<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Writing on blog.mitcdh</title><link>https://blog.mitcdh.au/tags/writing/</link><description>Recent content in Writing on blog.mitcdh</description><generator>Hugo</generator><language>en-AU</language><lastBuildDate>Sat, 05 Sep 2026 07:59:02 +0000</lastBuildDate><atom:link href="https://blog.mitcdh.au/tags/writing/index.xml" rel="self" type="application/rss+xml"/><item><title>Hearing the Music: A History of the Cyber ITC, 2016–2025</title><link>https://blog.mitcdh.au/posts/hearing-the-music/</link><pubDate>Sat, 05 Sep 2026 07:59:02 +0000</pubDate><guid>https://blog.mitcdh.au/posts/hearing-the-music/</guid><description>&lt;p&gt;&lt;em&gt;I was asked to write a history of the IAEA Cyber ITC for its 2026 delivery. I have been fortunate to be part of its development from near the beginning, starting with the original hands-on training consultancy meeting and RTC. I later served as the first Project Officer for Learners, the second for the CRP, and Scientific Secretary for the ITC from 2019 to 2024. I inherited parts of that work from colleagues at the IAEA who had carried it before me, and built on the vision they had established.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>There Is No Such Thing As Cyber Risk</title><link>https://blog.mitcdh.au/posts/no-such-thing-as-cyber-risk/</link><pubDate>Sun, 09 Aug 2026 07:34:55 +0000</pubDate><guid>https://blog.mitcdh.au/posts/no-such-thing-as-cyber-risk/</guid><description>&lt;blockquote&gt;
&lt;p&gt;There is no such thing as cyber risk.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That is deliberately provocative, but the distinction matters. My thesis is neither that cyber-related uncertainty is not real nor that it is incapable of producing material consequences. It is that &amp;ldquo;cyber&amp;rdquo; is the wrong boundary at which to express, govern, own, and accept the resulting risk.&lt;/p&gt;
&lt;p&gt;Risk arises because an organisation is pursuing an objective under uncertainty. It is something to understand, treat, and sometimes accept because the value of pursuing that objective can justify exposure (within applicable legal, regulatory, ethical, moral, and existing organisational constraints).&lt;/p&gt;</description></item><item><title>The Carousel Before the Feed</title><link>https://blog.mitcdh.au/posts/carousel-before-the-feed/</link><pubDate>Sun, 19 Jul 2026 14:30:00 +1000</pubDate><guid>https://blog.mitcdh.au/posts/carousel-before-the-feed/</guid><description>&lt;p&gt;There is a scene in &lt;em&gt;Mad Men&lt;/em&gt; where Don Draper pitches Kodak&amp;rsquo;s circular slide projector, &amp;ldquo;The Carousel&amp;rdquo;. He barely talks about the technology. Instead, he talks about what it allows people to feel, the ability to travel backwards and return to a place and a time where they still ache to be.&lt;/p&gt;
&lt;p&gt;When my dad passed away, I found myself going through thousands of slides from my grandfather&amp;rsquo;s collection. Many showed my dad growing up with his family. I saw the father I knew as a child, a brother, and a son, living through years that had previously existed for me only as stories.&lt;/p&gt;</description></item><item><title>Parsing Consensus</title><link>https://blog.mitcdh.au/posts/parsing-consensus/</link><pubDate>Sat, 18 Jul 2026 00:00:00 +1000</pubDate><guid>https://blog.mitcdh.au/posts/parsing-consensus/</guid><description>&lt;p&gt;The idea for this experiment came from a few conversations at CyberCon26. I spoke with people who had asked LLMs questions about IAEA safety and nuclear security guidance and come away with an understanding that the publications did not support. The answers were not always obvious hallucinations. Some quoted genuine passages but lost the distinctions that tell an experienced reader what those passages mean and how much weight to give them.&lt;/p&gt;</description></item><item><title>Beyond Mogura Taiji Security</title><link>https://blog.mitcdh.au/posts/beyond-mogura-taiji-security/</link><pubDate>Wed, 17 Jun 2026 14:30:00 +0900</pubDate><guid>https://blog.mitcdh.au/posts/beyond-mogura-taiji-security/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted verbatim from a paper accepted and presented during &lt;a href="https://events.incose.org/event/symposium26/program"&gt;INCOSE IS 2026&lt;/a&gt; titled &amp;lsquo;Beyond Mogura Taiji Security&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/mona-h-1b92b040/"&gt;Mona Humes&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/markwinstead/"&gt;Mark Winstead&lt;/a&gt; and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;Organizations typically achieve cybersecurity compliance for nuclear and other critical infrastructure through established control-based guidance documents such as NIST SP 800-53, NIST SP 800-82, ISO 27001, and IEC 63096. This paper presents an engineering-driven methodology that leverages the INCOSE Guide to Security Needs and Requirements (GtSNR) and the trustworthy secure concepts and principles defined in NIST SP 800-160 Volume 1 Revision 1 to derive security needs and requirements for critical systems (CS) and critical digital assets (CDA). The resulting requirements are realized through security-informed architecture, design, and implementation, and the resulting engineered security capability might be later mapped to controls to represent and assess that capability for governance and compliance purposes, when needed. By applying systems security engineering (SSE) as defined in NIST SP 800-160 Vol 1 Rev 1 and INCOSE GtSNR selectively to systems and assets of highest consequence, the proposed approach supports incremental adoption, reduces implementation burden, and enhances alignment between systems engineering and security practices.&lt;/p&gt;</description></item><item><title>Why Nuclear Security Needs Information Security</title><link>https://blog.mitcdh.au/posts/nuclear-needs-information-security/</link><pubDate>Thu, 28 May 2026 19:00:00 +0300</pubDate><guid>https://blog.mitcdh.au/posts/nuclear-needs-information-security/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted verbatim from a paper accepted and presented during the &lt;a href="https://www.iaea.org/events/cybercon26"&gt;International Conference on Computer Security in the Nuclear World: Securing the Future&lt;/a&gt; titled &amp;lsquo;&lt;a href="https://conferences.iaea.org/event/428/contributions/38952/"&gt;Why Nuclear Security Needs Information Security: The Promise Of NST070&lt;/a&gt;&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/mike-stjohn-green-685b6163/"&gt;Mike StJohn-Green&lt;/a&gt; and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;Effective computer security requires information security. Computers, like humans, are actors on information and adversaries target the functions they perform by compromising the confidentiality, integrity, or availability (CIA) of the information itself.&lt;/p&gt;</description></item><item><title>Where to Start — the System or the Function?</title><link>https://blog.mitcdh.au/posts/where-to-start-system-or-function/</link><pubDate>Thu, 28 May 2026 18:00:00 +0300</pubDate><guid>https://blog.mitcdh.au/posts/where-to-start-system-or-function/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted verbatim from a paper accepted and presented during the &lt;a href="https://www.iaea.org/events/cybercon26"&gt;International Conference on Computer Security in the Nuclear World: Securing the Future&lt;/a&gt; titled &amp;lsquo;&lt;a href="https://conferences.iaea.org/event/428/contributions/39258/"&gt;Where To Start — The System Or The Function? How The V-Model Clarifies Effective Computer Security&lt;/a&gt;&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/mike-stjohn-green-685b6163/"&gt;Mike StJohn-Green&lt;/a&gt; and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;IAEA guidance on computer security calls for two levels of risk management, initially a function-based analysis followed by a systems-based analysis. This concept of multiple levels of risk analysis is also present in other computer security standards (IEC 62443, IEC 62645, NRC), although they differ on the details of whether a graded approach should consider impact, adversarial-skill, or likelihood. However, the most significant practical challenge in implementing this guidance is bridging the functions-systems analyses, resulting in a struggle to translate between impacts, risks, and vulnerabilities.&lt;/p&gt;</description></item><item><title>Achieving Resilience Through the Preservation of Functions</title><link>https://blog.mitcdh.au/posts/preserving-functions/</link><pubDate>Wed, 23 Oct 2024 18:00:00 +0300</pubDate><guid>https://blog.mitcdh.au/posts/preserving-functions/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted verbatim from a paper accepted and presented during the &lt;a href="https://www.iaea.org/events/smr2024"&gt;International Conference on Small Modular Reactors and their Applications&lt;/a&gt; titled &amp;lsquo;&lt;a href="https://conferences.iaea.org/event/374/contributions/31393/"&gt;Achieving Resilience Through the Preservation of Functions: Safety and Security Working Together&lt;/a&gt;&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/mike-stjohn-green-685b6163/"&gt;Mike StJohn-Green&lt;/a&gt; and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;Advanced nuclear reactors, including Small Modular Reactors, promise enhanced safety and efficiency by harnessing complex digital technologies. However, these innovations also introduce risk management challenges regarding the computer security vulnerability of complex digital components to malicious action, faults and failures. Current nuclear industry approaches to safety and security operate with system-centric views, focusing on individual system robustness and redundancy. This approach does not explicitly address functional interdependencies, potentially causing gaps in understanding and addressing threats and vulnerabilities, resulting in a less efficient approach and less resilient result.&lt;/p&gt;</description></item><item><title>Approaches for Comprehensive Safety and Digital Risk Management</title><link>https://blog.mitcdh.au/posts/advanced-nuclear-digital-risk-management/</link><pubDate>Wed, 23 Oct 2024 17:00:00 +0300</pubDate><guid>https://blog.mitcdh.au/posts/advanced-nuclear-digital-risk-management/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted verbatim from a paper accepted and presented during the &lt;a href="https://www.iaea.org/events/smr2024"&gt;International Conference on Small Modular Reactors and their Applications&lt;/a&gt; titled &amp;lsquo;&lt;a href="https://conferences.iaea.org/event/374/contributions/31390/"&gt;Approaches for Comprehensive Safety and Digital Risk Management for Advanced Nuclear Technology and Small Modular Reactors&lt;/a&gt;&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/joseph-mahanes-a2940b57/"&gt;Joseph Mahanes&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/bob-anderson-414a2834/"&gt;Bob Anderson&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/shannoneggers/"&gt;Shannon Eggers&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/mike-stjohn-green-685b6163/"&gt;Mike StJohn-Green&lt;/a&gt; and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;Small Modular Reactor (SMR) designs are likely to rely on complex digital technology novel to nuclear industry applications while also leveraging passive systems and safety design simplification. The result of current approaches may lead to a safety-driven system design that lacks demonstrated robustness in the event of cyber-attacks against its digital equipment. Information and computer security should be an integral part of engineering and operational processes. Current safety and security thinking does not encourage sufficient interaction. Teams are often separate and management structures reinforce this separation. This paper provides a case for cybersecurity related safety and digital engineering security requirements to be considered together throughout design, licensing, and operation. Safety envelope boundaries may be expressed using many variables and suitably defined system theoretic models can be used to alert whether due to faults, failures, or malicious action. This provides a unifying &amp;ldquo;top down&amp;rdquo; framework for digital systems and approaches supporting and implementing safety and security requirements. This paper will identify existing work supporting this closer relationship. However, new tools, techniques, and ways of working need developing to enable SMR designers, regulators and operators to employ complex digital technology in a way that remains both safe and secure.&lt;/p&gt;</description></item><item><title>Lighting the Way for My Father</title><link>https://blog.mitcdh.au/posts/candles-for-dave/</link><pubDate>Wed, 13 Mar 2024 14:05:55 +1100</pubDate><guid>https://blog.mitcdh.au/posts/candles-for-dave/</guid><description>&lt;p&gt;My father was a good man and I thought he would live forever, but on Monday, he passed away while I held his hand. I had flown to Australia to take him on a holiday next week and build in him the confidence to persevere as he began chemo. I had five precious days in Sydney by his side—where he was in good health, mobile, and unburdened by sickness. The end began in the morning with an ambulance, and I, along with his family and friends, spent those final hours with him as he fought to live for himself, to survive for us, and ultimately, to hold on long enough for everyone to arrive.&lt;/p&gt;</description></item><item><title>Empowering Computer Security Training with 'Learners'</title><link>https://blog.mitcdh.au/posts/introducing-learners/</link><pubDate>Thu, 01 Feb 2024 20:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/introducing-learners/</guid><description>&lt;p&gt;I&amp;rsquo;m excited to share an inside view of a newly released open-source training tool, which has become a significant part of our approach to advancing information and computer security training for nuclear security. Developed as a collaboration between the &lt;a href="https://iaea.org"&gt;International Atomic Energy Agency (IAEA)&lt;/a&gt; and the &lt;a href="https://www.ait.ac.at/"&gt;Austrian Institute of Technology (AIT)&lt;/a&gt;, &amp;lsquo;Learners&amp;rsquo; addresses specific education challenges in information and computer security.&lt;/p&gt;
&lt;p&gt;You can obtain a copy freely here: &lt;a href="https://github.com/iaeaorg/learners"&gt;https://github.com/iaeaorg/learners&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img class="content-image" src="https://blog.mitcdh.au/images/introducing-learners_02.webp" width="1920" height="1200" alt="Screenshot of the Learners interface" loading="lazy" decoding="async"&gt;

&lt;em&gt;The Learners interface, focus is on the content rather than the platform.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Automatically Generating Photo Box Galleries in Hugo</title><link>https://blog.mitcdh.au/posts/photo-box-galleries/</link><pubDate>Thu, 11 Jan 2024 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/photo-box-galleries/</guid><description>&lt;p&gt;I enjoy photography. I&amp;rsquo;ve intermittently used &lt;a href="https://flickr.com/people/mitcdh/"&gt;Flickr&lt;/a&gt; to upload pictures I&amp;rsquo;ve captured for a long time, I&amp;rsquo;m a big proponent of sharing my work too so any photos not featuring an obviously identifiable human subject I release under a Creative Commons license, typically CC BY-NC-ND. Having shifted my blog to Hugo, I was bored and thought I could do something creative.&lt;/p&gt;
&lt;p&gt;The concept of photo boxes sprang to mind – the sort you order that arrives brimming with pictures which you then splay out at various angles (let&amp;rsquo;s be honest, even with OCD, it&amp;rsquo;s probably impossible to get them straight). Such a tangible experience is deeply satisfying, and I thought, why not replicate this on the internet? Integrating a few services I use, particularly given Flickr&amp;rsquo;s user-friendly API, seemed straightforward.&lt;/p&gt;</description></item><item><title>A Reflection on Sydney Sands to Vienna Snows</title><link>https://blog.mitcdh.au/posts/sydney-sands-to-vienna-snows-a-reflection/</link><pubDate>Sat, 02 Dec 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/sydney-sands-to-vienna-snows-a-reflection/</guid><description>&lt;p&gt;Coming from the beaches of Sydney 🇦🇺, I remember thinking Melbourne was too cold for me, but little did I know that one day I&amp;rsquo;d find myself living through snowy European winters ☃️ over a holiday season that was before sun and sea to me 🏄🏻‍♂️☀️&lt;/p&gt;
&lt;p&gt;I saw snowfall for the first time in my life after moving to Vienna 🇦🇹 when I was 27. Now, cold winters are the norm. But I can&amp;rsquo;t help but stop sometimes and think about how far removed this is from where I saw my life before 🤔&lt;/p&gt;</description></item><item><title>Quick Build for Self-signed Certs</title><link>https://blog.mitcdh.au/posts/quick-build-for-self-signed-certs/</link><pubDate>Fri, 01 Dec 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/quick-build-for-self-signed-certs/</guid><description>&lt;p&gt;I work on many projects involving local installations running on environments not connected to the internet, primarily for training purposes. Now, so many times, I&amp;rsquo;ve seen a codebase where someone, somewhere, sometime long ago, generated a self-signed SSL certificate and then left it. It got sucked up into the version control, and then everyone everywhere deploying this tool uses the same certificate. It just makes me crazy.&lt;/p&gt;
&lt;p&gt;So I wanted to quickly build something to deal with this: &lt;a href="https://github.com/mitcdh/docker-build-certs"&gt;https://github.com/mitcdh/docker-build-certs&lt;/a&gt;&lt;/p&gt;</description></item><item><title>The Transformative Power of Loss and Love</title><link>https://blog.mitcdh.au/posts/the-transformative-power-of-loss/</link><pubDate>Fri, 04 Aug 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/the-transformative-power-of-loss/</guid><description>&lt;p&gt;🤔💭 A friend handed me this lamp, saying, &amp;ldquo;You inspire me. You make the world a better place. I want to make magic happen here with you, and this is just a little reminder of that&amp;rdquo;. I&amp;rsquo;ve spent weeks thinking about why that gesture affected me so profoundly, and I now understand.&lt;/p&gt;
&lt;p&gt;The universe is a place of balance, of equal and opposite reactions—where energy is neither created nor destroyed but transformed. Yet, when we think about the end of a life, it feels like a violation of this. The thoughts, ideas, experiences, and memories, the unrealised potential to affect the world and others who share it, all contained within a single being, seemingly vanish instantly. It&amp;rsquo;s hard to reconcile.&lt;/p&gt;</description></item><item><title>Hallstatt Adventures Behind the Lens</title><link>https://blog.mitcdh.au/posts/hallstatt-adventures-behind-the-lens/</link><pubDate>Wed, 26 Jul 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/hallstatt-adventures-behind-the-lens/</guid><description>&lt;p&gt;📸 Trapped behind my camera lens earlier in the season, I explored Hallstatt like a wide-eyed tourist. The quaint houses, the serene lake, the towering Alps - every shot could be a postcard. But as I looked around, I realised something 🤔💭&lt;/p&gt;
&lt;p&gt;I wasn&amp;rsquo;t merely a spectator. I have been part of a larger picture of friendship and shared experiences since 2019. Seeing the small Austrian village for the first time, my friends, travelling from across the world like I had before them, caught what matters in focus.&lt;/p&gt;</description></item><item><title>How Artificial Intelligence Will Change Information and Computer Security in the Nuclear World</title><link>https://blog.mitcdh.au/posts/artificial-intelligence-nuclear-world/</link><pubDate>Mon, 26 Jun 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/artificial-intelligence-nuclear-world/</guid><description>&lt;p&gt;&lt;em&gt;This article was originally published in the &lt;a href="https://www.iaea.org/bulletin/64-2"&gt;June 2023 IAEA Bulletin&lt;/a&gt; titled Computer Security in a Nuclear World. The only modification has been to replace the cover image.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Artificial intelligence (AI) and machine learning technologies could potentially revolutionize the world, ushering in unprecedented progress and innovation by transforming how we create, consume and use information. As AI technologies become increasingly sophisticated, they will transform industries, streamline processes and may even impact how we live our lives. The nuclear sector is no exception, and the benefits of AI can be expected in many processes and operations in nuclear and radiological facilities.&lt;/p&gt;</description></item><item><title>Supporting Flexible and Engaging Computer Security Training Courses with the Online Learners Platform and Hands-on Exercises</title><link>https://blog.mitcdh.au/posts/online-learning-platform-paper/</link><pubDate>Fri, 23 Jun 2023 18:06:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/online-learning-platform-paper/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted with only formatting changes from a paper accepted and presented by &lt;a href="https://www.linkedin.com/in/lenhard-reuter-4a170aaa/"&gt;Lenhard Reuter&lt;/a&gt; during CyberCon23 titled &amp;lsquo;Supporting Flexible and Engaging Computer Security Training Courses with the Online Learners Platform and Hands-on Exercises&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/lenhard-reuter-4a170aaa/"&gt;Lenhard Reuter&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/b3n4kh/"&gt;Benjamin Akhras&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/david-allison-infosec/"&gt;David Allison&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/agronbajraktari/"&gt;Agron Bajraktari&lt;/a&gt;, &lt;a href="http://www.lac.usp.br/~rpm/english/index.html"&gt;Ricardo Paulino Marques&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/francesca-soro-40601b148/"&gt;Francesca Soro&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/paul-smith-2aa618297/"&gt;Paul Smith&lt;/a&gt;, and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;The IAEA provides training courses that have the goal of raising awareness of computer security issues that are associated with nuclear facilities and those associated with radioactive materials. As part of this goal, the courses aim to deliver &lt;em&gt;affective&lt;/em&gt; learning outcomes — in other words, outcomes that motivate the need for computer security and change attitudes toward the topic. To help achieve this, hands-on (practical) exercises are an ingredient of courses, using equipment and systems that are representative of those found in the field and show the functional consequences of cyber-attacks. To support these outcomes, the International Atomic Agency (IAEA) and AIT Austrian Institute of Technology have initiated a joint activity to develop an online learning platform and hands-on exercises that can be hosted on a cyber range — a virtual environment, which can be used to conduct computer security exercises and training. In this paper, we present an overview of this activity and describe the &lt;em&gt;Learners&lt;/em&gt; platform — a learning management system — and give an overview of the cyber range-based hands-on exercises that are being developed.&lt;/p&gt;</description></item><item><title>Safety Versus Security</title><link>https://blog.mitcdh.au/posts/safety-vs-security/</link><pubDate>Fri, 23 Jun 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/safety-vs-security/</guid><description>&lt;p&gt;&lt;em&gt;This article has been adapted verbatim from a paper accepted and presented during &lt;a href="https://www.iaea.org/events/cybercon23"&gt;CyberCon23&lt;/a&gt; titled &amp;lsquo;Safety versus Security: What’s the difference and why it matters&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/samuelclements/"&gt;Samuel Clements&lt;/a&gt;, &lt;a href="https://www.linkedin.com/in/mike-stjohn-green-685b6163/"&gt;Mike StJohn-Green&lt;/a&gt; and myself.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="1-abstract"&gt;1. Abstract&lt;/h2&gt;
&lt;p&gt;In the “Safety-First” culture of the nuclear industry, the nuanced differences between security and safety can be lost. The use of powerful software-programmable digital technology provides the means to transform instrumentation and control systems, but also provides unparalleled opportunity for malicious action by criminals and others.&lt;/p&gt;</description></item><item><title>Is “Cyber Security” Harmful?</title><link>https://blog.mitcdh.au/posts/cyber-security-considered-harmful/</link><pubDate>Tue, 21 Mar 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/cyber-security-considered-harmful/</guid><description>&lt;p&gt;Put down your tar and pitchforks. The activities connotated with &amp;ldquo;cyber security&amp;rdquo; are vital to avoid the worst consequences of malicious acts that could target computer-based systems. After all, we live in an era where computers are the predominant means we consume information, forming the basis of our knowledge and subsequent actions.&lt;/p&gt;
&lt;p&gt;I have been fortunate to work on nationally significant critical infrastructure where we developed function-centric approaches to computer security. Leveraging that experience, I have spent much of my career either working in support of or directly for an international organisation on the proposal, establishment, drafting, consensus building, and maintenance of internationally recognised consensus guidance documents on &amp;ldquo;information and computer security&amp;rdquo;.&lt;/p&gt;</description></item><item><title>Building a Custom Landing Page</title><link>https://blog.mitcdh.au/posts/building-a-custom-landing-page/</link><pubDate>Mon, 20 Mar 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/building-a-custom-landing-page/</guid><description>&lt;p&gt;I am a big proponent of portability in IT. In that regard, personal custom email domains are great; they let you easily change the backend email provider you use while maintaining a single identity to the rest of the world. You&amp;rsquo;re not tied to Gmail/Yahoo/Hotmail but something uniquely you.&lt;/p&gt;
&lt;p&gt;But what happens when someone tries to browse a website associated with your email? Having something to show them is excellent, and it&amp;rsquo;s not that hard. To get started on building a quick landing page, I set out a couple of objectives to hit:&lt;/p&gt;</description></item><item><title>A Primer on Subverting AI/ML</title><link>https://blog.mitcdh.au/posts/a-primer-on-subverting-ai-ml/</link><pubDate>Fri, 10 Mar 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/a-primer-on-subverting-ai-ml/</guid><description>&lt;p&gt;Artificial Intelligence/Machine Learning (AI/ML) models need more transparency and explainability, the lack of which makes it difficult to understand how they arrive at their conclusions and can degrade security. While achieving transparency and explainability can be challenging, failing to do so can require users of the AI/ML models to place blind trust in their output. When such AI/ML models are relied upon without considering how they can be subverted through a malicious act, there is a risk of weakening overall defence-in-depth.&lt;/p&gt;</description></item><item><title>Rethinking Security: Function-based Protection Against Malice</title><link>https://blog.mitcdh.au/posts/rethinking-security-function-based-protection-against-malice/</link><pubDate>Wed, 08 Mar 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/rethinking-security-function-based-protection-against-malice/</guid><description>&lt;p&gt;The concept of security is highly subjective and varies greatly depending on individual perceptions of the functional space and its known threats; this does not need to be the case. Physical security, personnel security, insider threat mitigation, information and computer security, engineered systems and business process design all contribute to a comprehensive security framework. Experts from each area may unintentionally prioritise the importance of their specific expertise &amp;mdash; protection against known threats will always seem more critical than unknown ones.&lt;/p&gt;</description></item><item><title>Harnessing Visualisation Because Maps</title><link>https://blog.mitcdh.au/posts/harnessing-visualisation-maps/</link><pubDate>Fri, 17 Feb 2023 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/harnessing-visualisation-maps/</guid><description>&lt;p&gt;Working for an international organisation, I&amp;rsquo;m constantly in a cycle of forward planning and trying to optimise global impact. There are a number of data sets that can help with this&amp;mdash;for example, all of the countries with certain types of infrastructure&amp;mdash;but they require a degree of piecing together.&lt;/p&gt;
&lt;p&gt;Some of the problems I&amp;rsquo;ve faced:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;There is no central data repository and a possible resistance to producing one.&lt;/li&gt;
&lt;li&gt;Different databases might use different formats, e.g., country names or ISO codes.&lt;/li&gt;
&lt;li&gt;Sometimes unstructured data is provided, which may reflect the contributor&amp;rsquo;s biases, e.g., alternate or unofficial country names.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This can make effective planning kind of hard. I want maps. I love maps. So why not build a map? I&amp;rsquo;ve created a small tool to do exactly that, which is available here: &lt;a href="https://mitcdh.github.io/cb2geochart/"&gt;https://mitcdh.github.io/cb2geochart/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Friendships Take Flight</title><link>https://blog.mitcdh.au/posts/friendships-take-flight/</link><pubDate>Mon, 05 Dec 2022 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/friendships-take-flight/</guid><description>&lt;p&gt;On a flight from Vienna to London, we struck up a conversation that changed the course of our journeys, particularly when we knew both our connecting flights were delayed. As the plane soared above the clouds, we shared stories of our travels and dreams, forming an instant connection. Little did we know that this chance encounter would leave a mark on our lives.&lt;/p&gt;
&lt;p&gt;Months later, in the heart of Seattle, we reunited under the city&amp;rsquo;s grey skies. The months apart had only strengthened our bond, and it felt like no time had passed. We explored the city&amp;rsquo;s coffee shops, braved the drizzling rain, and laughed as if we had known each other for a lifetime, all in a one-day stopover.&lt;/p&gt;</description></item><item><title>Nostalgia, Beaches, and Embracing the Present</title><link>https://blog.mitcdh.au/posts/nostalgia-beach/</link><pubDate>Mon, 17 Jan 2022 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/nostalgia-beach/</guid><description>&lt;p&gt;💭 What is nostalgia? Some of my best memories of family and friends, ones I can never recreate, were made at these three beaches 🏄‍♂️&lt;/p&gt;
&lt;p&gt;These Days 🎶 I have found myself living on the other side of the world in a landlocked country with no beaches or kangaroos 🇦🇹 When I feel the pressures of life, I think back to these moments.&lt;/p&gt;
&lt;p&gt;Now, for the first time in years, I relive this— to breathe that same sea breeze, feel my feet sink into the sand as the wave returns, and taste the salt. That makes me think 🤔&lt;/p&gt;</description></item><item><title>A Journey with the Sea</title><link>https://blog.mitcdh.au/posts/a-journey-with-the-sea/</link><pubDate>Wed, 30 Jun 2021 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/a-journey-with-the-sea/</guid><description>&lt;p&gt;There&amp;rsquo;s a special allure in riding at the front of the boat, where the world seems to open up with endless possibilities. Here, the salty breeze is a gentle whisper and a vibrant, living force. It rushes towards me, carrying the essence of the sea, a symphony of brine and freedom.&lt;/p&gt;
&lt;p&gt;As the boat slices through the waves, the wind greets me first, unfiltered and exhilarating. It&amp;rsquo;s a place of privilege where the ocean spray kisses my face, and the horizon stretches infinitely. Each journey becomes a personal dialogue with the elements, where the sea&amp;rsquo;s breath becomes my guide.&lt;/p&gt;</description></item><item><title>Finding Family in Italia</title><link>https://blog.mitcdh.au/posts/finding-family-in-italia/</link><pubDate>Mon, 28 Dec 2020 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/finding-family-in-italia/</guid><description>&lt;p&gt;In Italy, amidst the rolling hills and vibrant streets, I discovered something unexpected and profoundly touching—people who embraced me like family. Growing up, because of everyone going in different directions after a shared traumatic experience, I often felt a sense of distance from my own family, a subtle but persistent disconnect that left a void in my heart.&lt;/p&gt;
&lt;p&gt;But in Italy, that void began to heal. The people I met there, with their open arms and generous hearts, showed me what it felt like to be part of a family. From shared meals under the stars on a boat, where laughter and stories flowed as freely as the local wine, to quiet moments of understanding and companionship between the early morning rises at Christmas, they filled my days with a sense of belonging. Each gesture, whether a comforting word in times of need or a shared joke, wove a tapestry of familial love that transcended blood ties.&lt;/p&gt;</description></item><item><title>Scaling Heights on a Klettersteig Journey</title><link>https://blog.mitcdh.au/posts/scaling-heights-on-a-klettersteig/</link><pubDate>Sat, 08 Aug 2020 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/scaling-heights-on-a-klettersteig/</guid><description>&lt;p&gt;I embarked on the ascent, my hands gripping the cold metal of the klettersteig, each step a testament to the delicate balance between trust and skill. The route wound up the rugged cliffs of the Salzkammergut, revealing vistas of serene lakes nestled like hidden treasures in the valley below. With every meter I climbed, the landscape unfurled its grandeur – rugged peaks crowned with snow, lush forests in myriad shades of green, and the distant twinkle of quaint villages.&lt;/p&gt;</description></item><item><title>Secure Enterprise Integration for Multipurpose Research Reactors</title><link>https://blog.mitcdh.au/posts/reactor-enterprise-integration/</link><pubDate>Fri, 08 Dec 2017 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/reactor-enterprise-integration/</guid><description>&lt;p&gt;&lt;em&gt;This post has been adapted verbatim from a paper accepted and presented during &lt;a href="https://www.igorr.com/"&gt;International Group on Research Reactors (IGORR) 2017&lt;/a&gt; titled &amp;lsquo;Secure Enterprise Integration for Multipurpose Research Reactors&amp;rsquo; authored by &lt;a href="https://www.linkedin.com/in/nickhowarth/"&gt;Nick Howarth&lt;/a&gt;, myself, Christina Hunt, and &lt;a href="https://www.linkedin.com/in/anthony-noonan-09732364/"&gt;Anthony Noonan&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;The OPAL research reactor operated by the Australian Nuclear Science and Technology Organisation (ANSTO) is a multi-purpose scientific and manufacturing facility. Information produced by the reactor&amp;rsquo;s operational technology (OT) systems is relied upon by engineering, scientific, and manufacturing information systems.&lt;/p&gt;</description></item><item><title>Security Management of Virtualised Supervisory I&amp;C Systems in Nuclear Facilities</title><link>https://blog.mitcdh.au/posts/virtualised-security-management/</link><pubDate>Thu, 30 Nov 2017 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/virtualised-security-management/</guid><description>&lt;p&gt;&lt;em&gt;This post has been adapted verbatim from a paper accepted and presented during &lt;a href="https://www.isofic.org/"&gt;ISOFIC 2017&lt;/a&gt; titled &amp;lsquo;Security Management of Virtualised Supervisory I&amp;amp;C Systems in Nuclear Facilities&amp;rsquo; authored by myself &lt;a href="https://www.linkedin.com/in/nickhowarth/"&gt;Nick Howarth&lt;/a&gt;, Christina Hunt, and &lt;a href="https://www.linkedin.com/in/anthony-noonan-09732364/"&gt;Anthony Noonan&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id="1-introduction"&gt;1 Introduction&lt;/h2&gt;
&lt;p&gt;Instrumentation and Control (I&amp;amp;C) systems in nuclear facilities provide information and control capabilities for the operation of the plant in operational states and in accident conditions&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt;. I&amp;amp;C system vendors are continuing to adopt virtualisation technologies in their product offerings. Consequently, nuclear facilities will continue to expand the use of virtualised I&amp;amp;C systems. In this paper we review a number of out of band security management techniques available to nuclear I&amp;amp;C operators when responding to an incident on virtualised I&amp;amp;C systems.&lt;/p&gt;</description></item><item><title>Building and Breaking the Protection Provided by an Optical Data Diode</title><link>https://blog.mitcdh.au/posts/breaking-data-diode/</link><pubDate>Thu, 04 Jun 2015 18:05:55 +0300</pubDate><guid>https://blog.mitcdh.au/posts/breaking-data-diode/</guid><description>&lt;p&gt;&lt;em&gt;This post has been adapted verbatim from a paper accepted and presented during &lt;a href="https://www-pub.iaea.org/iaeameetings/46530/international-conference-on-computer-security-in-a-nuclear-world-expert-discussion-and-exchange"&gt;International Conference on Computer Security in a Nuclear World: Expert Discussion and Exchange&lt;/a&gt; titled &amp;lsquo;Building and Breaking the Protection Provided by an Optical Data Diode Using Spare Parts&amp;rsquo; authored by myself &lt;a href="https://www.linkedin.com/in/danielgleesontechie/"&gt;Daniel Gleeson&lt;/a&gt;, and &lt;a href="https://www.linkedin.com/in/ben-donovan-au/"&gt;Ben Donovan&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;!-- table-of-contents-marker --&gt;
&lt;h2 id="abstract"&gt;Abstract&lt;/h2&gt;
&lt;p&gt;This paper presents an overview of the construction and implementation of unidirectional networking through an optical fibre data diode while demonstrating post-implementation issues that need to be addressed to ensure the desired protection is provided.  This particular topic was chosen due to its relevance for nuclear facility operators.  Nuclear Security Series 17 highly encourages no inwards data flow of any kind to Level 1 systems.  Technical solutions are provided on implementing select applications that require stateful network protocols over the constructed unidirectional link. The paper stresses that there are further issues around implementing a data diode that are shared with both entirely connected and disconnected networks. Where a lack of a robust security culture on the more protected segment can lead to a compromise of the additional integrity protection that the data diode provides.  Throughout detail is provided that is accessible and easily understandable to various skill levels in networking, programming, and control system design; empowering operators and practitioners with a greater understanding of the optical diode technology and its implementation.  The design of the optical fibre diode, the software created in overcoming the requirement for stateful networking, and details of a covert device allowing foreign input will all be provided as technical resources. Where possible physical components are constructed with spare parts that would likely be found in a converged Industrial Control and Information Technology environment.&lt;/p&gt;</description></item></channel></rss>