Research // Agenda

Cyber-Resilience Under Isolation

Most cybersecurity guidance quietly assumes a connected, cooperating country — one that can buy the tooling, join the frameworks, call the vendor. These two working papers study what happens when those assumptions are removed, and who can be held to account when a government removes them on purpose.

Why this agenda

This isn't academic curiosity — it grew out of lived facts. My bachelor's thesis examined VPN solutions for peer-to-peer content delivery under national network restrictions, including fieldwork with people who depended on those workarounds to reach their own families. Later I experienced national-scale internet shutdowns from the inside, running a consulting practice through them. My current MA in International Relations adds the regional and institutional lens the technical training alone never provided. Both papers are living working papers, developed alongside my graduate study, with the same standing rule: strictly policy-analytical, the unit of study is the system and the institution, and every claim is verifiable or explicitly flagged as open.

Related writing on this site

The blog develops these strands in public, deliberately in the open, piece by piece — starting with Why Isolated States Build Cyber-Resilience Differently, and continuing through the governance and region-focused series. If you research adjacent questions — shutdowns, CIIP frameworks, CSIRT capacity, digital sovereignty — I'd genuinely like to compare notes.