand how it works, where trust exists, and how its parts interact.
Learning the underlying problem makes it easier to move between vendors, platforms, and new technologies without starting from zero.
Security controls have to account for human behaviour and how people actually get work done. A control that people route around is not doing its job.
02 // Depth
My foundation in microelectronics taught me to be curious about what is happening underneath the abstraction. Over time that curiosity moved from hardware and distributed terminals into computers, cabling, wireless, switching, routing, servers, directory services, WANs, enterprise communications, security operations, software, identity systems, data, and autonomous agents.
03 // Operating environments
I have applied that experience in very different environments, from systems that connect remote terminals and geographically distributed networks to business infrastructure, specialized operational systems, and large-scale software platforms. Consulting across private-sector organizations also meant regularly dropping into unfamiliar environments, learning how the business and technology worked, and becoming useful quickly. The constraints change by industry; the need to understand the system does not.
04 // Areas of expertise
These areas connect what I know with the research and tools I publish here. As the site grows, these pages will grow with it.
Identity, authorization, execution boundaries, human-in-the-loop controls, and evidence for agentic systems.
Identity lifecycle, access policy, zero trust, authorization, and the systems that connect people and workloads to resources.
Building controls that work in real systems: detection, response, vulnerability management, endpoint trust, automation, and risk.
Using data pipelines, measurement, and analysis to understand whether security controls are actually working.
Experience from the physical network upward: telecommunications, LAN/WAN, wireless, servers, directory services, firewalls, virtualization, and cloud.