Quadrant mapping uncertainty against consequence, with adaptation favoured at high uncertainty and anticipation at high consequence

Agile, where it fits and where it doesn't

Most engineering disciplines accept that method follows from context. Nobody expects a bridge engineer, a documentary director, and a trauma surgeon to share a planning model, and nobody finds the difference remarkable. Software is one of the few fields where people go looking for a single methodology and then try to apply it to everything in sight. Agile is the most successful instance of that search, which makes it an awkward thing to argue about. The useful question is not whether it is good or bad. It is what kind of work it was meant for, and that turns out to depend on two things that have nothing to do with how much anyone likes the method. ...

June 4, 2026 · 5 min

How a rebellion became a bureaucracy

Few movements in software have been as successful as Agile. What began as a reaction against heavyweight process, exhaustive documentation, and centralised planning became the dominant way organisations talk about building software. And somewhere in that success it acquired certifications, prescribed ceremonies, maturity models, governance structures, a consulting industry, and dedicated management hierarchies, which is to say it acquired most of the things it was a reaction against. The question worth asking is narrow. Not whether Agile succeeded, and not the broad point that institutions reshape ideas, but the specific mechanism. By what steps does a critique of bureaucracy turn into a bureaucracy, when nobody involved wanted that outcome? ...

June 4, 2026 · 5 min
A figure at a small desk in a high-ceilinged reading room, reading with the quiet satisfaction of someone who has found exactly the book they wanted; through the tall windows, crowds of other figures drift past, half-dissolving into a cheerful drizzle, their attention already elsewhere. The reader is entirely unbothered.

Audience design

A friend asked whether the proof-of-concept I had sketched on a docs page was worth actually building. I said no, for the usual reasons, and also because the page in question had been written in the specific style of a document that does not want to be read. A four-layer architecture diagram without the diagram. Ingestion, storage, correlation, presentation. Bullet lists of API names with the dispiriting authority of a railway timetable. It reads like a tender response written by a tender response. ...

May 14, 2026 · 6 min

DigiD and the rented engine room

The story is, on paper, narrow. Solvinity, the Dutch contractor that operates infrastructure underneath Logius and DigiD, looks set to be acquired by Kyndryl, an American spin-off of IBM’s managed-services arm. DigiD itself remains owned by the Dutch state via Logius, so technically the system is still Dutch. Politically and operationally, the distinction does not calm many people down. A rented engine room is still part of the ship. Across Europe there has been a push for “digital sovereignty”, meaning less dependency on American hyperscalers and infrastructure providers after years of quietly outsourcing half the state to Silicon Valley with the serene confidence of a man juggling chainsaws because the first three catches worked out fine. ...

May 7, 2026 · 7 min
admin attack surface

The administrative attack surface

A few days after sending an application to the Dutch Ministry of Defence for a senior cyber and information security advisory role, I read an NRC article about publicly accessible details of Dutch military infrastructure. Not leaked documents. Not espionage. Not shadowy dead drops in rainy parking garages. Public websites. Pipeline routes. Radar dependencies. Cable maps. Technical drawings. Backup systems. Segmentation details. Power feeds. Coordinates. Bits of information scattered across agencies, permits, infrastructure registries, environmental datasets and planning portals like breadcrumbs dropped by a committee convinced that nothing bad ever happens in spreadsheets. ...

May 6, 2026 · 5 min

How security failures learned to sound reasonable

The most useful phrases in a modern security programme are the ones that cannot be argued with. “The platform gives us coverage.”, “We have visibility.”, “The tool supports MFA.” Each one is calm, professional, and technically defensible. Each one can also be doing something quietly different from what the room hears. How the grammar works Three small grammatical moves do most of the heavy lifting. The first is capability standing in for implementation: “The platform supports MFA”, “Defender has ransomware protection”, “Our firewall can do segmentation”. ...

May 3, 2026 · 5 min
A boardroom with no walls, floating in calm white space. Six figures in identical grey suits sit around a long polished table, each with a smooth mirrored orb where their head should be, nodding politely at a single document hovering above the table

How some ideas outlast their own evidence

Across many mature organisations, the same phrases seem to keep coming back, like “Aligned with best practice”, “The control is in place”, and “We followed the framework”. They survive failure. They survive scandal. They survive the people who used them last time. The question worth asking is perhaps not whether they are accurate, but why they are so robust. The usual explanations cover bureaucratic inertia, regulatory capture, and the well-documented limits of organisational learning. These are real, but they are not the most interesting part. The more interesting possibility is that these phrases are doing useful work. Just not the work they appear to be doing. ...

May 3, 2026 · 6 min

Is your threat model already behind?

Most organisations think they have a threat model. What they usually have is a historical artefact: a snapshot of how the environment looked on the day several people sat in a room with diagrams, coffee, and varying levels of optimism. The session happens. Assets are mapped. Threats are identified. Risks are scored. A document is produced. The document is reviewed, approved, uploaded somewhere nobody voluntarily visits, and occasionally resurrected during audits or post-incident archaeology. ...

May 2, 2026 · 5 min

The Dealer smiles?

We are told that world politics is a chess game. Grandmasters move pieces across a board, sacrificing pawns to protect kings, calculating six moves ahead. It is rational. It is elegant. It is, above all, knowable. This is a lie. After walking through the resource wars of Venezuela, Greenland, Iran, Ukraine, Russia and China, and after one reader finally lost patience and called a certain former president a “greedy twat”, a different metaphor emerged. Not chess. Not even regular poker. ...

May 1, 2026 · 11 min

Building an exit from capitalism

A boring, decades-long plan for getting out of capitalism without burning the village down The two stories most often told about how to get past capitalism both fail in roughly the same way. The first is a Big Bang: revolutionary seizure of state power, redesign from above. The historical track record is grim. New rulers inherit the same coordination problems, the same resource constraints, and the same external threats, and tend to respond the way besieged regimes generally do, which involves rather more centralised violence than was originally promised. ...

April 30, 2026 · 14 min