Research
Research Areas
Long-running lines of enquiry. Each area is a question being worked on, not a claim of completed work.
Areas
-
Cyber Threat Intelligence
Adversary tracking, indicator lifecycle, and the evidence chain from raw collection to an assertion someone can act on.
-
Open-Source Intelligence
Collection from public sources with provenance preserved — where a finding came from matters as much as the finding.
-
AI-assisted Intelligence
Using language models as analytical instruments, measured against deterministic baselines rather than assumed to be better.
-
Security Engineering
Building systems where the safe path is the easy path, and where failure states are distinguishable from silence.
-
Security Automation
Automating the repeatable parts of defence without automating away the judgement.
-
Agentic AI
Multi-agent systems with observability, causal tracing, and verifiable control planes.
-
Technology Strategy
Translating technical capability into decisions that hold up outside the lab.
Selected Research
-
Cyber Threat Intelligence
From OSINT Collection to Actionable Cyber Threat Intelligence
An eight-stage pipeline from public sources to SOC detection — and the specific way each stage fails. Most pipelines do not break where they are monitored; they break at the handoffs, silently, in the direction of false confidence.
-
Collection & Measurement
Measuring Blind Spots in Intelligence Collection
Every collection programme has a shape, and the shape determines what it can never see. Most programmes measure volume and coverage against their own output — a denominator that cannot detect the data that never arrived.
-
Cyber Threat Intelligence
IOC ≠ Intelligence: Turning Indicators into Decisions
An indicator is an observation. Intelligence is an observation someone can act on, with a stated confidence and an expiry. The distance between them is where most security programmes quietly lose the value they paid for.