Search this site

Mitchell Hewes's Picture

Mitchell Hewes

I help people secure computers and neutrons. Occasionally, I go on adventures and always spend far too much time thinking.

I help make nuclear systems secure by design—and bring the world together to keep them that way.

For more than a decade, I have worked at the intersection of nuclear science, critical infrastructure, engineering, and computer security. My path began at ANSTO, where I became absorbed by a deceptively simple question: how can computer security become part of engineering practice, rather than something added after the most important design decisions have already been made?

That question has always had a practical side. My work has included experimenting with one-way data transfer and data diodes, developing open-source infrastructure, and building tools for research and training. Working directly with technology makes the engineering questions tangible: what does the design allow, what does it prevent, and which assumptions must hold for it to be trusted?

At the IAEA, I brought that practical approach to international research, guidance and training. This included serving as the Agency’s project lead for CRP J02008 as well as Learners, an open-source project supporting nuclear-security training. Alongside that work, I led the development of standards, training programmes, and governance frameworks shaped through international consensus and delivered through the IAEA and the wider UN system.

Just as importantly, I have helped build the national and international expert networks that carry this work beyond a particular project or publication.

Standards matter, but documents alone do not change outcomes. People need the understanding, confidence, and opportunity to challenge them and apply them within the realities of complex organisations and engineered systems.

Much of my work now involves a form of interpretation, not by simplifying complexity away, but making it possible for engineers, security specialists, operators, and decision-makers to reason about the same problem. I help make assumptions visible, connect different perspectives and create room for people to contribute their expertise. Effective cooperation isn’t a nice-to-have; it is part of how resilient systems are built.

Working directly with technology continues to shape how I approach whole systems: examining what the design permits, which assumptions it depends on, and what evidence justifies trusting it. Today, I use function-based systems thinking to integrate safety and security from the outset.

I remain interested in emerging technologies, not simply in what they can do, but in the assumptions, dependencies, and vulnerabilities they introduce. I continue to build practical tools that make interactions between people, software, information and engineered systems visible, helping different disciplines explore their implications together.

The same curiosity shapes how I explore the world.

Through travel, photography and writing, I look for experiences that unsettle familiar perspectives and reveal something new about places, institutions and everyday life. I document some of those shifts here.

Whether I am building something, working through a systems-security problem or writing about a place, I share what I learn because knowledge and creativity become more useful when they circulate. Wherever possible, I release my work under permissive licences so that others can use it, challenge it, and build upon it.

Connect

I value thoughtful dialogue across disciplines, particularly conversations that lead to collaboration, constructive disagreement or simply a better question. You are always welcome to reach out.

The views expressed here are personal and reflect my perspective at a particular moment in time. They may evolve—as all ideas should—and do not represent the positions of any organisation with which I am associated.

View original image