AnalysisPermanent written record

Ideas worth keeping after the feed moves on.

Analysis turns the strongest LinkedIn theses and podcast cases into durable, source-backed references. Some pieces have a matching episode. Others begin on the analysis desk and stand alone.

24 current piecesOT · Automotive · Railway · Product · AI · Supply Chain
Automotive · Product Security9 Aug 2026

Aftermarket Security Devices Can Become Part of the Vehicle Attack Surface

4 min read · 3 cited sources · 1 visual

Dealer-installed security hardware can cross the vehicle trust boundary without being governed like an OEM security component.

Read analysis →
Product Security · Supply Chain7 Aug 2026

Why Patching Windchill Is Not Enough

3 min read · 3 cited sources · 1 visual

A PLM recovery problem becomes a product-assurance problem.

Read analysis →
AI Security · Supply Chain5 Aug 2026

When AI Crossed the Trust Boundary

4 min read · 3 cited sources · 1 visual

Transitive trust can defeat an apparently isolated evaluation environment.

Read analysis →
Railway · Supply Chain2 Aug 2026

Stadler Rail: When Supplier Trust Becomes the Attack Surface

3 min read · 5 cited sources · 1 visual

Supplier identity compromise without a production outage can still matter.

Read analysis →
OT & ICS1 Aug 2026

The Restart Bottleneck Is Not the Backup. It Is the Evidence.

3 min read · 4 cited sources · 1 visual

Production recovery needs a defensible evidence chain, not only restored systems.

Read analysis →
Automotive · Product Security31 Jul 2026

An IDPS Alert Is Not an Incident Response Capability

3 min read · 4 cited sources · 1 visual

Detection matters only when the organisation can translate it into an owned product decision.

Read analysis →
Automotive · Supply Chain30 Jul 2026

The Next Production Delay May Be Missing Cybersecurity Evidence

3 min read · 4 cited sources · 1 visual

Supplier evidence becomes part of production resilience during a live decision.

Read analysis →
OT & ICS · Critical Infrastructure9 Aug 2026

Safety Independence Must Survive a Cyber Compromise

3 min read · 4 cited sources · 1 visual

If control and safety share the same identities, engineering paths or infrastructure, a cyber incident can turn nominal independence into common-mode failure.

Read analysis →
Railway29 Jul 2026

When a Security Patch Collides with the Safety Case

3 min read · 5 cited sources · 1 visual

Cyber urgency and safety assurance need one engineering interface.

Read analysis →
OT & ICS28 Jul 2026

The Remote Access Path Nobody Questions Anymore

3 min read · 5 cited sources · 1 visual

Legacy VPN trust can quietly bypass the plant segmentation model.

Read analysis →
Automotive · Product Security9 Aug 2026

Euro 7 Turns Emissions Compliance into a Cybersecurity Evidence Chain

3 min read · 3 cited sources · 1 visual

When regulatory evidence depends on sensors, ECUs, onboard monitoring and off-board data, integrity has to survive the complete chain.

Read analysis →
OT & ICS · Supply Chain9 Aug 2026

When Legitimate Engineering Workflows Can Carry Malicious Control Logic

3 min read · 4 cited sources · 1 visual

OpenPLC research demonstrates malicious modification of the running user program. Source, repository or build compromise is a separate engineering risk scenario, not a demonstrated finding.

Read analysis →
Automotive · Product Security9 Aug 2026

The Connected Vehicle Perimeter Includes Dealer APIs

3 min read · 2 cited sources · 1 visual

The Kia research showed how a public identifier and an over-privileged dealer workflow could become an internet-to-vehicle control path.

Read analysis →
Product Security · Supply Chain9 Aug 2026

The CRA Reporting Clock Is Really a Decision-Readiness Test

3 min read · 3 cited sources · 1 visual

A 24-hour early warning is manageable only when product identity, exploitability evidence and decision authority already exist before the incident.

Read analysis →
OT & ICS9 Aug 2026

Industrial 5G Makes Radio Availability Part of the Safety and Production Model

3 min read · 4 cited sources · 1 visual

Private 5G can provide strong identity and segmentation while still remaining physically vulnerable to selective interference.

Read analysis →
OT & ICS · Automotive9 Aug 2026

EV Charging Security Is Becoming Grid Resilience

3 min read · 3 cited sources · 1 visual

The risk is not one compromised charger. It is coordinated control across an ecosystem that can aggregate into material grid behaviour.

Read analysis →
OT & ICS9 Aug 2026

Zero Trust in OT Should Mediate Authority, Not Modernise Every PLC

3 min read · 2 cited sources · 1 visual

Legacy controllers do not need to speak modern identity protocols for the surrounding architecture to remove implicit trust.

Read analysis →
Product Security · Supply Chain9 Aug 2026

A VEX Statement Is a Claim That Needs Evidence

3 min read · 3 cited sources · 1 visual

VEX can suppress false urgency, but an unsupported “not affected” status simply converts vulnerability noise into governance risk.

Read analysis →
Railway9 Aug 2026

FRMCS Should Treat the Mobile Network as Transport, Not as Trust

3 min read · 5 cited sources · 1 visual

Railway applications can use modern mobile connectivity without delegating safety or cyber authority to the transport network.

Read analysis →
Automotive · Product Security9 Aug 2026

How a Software-Defined Vehicle Could Inherit Compromise Before Delivery

3 min read · 3 cited sources · 1 visual

This engineering scenario examines how compromised flashing, signing or cryptographic provisioning could establish an incorrect software or identity baseline before delivery.

Read analysis →
Railway · OT & ICS9 Aug 2026

Legacy Rail Assets Do Not Become Secure Because the Policy Improved

3 min read · 4 cited sources · 1 visual

New cybersecurity requirements have to be translated into compensating architecture around assets that cannot be patched, authenticated or replaced quickly.

Read analysis →
OT & ICS · Critical Infrastructure9 Aug 2026

Oldsmar Is a Warning About Standing Remote Authority

3 min read · 3 cited sources · 1 visual

The enduring lesson is not a single remote-access product. It is the danger of persistent authority that remains available when nobody is actively using it.

Read analysis →
AI Security · Product Security9 Aug 2026

Prompt Injection Is an Authority-Boundary Failure

3 min read · 3 cited sources · 1 visual

When an AI system reads untrusted content and can act on tools, the security question becomes which text is allowed to become authority.

Read analysis →
AI Security · Product Security9 Aug 2026

AI Agents Turn Excessive Permission into Operational Risk

3 min read · 3 cited sources · 1 visual

An agent becomes security-sensitive when it can combine untrusted information with credentials, tools and the authority to take action.

Read analysis →