What belongs here
This section contains professional work on cybersecurity, FinTech, RegTech, AI and system architecture. Topics describe the subject; this lane describes the context of the work.
Ancveirs
This section contains professional work on cybersecurity, FinTech, RegTech, AI and system architecture. Topics describe the subject; this lane describes the context of the work.
Context + topic
A good bug bounty programme allocates researcher attention, rewards useful novel signal fairly and converts validated findings into measurable remediation.
A practical CVD lifecycle covering intake, acknowledgement, triage, reproduction, ownership, remediation, retest, disclosure and evidence-based closure.
A practical analysis of CRA Article 14 reporting: AEVs, severe incidents, 24/72-hour deadlines, final-report clocks, the SRP and common simplification errors.
CVD, VDPs, bug bounties, penetration tests and red teams differ in purpose, authority, scope, incentives, coverage and stop conditions. A practical European comparison.
Cybersecurity certification should prove scope, operating effectiveness, retesting and reassessment after material change—not merely that a control exists.
A practical European approach to vulnerability prioritisation that keeps CVSS severity, EPSS forecasts, known exploitation and local asset context distinct.
Where does good-faith vulnerability research stop being permitted testing? NIS2, cybercrime law, CVD and a documented Latvian case study.
NIS2 requires national CVD coordination but does not create a universal researcher safe harbour. What Article 12, Recital 60 and national cybercrime law actually mean.
A practical evidence standard for AI-assisted vulnerability reports: scope, reproduction, PoC, demonstrated impact, severity, data minimisation and accountability.
CVD and bug bounty cannot replace a secure SDLC. Use threat modelling, secure defaults, code and dependency controls, release gates and finding feedback.
Pentesting, red teaming, purple teaming, CVD, bug bounty and TLPT produce different evidence. Combine them deliberately into layered security assurance.
A finding is not closed because a ticket says Done. Use risk ownership, residual risk, remediation evidence and verification to make decisions reconstructable.
Critical systems need differentiated research models: public reporting, low-impact testing, registered researchers, vetted programmes and controlled testing.
Generative AI accelerates recon, hypotheses and reporting, while scope judgment, validation, impact analysis and accountable disclosure remain human responsibilities.
A practical model for degraded digital-service operation: minimum service, dependency failure, manual fallback, reconciliation and controlled return to normal.
What to do when vulnerability validation exposes personal data: researcher roles, lawful basis, minimum evidence, storage, reporting, deletion and breach boundaries.
Caller ID is not identity proof. Separate number control, call-origin consistency and fraud risk without turning a “verified” label into a false safety promise.
Anti-fraud network API interoperability needs more than a common schema: semantics, provenance, freshness, unknown states, privacy and clear legal-effect boundaries.
A practical analysis of CRA Article 14 reporting: AEVs, severe incidents, 24/72-hour deadlines, final-report clocks, the SRP and common simplification errors.
A practical way to assess data sovereignty through identity, keys, control planes, logs, backups, supply chains, portability, recovery and tested provider exit.
Pentesting, red teaming, purple teaming, CVD, bug bounty and TLPT produce different evidence. Combine them deliberately into layered security assurance.
Caller ID is not identity proof. Separate number control, call-origin consistency and fraud risk without turning a “verified” label into a false safety promise.
Generative AI makes plausible claims, code and submissions cheap to produce. The deeper problem is what happens when verification still consumes scarce human time.
A practical evidence standard for AI-assisted vulnerability reports: scope, reproduction, PoC, demonstrated impact, severity, data minimisation and accountability.
Generative AI accelerates recon, hypotheses and reporting, while scope judgment, validation, impact analysis and accountable disclosure remain human responsibilities.
How to interpret AI benchmark results without overclaiming: test scope, data provenance, language coverage, uncertainty, reproducibility and intended-use evidence.
A practical way to assess data sovereignty through identity, keys, control planes, logs, backups, supply chains, portability, recovery and tested provider exit.
CVD and bug bounty cannot replace a secure SDLC. Use threat modelling, secure defaults, code and dependency controls, release gates and finding feedback.
A practical model for degraded digital-service operation: minimum service, dependency failure, manual fallback, reconciliation and controlled return to normal.
Generative AI makes plausible claims, code and submissions cheap to produce. The deeper problem is what happens when verification still consumes scarce human time.
Anti-fraud network API interoperability needs more than a common schema: semantics, provenance, freshness, unknown states, privacy and clear legal-effect boundaries.
A practical way to assess data sovereignty through identity, keys, control planes, logs, backups, supply chains, portability, recovery and tested provider exit.
Where does good-faith vulnerability research stop being permitted testing? NIS2, cybercrime law, CVD and a documented Latvian case study.
NIS2 requires national CVD coordination but does not create a universal researcher safe harbour. What Article 12, Recital 60 and national cybercrime law actually mean.
A finding is not closed because a ticket says Done. Use risk ownership, residual risk, remediation evidence and verification to make decisions reconstructable.
Critical systems need differentiated research models: public reporting, low-impact testing, registered researchers, vetted programmes and controlled testing.
A practical model for degraded digital-service operation: minimum service, dependency failure, manual fallback, reconciliation and controlled return to normal.
What to do when vulnerability validation exposes personal data: researcher roles, lawful basis, minimum evidence, storage, reporting, deletion and breach boundaries.