Research // Agenda
Cyber-Resilience Under Isolation
Most cybersecurity guidance quietly assumes a connected, cooperating country — one that can buy the tooling, join the frameworks, call the vendor. These two working papers study what happens when those assumptions are removed, and who can be held to account when a government removes them on purpose.
Working papers
-
Internet Shutdowns as a Governance Instrument, and What Could Hold Them Accountable
When a government shuts down the internet, the same actor gives the order, controls the network, owns the evidence, and writes the law it's judged against — a concentration of power ordinary oversight can't reach. This paper maps seven accountability mechanisms against that gap and proposes a layered framework for which ones can actually constrain a state that controls the switch.
-
Cyber-Resilience Under Isolation
Isolation doesn't just make cybersecurity harder — it changes the shape of the problem. This paper traces four strands (comparative resilience models, shutdowns as infrastructure failure, minimum-viable incident response, and the security supply chain under sanctions) to ask what states build instead, and at what cost.
Why this agenda
This isn't academic curiosity — it grew out of lived facts. My bachelor's thesis examined VPN solutions for peer-to-peer content delivery under national network restrictions, including fieldwork with people who depended on those workarounds to reach their own families. Later I experienced national-scale internet shutdowns from the inside, running a consulting practice through them. My current MA in International Relations adds the regional and institutional lens the technical training alone never provided. Both papers are living working papers, developed alongside my graduate study, with the same standing rule: strictly policy-analytical, the unit of study is the system and the institution, and every claim is verifiable or explicitly flagged as open.
Related writing on this site
The blog develops these strands in public, deliberately in the open, piece by piece — starting with Why Isolated States Build Cyber-Resilience Differently, and continuing through the governance and region-focused series. If you research adjacent questions — shutdowns, CIIP frameworks, CSIRT capacity, digital sovereignty — I'd genuinely like to compare notes.