Before the election I submitted a resilience checklist to Latvia’s CEC. Election week showed why fallback modes, readiness evidence and feedback loops matter.
Generative AI makes plausible claims, code and submissions cheap to produce. The deeper problem is what happens when verification still consumes scarce human time.
Anti-fraud network API interoperability needs more than a common schema: semantics, provenance, freshness, unknown states, privacy and clear legal-effect boundaries.
A good bug bounty programme allocates researcher attention, rewards useful novel signal fairly and converts validated findings into measurable remediation.
A governance model for treating some good-faith security research as operational civic participation — without turning public interest into a licence to test anything.
How public-sector ICT can prove what was approved, accepted and actually deployed without creating another central evidence warehouse or compliance document.
A practical CVD lifecycle covering intake, acknowledgement, triage, reproduction, ownership, remediation, retest, disclosure and evidence-based closure.
A practical analysis of CRA Article 14 reporting: AEVs, severe incidents, 24/72-hour deadlines, final-report clocks, the SRP and common simplification errors.
CVD, VDPs, bug bounties, penetration tests and red teams differ in purpose, authority, scope, incentives, coverage and stop conditions. A practical European comparison.
Cybersecurity certification should prove scope, operating effectiveness, retesting and reassessment after material change—not merely that a control exists.
How to turn cybersecurity requirements in public ICT procurement into verifiable outcomes through evidence, acceptance, remediation and lifecycle controls.
A practical way to assess data sovereignty through identity, keys, control planes, logs, backups, supply chains, portability, recovery and tested provider exit.