Before the election I submitted a resilience checklist to Latvia’s CEC. Election week showed why fallback modes, readiness evidence and feedback loops matter.
Generative AI makes plausible claims, code and submissions cheap to produce. The deeper problem is what happens when verification still consumes scarce human time.
Anti-fraud network API interoperability needs more than a common schema: semantics, provenance, freshness, unknown states, privacy and clear legal-effect boundaries.
A governance model for treating some good-faith security research as operational civic participation — without turning public interest into a licence to test anything.
How public-sector ICT can prove what was approved, accepted and actually deployed without creating another central evidence warehouse or compliance document.
How to turn cybersecurity requirements in public ICT procurement into verifiable outcomes through evidence, acceptance, remediation and lifecycle controls.
A practical way to assess data sovereignty through identity, keys, control planes, logs, backups, supply chains, portability, recovery and tested provider exit.
Where does good-faith vulnerability research stop being permitted testing? NIS2, cybercrime law, CVD and a documented Latvian case study.
NIS2 requires national CVD coordination but does not create a universal researcher safe harbour. What Article 12, Recital 60 and national cybercrime law actually mean.
A legal right to report vulnerabilities is necessary but insufficient. Sustainable participation also needs trust, feedback, recognition, progression and closure.
A finding is not closed because a ticket says Done. Use risk ownership, residual risk, remediation evidence and verification to make decisions reconstructable.
How independent security-research signals can connect to CVD, CSIRTs, remediation and vulnerability intelligence without outsourcing state responsibility.
Critical systems need differentiated research models: public reporting, low-impact testing, registered researchers, vetted programmes and controlled testing.
A documented Latvian case study on vulnerability discovery, reward demands, disclosure threats, extortion, clemency and safer coordinated disclosure.
A practical model for degraded digital-service operation: minimum service, dependency failure, manual fallback, reconciliation and controlled return to normal.
What to do when vulnerability validation exposes personal data: researcher roles, lawful basis, minimum evidence, storage, reporting, deletion and breach boundaries.