Essays written in an internal strategy memo register: the argument as it
would be made to an architecture board, not a summary of it. No calls to
action.
Which zero trust principles survive contact with operational technology, and which will break your control systems if you apply them. Identity, segmentation and encryption reconsidered for hybrid IT/OT estates.
Adversarial machine learning meets industrial control. Training-time poisoning, inference-time evasion and model extraction against OT anomaly detection, with the architectural and operational controls that build in robustness.
The traditional grid had thousands of controllable assets; the smart grid has millions. Securing distributed energy resources, virtual power plants and edge devices at a scale the existing security architecture was never designed for.
In enterprise IT a bad incident response decision costs you an outage. In OT it can cost a life. Why SIEM playbooks do not transfer to operational environments, and what an OT-specific response capability has to look like.
The OT DMZ is the most important zone in an industrial security architecture and the one most often designed by people who have never operated a control system. What a defensible design actually requires, broker by broker.
A practical design guide for regulated energy operators adopting cloud without surrendering the control properties that regulation and operational safety demand: data residency, sovereignty boundaries, and assurance under IRAP and SOCI.
Where machine learning genuinely earns its place in industrial control, and where it does not. Anomaly detection and predictive maintenance assessed honestly against the determinism and safety constraints of OT environments.
The most dangerous moment for a control system is when someone decides to replace it. Architecture patterns for SCADA modernisation (migration strategy, historian placement, remote access) that preserve operational safety properties.
STRIDE was built to find bugs in software; critical national infrastructure has an adversary problem. A consequence-driven approach to threat modelling using PASTA, MITRE ATT&CK for ICS, and process hazard analysis as first-class inputs.
Convergence is routinely treated as an engineering convenience problem when it is a security architecture problem. Why the Purdue Model still matters, how convergence projects break it, and what ISA/IEC 62443 actually demands of energy operators.