What belongs here
This section covers work where external professional expertise meets public institutions, regulation and public digital systems. An article may also belong to a technical topic at the same time.
Ancveirs
This section covers work where external professional expertise meets public institutions, regulation and public digital systems. An article may also belong to a technical topic at the same time.
Context + topic
Before the election I submitted a resilience checklist to Latvia’s CEC. Election week showed why fallback modes, readiness evidence and feedback loops matter.
A governance model for treating some good-faith security research as operational civic participation — without turning public interest into a licence to test anything.
How public-sector ICT can prove what was approved, accepted and actually deployed without creating another central evidence warehouse or compliance document.
How to turn cybersecurity requirements in public ICT procurement into verifiable outcomes through evidence, acceptance, remediation and lifecycle controls.
A legal right to report vulnerabilities is necessary but insufficient. Sustainable participation also needs trust, feedback, recognition, progression and closure.
How independent security-research signals can connect to CVD, CSIRTs, remediation and vulnerability intelligence without outsourcing state responsibility.
A documented Latvian case study on vulnerability discovery, reward demands, disclosure threats, extortion, clemency and safer coordinated disclosure.
How public-sector ICT can prove what was approved, accepted and actually deployed without creating another central evidence warehouse or compliance document.
Before the election I submitted a resilience checklist to Latvia’s CEC. Election week showed why fallback modes, readiness evidence and feedback loops matter.
A governance model for treating some good-faith security research as operational civic participation — without turning public interest into a licence to test anything.
How public-sector ICT can prove what was approved, accepted and actually deployed without creating another central evidence warehouse or compliance document.
How to turn cybersecurity requirements in public ICT procurement into verifiable outcomes through evidence, acceptance, remediation and lifecycle controls.
A legal right to report vulnerabilities is necessary but insufficient. Sustainable participation also needs trust, feedback, recognition, progression and closure.
How independent security-research signals can connect to CVD, CSIRTs, remediation and vulnerability intelligence without outsourcing state responsibility.
A documented Latvian case study on vulnerability discovery, reward demands, disclosure threats, extortion, clemency and safer coordinated disclosure.