Before the election I submitted a resilience checklist to Latvia’s CEC. Election week showed why fallback modes, readiness evidence and feedback loops matter.
A good bug bounty programme allocates researcher attention, rewards useful novel signal fairly and converts validated findings into measurable remediation.
A governance model for treating some good-faith security research as operational civic participation — without turning public interest into a licence to test anything.
How public-sector ICT can prove what was approved, accepted and actually deployed without creating another central evidence warehouse or compliance document.
A practical CVD lifecycle covering intake, acknowledgement, triage, reproduction, ownership, remediation, retest, disclosure and evidence-based closure.
A practical analysis of CRA Article 14 reporting: AEVs, severe incidents, 24/72-hour deadlines, final-report clocks, the SRP and common simplification errors.
CVD, VDPs, bug bounties, penetration tests and red teams differ in purpose, authority, scope, incentives, coverage and stop conditions. A practical European comparison.
Cybersecurity certification should prove scope, operating effectiveness, retesting and reassessment after material change—not merely that a control exists.
How to turn cybersecurity requirements in public ICT procurement into verifiable outcomes through evidence, acceptance, remediation and lifecycle controls.
A practical European approach to vulnerability prioritisation that keeps CVSS severity, EPSS forecasts, known exploitation and local asset context distinct.
Where does good-faith vulnerability research stop being permitted testing? NIS2, cybercrime law, CVD and a documented Latvian case study.
NIS2 requires national CVD coordination but does not create a universal researcher safe harbour. What Article 12, Recital 60 and national cybercrime law actually mean.
A legal right to report vulnerabilities is necessary but insufficient. Sustainable participation also needs trust, feedback, recognition, progression and closure.
A practical evidence standard for AI-assisted vulnerability reports: scope, reproduction, PoC, demonstrated impact, severity, data minimisation and accountability.
CVD and bug bounty cannot replace a secure SDLC. Use threat modelling, secure defaults, code and dependency controls, release gates and finding feedback.
Pentesting, red teaming, purple teaming, CVD, bug bounty and TLPT produce different evidence. Combine them deliberately into layered security assurance.
A finding is not closed because a ticket says Done. Use risk ownership, residual risk, remediation evidence and verification to make decisions reconstructable.
How independent security-research signals can connect to CVD, CSIRTs, remediation and vulnerability intelligence without outsourcing state responsibility.
Critical systems need differentiated research models: public reporting, low-impact testing, registered researchers, vetted programmes and controlled testing.
A documented Latvian case study on vulnerability discovery, reward demands, disclosure threats, extortion, clemency and safer coordinated disclosure.
Generative AI accelerates recon, hypotheses and reporting, while scope judgment, validation, impact analysis and accountable disclosure remain human responsibilities.
A practical model for degraded digital-service operation: minimum service, dependency failure, manual fallback, reconciliation and controlled return to normal.
What to do when vulnerability validation exposes personal data: researcher roles, lawful basis, minimum evidence, storage, reporting, deletion and breach boundaries.
Caller ID is not identity proof. Separate number control, call-origin consistency and fraud risk without turning a “verified” label into a false safety promise.