Weekly Brief archivePermanent weekly record

The weekly signal, kept after the feed moves on.

Each issue connects three real cases to one recurring engineering pattern and one decision worth carrying into the next week.

8 issuesAbout five minutes eachDelivered through LinkedIn
Issue 08 · 26 September 2026Latest

The label is not the assurance case.

This week, three different security discussions exposed the same decision problem. A PLC can contain a second software lifecycle. A vulnerability can require local access and still reach a high-impact platform boundary. A supplier can provide valid records without giving you a provenance chain that remains independently verifiable. The labels are useful for organising the problem. They are not enough to close the assurance argument.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 07 · 19 September 2026

Security assurance has to survive the lifecycle.

This week, three cases exposed the same lifecycle problem. NSA's ASIC guidance pushes assurance upstream into design, third-party IP and manufacturing evidence. Airwall shows how a deployed cryptographic secret can become a migration and recovery dependency. Semiconductor security sign-off then asks what evidence is sufficient at release when those assumptions will be inherited downstream. A control can keep working technically while the trust decision behind it becomes harder to reassess.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 06 · 12 September 2026

Supporting systems become security boundaries when they inherit authority.

This week, three systems that can look secondary to the primary product exposed the same security problem. A railway diagnostic platform is not the axle-counting safety function. An industrial security router is supposed to protect the boundary rather than become the process. A dealer-installed anti-theft module sits outside the OEM's original engineering lifecycle. Yet each can accumulate sensitive information, privileged connectivity or state-changing authority. The useful security boundary therefore follows what a component can know, reach and change, not the label attached to it.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 05 · 5 September 2026

Security evidence has to follow the attack path.

This week, three very different systems exposed the same assurance gap. An automotive IDS can detect malicious traffic, a critical PLC vulnerability can justify urgent remediation, and an application can enforce apparently limited permissions. None of those observations, on its own, proves what authority an attacker can exercise in the deployed system. The missing evidence sits between layers: preconditions, reachability, privilege transitions and the real path from threat origin to consequence.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 04 · 29 August 2026

The trusted path can become the attack path.

This week, three very different systems reached the same security boundary. An industrial firewall depends on third-party software. A PLC depends on legitimate engineering access. An automotive head unit depends on infrastructure authorised to install new software. None of those paths is inherently a weakness. The problem appears when a trusted mechanism retains enough authority to change the system after trust in the infrastructure behind it has been lost.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 03 · 22 August 2026

Security assurance breaks at the boundaries.

Security failures do not always begin with a missing control. A safety process can work. Software execution can remain trusted. An API can authenticate its sender. The weakness can appear at the boundary between those assurances and the physical or operational reality they are supposed to protect. This week, three cases expose the same problem: a valid control is not enough when the next layer inherits an unverified assumption.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 02 · 15 August 2026

The control may be valid. The evidence can still be wrong.

This week, three very different systems reached the same engineering boundary. An OT alert can be technically correct while the physical state remains uncertain. Firmware can carry a valid signature while retaining a vulnerable dependency. A railway AI control layer can be deterministic while inheriting the same corrupted telemetry as the system it supervises. Trust is not a property of a control. It is a property of the evidence chain behind the decision.

5 minute read · 3 cases · 1 decision to revisit · 3 external readsRead issue →
Issue 01 · 8 August 2026

Recovery is getting faster than assurance.

This week, three very different incidents pointed to the same problem. Organisations can patch a platform, contain a workload or keep production running before they can prove that the state left behind is trustworthy. The technical fixes matter. The harder question is what evidence is strong enough to authorise the next decision.

5 minute read · 3 cases · 1 decision to revisit · 4 external readsRead issue →