<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Digital Promises on Digital Infrastructures at Scale</title>
    <link>https://digitalinfrastructures.nl/</link>
    <description>Recent content in Digital Promises on Digital Infrastructures at Scale</description>
    <generator>Hugo -- 0.148.0</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 28 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://digitalinfrastructures.nl/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Multiparty Promises</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/promise-multiparty/</link>
      <pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/promise-multiparty/</guid>
      <description>&lt;p&gt;Promise theory helps us understand commitments that actors make.
The basic interaction handles one transaction, as we saw earlier.
But there are many variations.&lt;/p&gt;
&lt;p&gt;Instead of just having a single transaction, you can have a sequence, through the &amp;ldquo;subscribe&amp;rdquo; pattern.
In this pattern, the provider says: &amp;ldquo;I promise to update you whenever something interesting happens, until you unsubscribe, or I am finished.&amp;rdquo;
Interest could derive from a specific event, or just enough time having passed.
Examples include subscribing to a magazine or newsletter.
Under the hood of chatbots there is often also a subscription at work, where the LLM gradually delivers your answer as it is being produced (&amp;ldquo;completion&amp;rdquo;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Automation Business Case</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/automation-business-case/</link>
      <pubDate>Wed, 12 Aug 2026 19:59:30 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/automation-business-case/</guid>
      <description>&lt;p&gt;Automation is a big part of IT, but not all automation brings value.
Automation takes time and effort, upfront, and any benefits come later.&lt;/p&gt;
&lt;p&gt;Think of the IT projects you were involved in, most of those aimed at providing a measurable benefit somewhere.&lt;/p&gt;
&lt;p&gt;This diagram (from xkcd, a series of webcomics) illustrates when automating repetitive tasks, or even just parts of them, brings benefit.
In other words, is there a &lt;em&gt;business case&lt;/em&gt; for such an intervention?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why we signed the cloud deal</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/the-solvency-ii-deadline/</link>
      <pubDate>Mon, 03 Aug 2026 11:24:29 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/the-solvency-ii-deadline/</guid>
      <description>&lt;p&gt;Let&amp;rsquo;s look at a realistic and uncommon story of cloud and outsourcing.
It illustrates what value a customer got and how they got there.&lt;/p&gt;
&lt;p&gt;Aegon Levensverzekering N.V. is a life insurance company that needed to comply with what&amp;rsquo;s called the Solvency II regulation,
which required reporting the net-present-value (NPV) estimate of its entire life-policy portfolio,
millions of policies across thousands of scenarios.
The Dutch regulator is worried that the insurer might not be capable of honoring the life insurance policies.
There are many scenario&amp;rsquo;s: changing retirement ages, changing life expectancies, changing interest rates and investment returns.
Off the shelf scenario-based actuarial risk-modeling software exists to do this, but the compute requirement is pretty big.
This requires a high performance compute environment with hundreds of CPUs, for several weeks, every quarter.
But outside of that batch, all the machines are idle.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Real Story Behind the OpenAI &#39;Escape&#39;</title>
      <link>https://digitalinfrastructures.nl/posts/open-escape/</link>
      <pubDate>Sat, 01 Aug 2026 19:28:46 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/open-escape/</guid>
      <description>&lt;p&gt;An unnamed OpenAI model allegedly &amp;lsquo;broke out&amp;rsquo; and &amp;rsquo;escaped into the wild&amp;rsquo; from its &amp;lsquo;highly isolated sandbox&amp;rsquo; and then hacked Hugging Face.
The story is all over the internet warning about the power of current day LLMs.
But that is not what happened.&lt;/p&gt;
&lt;p&gt;Don&amp;rsquo;t let popular trade press stories confuse you.
They can be nice cyberpunk narratives, they may be interesting PR, but they do little to give you actionable advice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Software Dissemination</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/software-dissemination/</link>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/software-dissemination/</guid>
      <description>&lt;h3 id=&#34;how-software-grows&#34;&gt;How software grows&lt;/h3&gt;
&lt;p&gt;A lot of software begins its life as the project of an individual, but ends up being used widely in organizations, or even society at large.&lt;/p&gt;
&lt;p&gt;I have seen many Excel files that started out as a small set of notes and grew to be the operational backbone of entire departments.
Examples I have seen include complete bookkeeping ledgers, customer relationship systems, and planning tools.
And the allure of tools such as Excel, Airtable, et cetera, is that they are flexible, and don&amp;rsquo;t require a skilled programmer to update them.
The risk there, though, is that as the software grows in importance, its governance does not necessarily keep up.
More specifically, there are specific thresholds that, when crossed, cause specific new risks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Counting the copies: how an AI wiki helped me read my father&#39;s digital legacy</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/an-infra-dedup-story/</link>
      <pubDate>Sun, 28 Jun 2026 10:41:46 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/an-infra-dedup-story/</guid>
      <description>&lt;h3 id=&#34;the-root-cause&#34;&gt;The root cause&lt;/h3&gt;
&lt;p&gt;In the 1990s my father&amp;rsquo;s health deteriorated as a result of what was later thought to be some
immune system related disease.
He found out that living in warm climates with little pollution and no need to stay indoors for very long helped him maintain his health.
So he took a bold move, sold his house, and became a traveling academic.
In the summers he would stay in the south of France where we visited him, in the shoulder seasons he lived on one of the Canary Islands, and in the winter months he traveled to the southern hemisphere (Chile, Africa, Australia).
Jokingly he called himself a &amp;ldquo;refugié pollutique&amp;rdquo;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Benchmarking Local Coding Models</title>
      <link>https://digitalinfrastructures.nl/posts/local-coding-models/</link>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/local-coding-models/</guid>
      <description>&lt;h1 id=&#34;can-ibms-granite-41-code-i-ran-it-against-other-local-models-to-find-out&#34;&gt;Can IBM&amp;rsquo;s Granite 4.1 code? I ran it against other local models to find out&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;Full transparency&lt;/strong&gt;: Except for some initial prompting, most of this blog and the research behind it was AI generated. I did check everything manually though.
While I tried to include all relevant files in &lt;a href=&#34;https://github.com/pve/local-model-coding&#34;&gt;this repo&lt;/a&gt;, reproducibility may be hampered by some of my older Claude contexts leaking into this process (e.g. about how opinionated I can be).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Digital autonomy: Controls</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/digital-autonomy-controls/</link>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/digital-autonomy-controls/</guid>
      <description>&lt;p&gt;Suppose you are a government, a regulator, or a concerned cloud consumer.
What can you actually do to mitigate sovereignty risks and achieve adequate autonomy?&lt;/p&gt;
&lt;p&gt;The honest starting point is that full digital autonomy, autarky, is not achievable, and not worth pursuing.
Read &lt;a href=&#34;https://digitalinfrastructures.nl/posts/digital-autonomy-autarky/&#34;&gt;here for more on that&lt;/a&gt;.
No well-developed country is fully independent of others.
The goal is not independence, but resilience: reducing the negative effects of dependence, and preserving options.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Prisoner&#39;s Dilemma</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/prisoners-dilemma/</link>
      <pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/prisoners-dilemma/</guid>
      <description>&lt;h3 id=&#34;the-game-of-trust&#34;&gt;The game of trust&lt;/h3&gt;
&lt;p&gt;How do people establish trust under the most adverse circumstances?
How can sworn enemies get into a position that it makes sense for them to help each other.&lt;/p&gt;
&lt;p&gt;In game theory, this is the surprising phenomenon that the prisoner&amp;rsquo;s dilemma aims to explain.&lt;/p&gt;
&lt;p&gt;Imagine two suspects held by the police who don&amp;rsquo;t have enough evidence against them.
Their choices (game moves) are to confess or stay silent.
If they help each other by staying silent, they will both get a positive pay-off: they will be free.
If one confesses, and therefore betrays the other, the second one will go to prison for a longer time than the first one.
If they both confess, they will both go to prison.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Digital autonomy: Autarky</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/digital-autonomy-autarky/</link>
      <pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/digital-autonomy-autarky/</guid>
      <description>&lt;h3 id=&#34;autarky&#34;&gt;Autarky&lt;/h3&gt;
&lt;p&gt;Implicit in many discussions on digital autonomy is the quest for &amp;ldquo;autarky&amp;rdquo;, being completely independent from other actors, for example those actors whose objectives may be in conflict with ours.
This is driving the call for national cloud providers, local manufacturing, and more open source, to name just a few.&lt;/p&gt;
&lt;p&gt;Autarky, however, is just one tool for establishing autonomy, and a very difficult one as well.&lt;/p&gt;
&lt;p&gt;Economic history shows that no well-developed country is in a state of autarky.
For example, in World War II, England was heavily dependent on transatlantic shipping convoys for its supplies, including food.
This should be familiar to anybody who has studied the role of Alan Turing and others at Bletchley Park in deciphering the German military code (Enigma) that threatened those convoys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Digital autonomy: The risks</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/digital-autonomy-the-risks/</link>
      <pubDate>Wed, 13 May 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/digital-autonomy-the-risks/</guid>
      <description>&lt;p&gt;Many people think we are overly dependent on big tech, and we should be more autonomous and sovereign.
Fewer can say what exactly is the risk here.
Digital autonomy and sovereignty form a wicked problem: its parts are intertwined with many
other issues and conflicting interests, so there is no clean solution.
Before
reaching for solutions, it pays to be precise about the risk.&lt;/p&gt;
&lt;p&gt;At risk is our power to decide which data flows where, a power exercised through
control over digital infrastructures such as cloud and social media.
The risk,
then, is what happens when that power sits with someone else.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Digital Autonomy: the Actors</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/digital-autonomy-the-actors/</link>
      <pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/digital-autonomy-the-actors/</guid>
      <description>&lt;p&gt;Achieving some form of digital autonomy or sovereignty is a &lt;a href=&#34;https://digitalinfrastructures.nl/posts/wicked-2026/&#34;&gt;wicked problem&lt;/a&gt;, too large to handle in one go.
Let&amp;rsquo;s start therefore with the main actors, and what is at stake for them.
We can then talk about how digital autonomy allows these actors to collaborate and compete, and therefore impacts the risks they see.
Elsewhere, I write about &lt;a href=&#34;https://digitalinfrastructures.nl/book/act4-power/international-actors/&#34;&gt;international actors&lt;/a&gt;, and this story builds on that.&lt;/p&gt;
&lt;p&gt;All actors (e.g. governments, companies) perceive IT risk in their own way.
Generally though, they include the standard IT risks (confidentiality, integrity, and availability).
Beyond that, there is the risk of failing to capture the value of new technology, and failure to exercise governance and control over relevant other actors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A badge on the wall</title>
      <link>https://digitalinfrastructures.nl/posts/mch2022-badge-repurposed/</link>
      <pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/mch2022-badge-repurposed/</guid>
      <description>&lt;h2 id=&#34;a-badge-on-the-wall-repurposing-hacker-camp-hardware-as-a-home-energy-display&#34;&gt;A badge on the wall: repurposing hacker camp hardware as a home energy display&lt;/h2&gt;
&lt;p&gt;I wanted a wall display for my house&amp;rsquo;s energy. Not an app, but something glanceable, always on, no clicks required.
Apparently that&amp;rsquo;s harder to buy than it sounds.&lt;/p&gt;
&lt;p&gt;On a sunny day, it makes sense to turn on energy-intensive appliances such as washing machines, because the energy surplus from our solar panels earns us almost nothing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why You Work: Amateur, Professional, or Passionate?</title>
      <link>https://digitalinfrastructures.nl/posts/am-prof/</link>
      <pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/am-prof/</guid>
      <description>&lt;p&gt;Have you ever been called an amateur? It stings. It shouldn&amp;rsquo;t be.&lt;/p&gt;
&lt;h3 id=&#34;amateurs&#34;&gt;Amateurs&lt;/h3&gt;
&lt;p&gt;The label &amp;lsquo;amateur&amp;rsquo; has a negative feel, it refers to unskilled workers, hobbyists, and poor results.
But the word actually derives from the Latin &amp;lsquo;amare&amp;rsquo;, meaning to love.
So an amateur is somebody who is doing it for the love of it.&lt;/p&gt;
&lt;p&gt;They come to their work for play, for fun, and discovery.
When it comes to the quality of their work, they are setting the bar for themselves only.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Local AI inferencing or cloud based?</title>
      <link>https://digitalinfrastructures.nl/posts/local-ai-pendulum/</link>
      <pubDate>Sat, 07 Mar 2026 14:24:22 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/local-ai-pendulum/</guid>
      <description>&lt;p&gt;I am trying to figure out where the pendulum for AI LLM inference hosting will swing to.&lt;/p&gt;
&lt;p&gt;Will we have more cloud service usage of the cloud hyperscalers, or will inferencing be on local devices such as laptops or in corporate datacenter?&lt;/p&gt;
&lt;p&gt;Here is my thinking.&lt;/p&gt;
&lt;p&gt;I believe Moore’s law will be relevant for a few more years, implying that an affordable supply of local capacity will grow.&lt;/p&gt;
&lt;p&gt;I also believe that there is a minimum LLM size to make them functional, in the same way that there is a minimum number of bytes for a decent picture or audible sound. But above a certain size, there is going to be a diminishing return.
Depending on the scenario, we are talking about billions to trillions of parameters in the LLM.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Architectural Integrity, Angkor Wat, and open source</title>
      <link>https://digitalinfrastructures.nl/posts/architecture-integrity/</link>
      <pubDate>Fri, 06 Feb 2026 07:31:06 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/architecture-integrity/</guid>
      <description>&lt;p&gt;Angkor Wat (Cambodia) is the world&amp;rsquo;s largest religious building and site.
Built in the 12th century, it is still a stunning building, featuring high symmetry and perfect north-south alignment.&lt;/p&gt;
&lt;p&gt;As I was visiting this and other temples, I got to think about architectural integrity.
For example, Angkor Wat has 4 major towers around a central tower.
I call that an architectural feature.&lt;/p&gt;
&lt;p&gt;Symmetry like this does not happen automatically.
It takes an architect and good execution, in other words carefully controlled power, to realize this.
As a visitor, you notice, maybe only subconsciously, that great power was required to construct such a building.
The building is a symbol of power.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How are AI Agents Self Aware?</title>
      <link>https://digitalinfrastructures.nl/posts/agent-self-aware/</link>
      <pubDate>Wed, 04 Feb 2026 08:56:29 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/agent-self-aware/</guid>
      <description>&lt;p&gt;I was chatting with an AI agent about its own configuration,
and it answered with surprising confidence.&lt;/p&gt;
&lt;p&gt;Then I thought: wait. How would it even know that?&lt;/p&gt;
&lt;p&gt;This post is about what I found when I went looking.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://github.com/HKUDS/nanobot&#34;&gt;Nanobot&lt;/a&gt;
is a deliberately simpler version of &lt;a href=&#34;https://openclaw.ai&#34;&gt;OpenClaw&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you haven&amp;rsquo;t heard about it, OpenClaw is an AI agent running on your behalf 24/7, potentially having all your credentials.
This is possibly the piece of software with the steepest adoption curve of all time, it got to over 1 million active users in 1 week.
Potentially it is also one of the biggest IT security dramas of all time.
Because the more powerful they are, the more risky they become.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Securing my AI travel mail bot</title>
      <link>https://digitalinfrastructures.nl/posts/travel-mail-bot/</link>
      <pubDate>Fri, 23 Jan 2026 09:55:29 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/travel-mail-bot/</guid>
      <description>&lt;p&gt;I wanted to experiment with AI automation while also paying particular attention to security concerns.
Security is something I take seriously (I delivered cloud security training for more than 10 years), and the power that AI has is very scary.&lt;/p&gt;
&lt;p&gt;There are lots of frameworks related to AI security, and I feel that it is hard to apply them to the real world.&lt;/p&gt;
&lt;p&gt;For example how would you mitigate LLM06 – Sensitive Information Disclosure, or ASI05 - Inadequate Guardrails and Sandboxing from the OWASP guidelines?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wicked problems in 2026</title>
      <link>https://digitalinfrastructures.nl/posts/wicked-2026/</link>
      <pubDate>Thu, 25 Dec 2025 00:39:13 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/wicked-2026/</guid>
      <description>&lt;p&gt;As 2025 ends, I reflected on the major topics that I see evolving in my practice.
They are digital sovereignty and AI security, in particular the security of AI agent systems.
These are systems where AI is not just used as an advanced data processor, but is undertaking autonomous actions.&lt;/p&gt;
&lt;p&gt;I focus specifically on so-called wicked problems: problems that do not have simple solution because they are intertwined with many other issues and conflicting interests.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Non-Monetary Values</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/non-monetary/</link>
      <pubDate>Wed, 19 Nov 2025 20:10:47 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/non-monetary/</guid>
      <description>Money isn&amp;#39;t the only currency of value. Belonging, identity, and professional pride shape IT decisions as much as budgets do — and are a source of power in their own right.</description>
    </item>
    <item>
      <title>How Claude Flow helped me create my next tool</title>
      <link>https://digitalinfrastructures.nl/posts/claude-flow-parallamr/</link>
      <pubDate>Wed, 15 Oct 2025 20:01:08 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/claude-flow-parallamr/</guid>
      <description>&lt;p&gt;After &lt;a href=&#34;https://digitalinfrastructures.nl/posts/Claude-flow-ttt&#34;&gt;coding a demo application with Claude Flow&lt;/a&gt; it was time to do a larger project.&lt;/p&gt;
&lt;p&gt;Claude Flow allows the distribution of coding work over a variety of agents.
Each of the agents has a specific role in the project, such as coder, tester, analyst, and others.&lt;/p&gt;
&lt;p&gt;These agents create stuff, inform each other, and check each other&amp;rsquo;s results.&lt;/p&gt;
&lt;p&gt;But even after a few projects, I still find it difficult to grasp the subtleties and intricacies of its various agents, components and options.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Security and AI</title>
      <link>https://digitalinfrastructures.nl/posts/cloud-sec-ai/</link>
      <pubDate>Tue, 09 Sep 2025 06:10:21 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/cloud-sec-ai/</guid>
      <description>&lt;p&gt;How can you use cloud security lessons to better secure AI?
This is what is keeping some of my clients busy recently.&lt;/p&gt;
&lt;p&gt;Arguably the most important concept in cloud security is the allocation of responsibilities across the independent actors that contribute to any digital service.
Often referred to as &amp;lsquo;shared responsibility&amp;rsquo;, this is about &amp;lsquo;who does what?&amp;rsquo;.
For example, in an IaaS service model, the provider does the physical security of servers, offers a variety of network isolation options, and so forth.
The IaaS consumer&amp;rsquo;s job is to use those features to, for example, organize logical server access, so only authorized access is permitted.
In contrast, many mistakenly think it is the provider&amp;rsquo;s job to secure and update the operating system.
It is not, in an IaaS model, it is the consumer&amp;rsquo;s job.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Data, Risk, or Controls: where to start?</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/darico/</link>
      <pubDate>Mon, 01 Sep 2025 19:48:55 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/darico/</guid>
      <description>&lt;p&gt;Where do you start your IT security journey?
It is important, but it can be confusing.&lt;/p&gt;
&lt;p&gt;For many organizations, the trigger is a compliance obligation to show that confidential information remains confidential.
Maybe their customers are asking for an ISO/IEC 27001 certification, demonstrating that an IT risk management system is in place.
Maybe they are handling credit cards and therefore need to worry about compliance to PCI DSS.&lt;/p&gt;
&lt;h3 id=&#34;controls&#34;&gt;Controls&lt;/h3&gt;
&lt;p&gt;The common theme in these is that they are &lt;em&gt;control&lt;/em&gt; based.
The process is that you realize compliance by implementing a set of controls, such as defining a password policy, or implementing a type of firewall.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Testing RSS updates</title>
      <link>https://digitalinfrastructures.nl/blog/newblog/</link>
      <pubDate>Mon, 01 Sep 2025 11:28:58 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/blog/newblog/</guid>
      <description>&lt;p&gt;Testing RSS&lt;/p&gt;</description>
    </item>
    <item>
      <title>AI Roles and Responsibilities</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/ai-roles/</link>
      <pubDate>Tue, 26 Aug 2025 15:56:05 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/ai-roles/</guid>
      <description>Six roles run every AI system, from customer to data provider, each bound by its own promise. Based on the CSA AI Controls Matrix.</description>
    </item>
    <item>
      <title>Agentic coding, the next level</title>
      <link>https://digitalinfrastructures.nl/posts/claude-flow-ttt/</link>
      <pubDate>Mon, 25 Aug 2025 10:09:31 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/claude-flow-ttt/</guid>
      <description>&lt;p&gt;My AI coding journey continues.&lt;/p&gt;
&lt;p&gt;My &lt;a href=&#34;https://digitalinfrastructures.nl/posts/ai-nocode/&#34;&gt;first version&lt;/a&gt; of the Tic-Tac-Toe game took some time to get right
even though I already applied some serious automated top-down design.&lt;/p&gt;
&lt;p&gt;As explained, understanding feedback loops is crucial for correcting errors.
Part of this is using explicit tests for desirable outcomes.
A process for test-driven design would be even better.&lt;/p&gt;
&lt;p&gt;The main question from that experience was: How can we let the AI check itself?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Compliance is a Risk</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/uneasy-compliance-risk/</link>
      <pubDate>Fri, 22 Aug 2025 09:18:35 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/uneasy-compliance-risk/</guid>
      <description>Target was PCI-DSS compliant and still lost 40 million card numbers — compliance forces risk management onto reluctant actors, but never guarantees security.</description>
    </item>
    <item>
      <title>Games of value and power</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/game-theory/</link>
      <pubDate>Thu, 31 Jul 2025 12:30:29 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/game-theory/</guid>
      <description>&lt;p&gt;A great way to look at how value is created in interactions between autonomous actors is game theory.
How do autonomous actors respond to other actors?
This is the core question here.
How do you respond to an offer from a service provider? But also, how do they respond to you?&lt;/p&gt;
&lt;p&gt;I have found game theory to be an effective model to think about the outcomes of sequences of interactions.
This is because it clearly identifies the actors (or players) and their interests.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why 2025 resources</title>
      <link>https://digitalinfrastructures.nl/posts/why2025/</link>
      <pubDate>Thu, 31 Jul 2025 08:10:04 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/why2025/</guid>
      <description>&lt;h1 id=&#34;digital-power-the-book&#34;&gt;Digital Power: The book&lt;/h1&gt;
&lt;p&gt;For the book and my blog, here is the link: &lt;a href=&#34;https://digitalinfrastructures.nl&#34;&gt;https://digitalinfrastructures.nl&lt;/a&gt;.&lt;/p&gt;
&lt;h1 id=&#34;coaching-for-professionals&#34;&gt;Coaching for professionals&lt;/h1&gt;
&lt;p&gt;I run a group coaching program for senior IT professionals.
This addresses knowledge and skills in technology, governance, and your own career objectives.&lt;/p&gt;
&lt;p&gt;Read more on &lt;a href=&#34;https://docs.google.com/document/d/1rdQNA04RmalRzg77hGqMXuYKNQ4_S8x7kggiQB-R3Fc/edit?tab=t.0&#34;&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;h1 id=&#34;presentations-at-why-2025&#34;&gt;Presentations at WHY 2025&lt;/h1&gt;
&lt;p&gt;PDF: &lt;a href=&#34;https://digitalinfrastructures.nl/How-to-bluff-ZT-WHY2025.pdf&#34;&gt;How to bluff your way into Zero Trust&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;PDF: &lt;a href=&#34;Diagrams-that-communicate&#34;&gt;Using deployment diagrams to explain architecture and security to everybody&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The presentations are also online in the WHY2025 YouTube channel and at the &lt;a href=&#34;https://media.ccc.de/b/conferences/camp-NL/why2025&#34;&gt;CCC&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Computing</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/cloudcomputing/</link>
      <pubDate>Fri, 25 Jul 2025 07:45:07 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/cloudcomputing/</guid>
      <description>&lt;p&gt;Cloud Computing is an important and big set of digital infrastructures.&lt;/p&gt;
&lt;p&gt;Between 2000 and 2010, as the internet was growing in reach, it also became a vehicle for the delivery of compute services.
Back in the day, Application Services Providers, as they were known, offered software remotely, so it was no longer necessary to install it in a company&amp;rsquo;s datacenter.
I could tell horror stories about how early client server application installations went, so not needing that was a key selling point.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AI Coding: &#34;Look Ma, no hands!&#34;</title>
      <link>https://digitalinfrastructures.nl/posts/ai-nocode/</link>
      <pubDate>Sat, 19 Jul 2025 12:22:13 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/ai-nocode/</guid>
      <description>&lt;p&gt;Here is how I AI-coded a fully functional Tic-Tac-Toe web game &lt;em&gt;without&lt;/em&gt; looking at a single line of code or manually identifying a GUI or logic error.
I ran Claude Code (Pro) in VS Code without any other IDE/AI tooling.&lt;/p&gt;
&lt;p&gt;But it takes some effort and discipline to get there.
The core idea is to be very specific and use an opinionated environment that includes extensive automated testing.&lt;/p&gt;
&lt;h3 id=&#34;the-agentic-ai-way&#34;&gt;The Agentic AI way&lt;/h3&gt;
&lt;p&gt;Many people are researching this, all with slightly different approaches.
There are a variety of ways to do more or less the same thing.
Here are some of the interesting approaches I found.
Interestingly, they all popped up in the first half of 2025.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AI coding rabbit holes</title>
      <link>https://digitalinfrastructures.nl/posts/monkey-coding/</link>
      <pubDate>Sat, 12 Jul 2025 06:26:24 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/monkey-coding/</guid>
      <description>&lt;h3 id=&#34;the-approach&#34;&gt;The approach&lt;/h3&gt;
&lt;p&gt;People call LLMs statistical completion engines and that they therefore cannot write computer code.
While the first may be true, the conclusion not necessarily follows.&lt;/p&gt;
&lt;p&gt;My answer to this question: let&amp;rsquo;s try this out!
Inspired by modern discoveries in, for example, context engineering and swarm coding (references to come) I decided to give AI assisted coding  a shot.&lt;/p&gt;
&lt;p&gt;I had a little used SaaS application (an LMS) that was nevertheless costing serious money.
Yet, completely killing it was not an option.
It was relatively easy to extract the Gigabytes of content in there, also through a bit of AI assistance.
So I decided to rebuild the app, or at least a minimal version of it.
Of many options, I selected Claude as my coding assistant.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A guide to digital sovereignty, autonomy, and business resilience</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/guide-autonomy-resilience/</link>
      <pubDate>Fri, 11 Jul 2025 14:57:31 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/guide-autonomy-resilience/</guid>
      <description>&lt;p&gt;Imagine that you are part of the government of an average nation, and you have just realized that IT has become a substantial factor in your operation.
Or you have a similar position in a manufacturing industry, or in the financial sector.
As IT increased in volume, you have tried to keep its costs down, it was just a facility.
Outsourcing to more experienced partners was an option, and so was the use of cloud computing, for example for your Office applications.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Can AI automate compliance?</title>
      <link>https://digitalinfrastructures.nl/posts/risk-value/</link>
      <pubDate>Tue, 24 Jun 2025 14:37:11 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/risk-value/</guid>
      <description>&lt;p&gt;My AI-supported risk analysis assistant mirrors a common pitfall in risk management: focusing on irrelevant controls rather than genuine threats.&lt;/p&gt;
&lt;p&gt;I have created a risk analyst AI based on industry best practices, or so I assume.
This is part of a quest toward more compliance automation, because as an industry we are falling behind in security.&lt;/p&gt;
&lt;p&gt;I am running through a simple example of a chatbot that answers questions over a nonsensitive dataset.
The analyst dives deep into questions on all kinds of controls that, in my view, are quite irrelevant to the risk at the business level.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How I Got Started in Computer Networks</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/first-network/</link>
      <pubDate>Sun, 08 Jun 2025 14:31:28 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/first-network/</guid>
      <description>&lt;p&gt;My first interest in networking came in the early 80s, as I was in the final years of my mathematics and computer science master&amp;rsquo;s program.&lt;/p&gt;
&lt;p&gt;At the time, dial-up terminal networking was about the most advanced there was.
And if you were lucky, you&amp;rsquo;d get 1200 baud (transmitting approximately 120 characters per second).
My current fiber-optic home links are 1 Gigabit/sec, which is about 1 million times faster.&lt;/p&gt;
&lt;p&gt;Beyond this, computer-to-computer communication was mostly confined to the local data center.
Transferring files from one computer to another typically involved physically moving storage media around.
I have a great story about that, but that will be in another unit.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Shared Services Lead to Conflicts</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/shared-service-conflict/</link>
      <pubDate>Fri, 06 Jun 2025 10:32:19 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/shared-service-conflict/</guid>
      <description>&lt;p&gt;Digital infrastructures serve, nearly always, multiple customers.
These customers therefore share the resources provided by these digital infrastructures.
With that sharing comes the potential for conflicts over those resources.&lt;/p&gt;
&lt;p&gt;When I talk to my friend over the phone, we share a connection, and that is exactly when sharing is part of the value of that infrastructure.
But when multiple users draw computer capacity from the same pool, there is a risk that the pool is too small, and some users will not get the capacity that they require.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Zero Trust Myths</title>
      <link>https://digitalinfrastructures.nl/posts/zt-myths/</link>
      <pubDate>Tue, 03 Jun 2025 10:37:45 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/zt-myths/</guid>
      <description>&lt;p&gt;What is the problem with the image that Zero Trust based information security brings along?&lt;/p&gt;
&lt;p&gt;Once you understand the principles, and they are not really difficult, it is obvious that only ZT can lead us to a more secure cyber future.&lt;/p&gt;
&lt;p&gt;So, what is holding us back?&lt;/p&gt;
&lt;p&gt;Here are some of the misconceptions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&amp;ldquo;It is a boatload of work, so let&amp;rsquo;s not start.&amp;rdquo; Truth: yes, fully securing your IT with all its technical debt is a boatload of work. That is exactly the reason why you need ZT, so that you know where you can get started quickly, and be more secure &lt;em&gt;before&lt;/em&gt; the last hole is plugged.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The AI Coding Age</title>
      <link>https://digitalinfrastructures.nl/posts/ai-coding-age/</link>
      <pubDate>Sun, 01 Jun 2025 13:13:09 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/ai-coding-age/</guid>
      <description>&lt;p&gt;This is the dawn of a new age.&lt;/p&gt;
&lt;p&gt;I have been observing software development for more than fifty years, ever since I wrote my first computer program.
In that entire time, I have never witnessed a development that has changed the profession deeper, faster, or more pervasively than now.
AI-assisted coding has escaped from the lab, and is impacting the work of every software developer.&lt;/p&gt;
&lt;p&gt;In the communities I track I hear stories of software engineers regret taking a single week of vacation because of the innovations that they now have to catch up to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lean Risk and Economics</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/lean-risk/</link>
      <pubDate>Tue, 27 May 2025 19:58:41 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/lean-risk/</guid>
      <description>&lt;p&gt;From the moment a security vulnerability is discovered, it represents a negative value to its potential victims.
When it gets exploited, it can lead to loss of data or loss of integrity of the data.
This in turn impacts the victim&amp;rsquo;s business processes.&lt;/p&gt;
&lt;p&gt;For example, if personal data is leaked, reputations will be damaged, financial losses and fines can be expected. Credit card abuse forms another example of loss.&lt;/p&gt;
&lt;p&gt;This &amp;ldquo;damage potential&amp;rdquo; increases as the vulnerability becomes well-known, progressing from nation state actors, to organized crime, to script kiddies, just to name one example pathway.
At first, few people know about it, but gradually more people will be able to inflict damage with it.
Over time, each step adds to the likelihood of that vulnerability being exploited and causing real damage.
The likelihood starts at near zero, and ends at close to 100% as the vulnerability is completely public.
This only stops when an investment is made to mitigate the vulnerability, for example by updating the software.
And hopefully, that investment is less costly than the damage potential.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AI will replace coders, not software engineers</title>
      <link>https://digitalinfrastructures.nl/posts/ai-code-software/</link>
      <pubDate>Fri, 23 May 2025 12:45:13 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/ai-code-software/</guid>
      <description>&lt;p&gt;If you build software for a living, generative AI may be a scary development, as it has the potential to take over a lot of software creation.
But I think it depends on what you see as the job of creating software.&lt;/p&gt;
&lt;p&gt;A coder in the world of IT is somebody who writes code in some programming language.
More typically they modify code instead of writing it from scratch.
This is in response to bugs, feature requests, and so on.
In the age of AI, a lot of coding can be automated.
We have seen many examples of AI generating lots of code based on fairly compact specifications.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vibe OPSing with MCP: proof of concept</title>
      <link>https://digitalinfrastructures.nl/posts/vibe-opsing/</link>
      <pubDate>Tue, 20 May 2025 09:30:03 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/vibe-opsing/</guid>
      <description>&lt;p&gt;Here is the story of how I started to use AI to help with running and securing my home network.
I call it vibe ops, in analogy to vibe programming.&lt;/p&gt;
&lt;p&gt;This post is going to be obsolete very soon, even though it is already the second version &amp;hellip;&lt;/p&gt;
&lt;p&gt;My home network plays an additional role as a nice lab, and in the process of better securing it, preferably with Zero Trust Architectures, I am doing some experiments.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Where the buck stops</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/buck-stops/</link>
      <pubDate>Thu, 15 May 2025 21:08:13 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/buck-stops/</guid>
      <description>&lt;p&gt;The US president Harry S. Truman famously had a sign on his desk that said:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The buck stops here.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;This refers to the process of &amp;ldquo;passing up the buck&amp;rdquo;, meaning to escalate decisions to the next higher level in the organization.&lt;/p&gt;
&lt;p&gt;Truman implied that he took responsibility but also that this is where power comes from.&lt;/p&gt;
&lt;p&gt;This is an essential part of governance, and this vertical line of responsibility represents one way of looking at it.
We can trace how this works in the following risk management example.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Contracts are complementary promises</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/promise-contract/</link>
      <pubDate>Thu, 15 May 2025 21:03:24 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/promise-contract/</guid>
      <description>A contract is just two complementary conditional promises plus a fallback for non-delivery: what do I do, what do you do, what do I do if you don&amp;#39;t?</description>
    </item>
    <item>
      <title>A Unified Framework</title>
      <link>https://digitalinfrastructures.nl/book/wrap/unified-theory/</link>
      <pubDate>Mon, 12 May 2025 21:05:36 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/wrap/unified-theory/</guid>
      <description>&lt;p&gt;The units so far have explored quite a few, seemingly unrelated, concepts and observations.
Here we&amp;rsquo;ll embed them in a unified framework that illustrates how they fit together.&lt;/p&gt;
&lt;p&gt;From the title of this book you can see that the main pillars of that framework include value, power, and risk.
To get there, we need a fourth pillar: change.
For now, we&amp;rsquo;ll call these pillars layers, though there is no implied hierarchy between them.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Security Assets</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/assets/</link>
      <pubDate>Sun, 11 May 2025 08:37:01 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/assets/</guid>
      <description>Data, not hardware, is the real asset at risk — ENISA&amp;#39;s cloud taxonomy, the threat/vulnerability chain, and why risk = impact x probability needs a real victim.</description>
    </item>
    <item>
      <title>What is the value of information?</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/value-of-information/</link>
      <pubDate>Sat, 10 May 2025 11:33:28 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/value-of-information/</guid>
      <description>&lt;p&gt;What is information really?
If we know that, we can try to understand how we can judge its value, or even start to understand how we can create value with information.&lt;/p&gt;
&lt;p&gt;In Claude Shannon&amp;rsquo;s theory of communication, information is about reducing uncertainty.
Another way is to say that more information means less noise because if you add noise to information, that information will have more uncertainty and less value.&lt;/p&gt;
&lt;p&gt;To visualize this, think of a picture that is obscured by a bit of fog or haze.
You can still see some of the picture, but not very clearly.
You will make more errors when trying to understand what the picture means.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why Organization Size Determines Who You Trust</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/org-size-matters/</link>
      <pubDate>Thu, 08 May 2025 20:45:16 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/org-size-matters/</guid>
      <description>Below 150 people you know who to trust by name. Above it, Dunbar&amp;#39;s number kicks in — trust gives way to roles, processes, and bureaucracy.</description>
    </item>
    <item>
      <title>A service agreement is a set of promises</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/promise-theory-services/</link>
      <pubDate>Mon, 05 May 2025 05:58:14 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/promise-theory-services/</guid>
      <description>&lt;p&gt;A service agreement is a contract.
And a contract, as we saw earlier, is essentially a set of complementary promises.&lt;/p&gt;
&lt;p&gt;So a service agreement is really a set of promises between a provider and a consumer.
Not a technical specification, not a piece of legal boilerplate: a set of promises.&lt;/p&gt;
&lt;p&gt;Take a typical IT service.
The provider might promise things like this:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;We promise to prevent unauthorized access.&lt;/li&gt;
&lt;li&gt;We promise to keep your information safe.&lt;/li&gt;
&lt;li&gt;We promise to maintain the service according to vendor best practices.&lt;/li&gt;
&lt;li&gt;We promise to keep a spare copy of your data off site.&lt;/li&gt;
&lt;li&gt;We promise to add resources as needed.&lt;/li&gt;
&lt;li&gt;We promise to apply updates and improvements.&lt;/li&gt;
&lt;li&gt;We promise to have trained staff that reacts timely and professionally.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of these promises are self-evident.
Each one could fail, or be broken.
Each one is, in other words, also a risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New skills needed</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/new-skills-needed/</link>
      <pubDate>Fri, 02 May 2025 08:07:42 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/new-skills-needed/</guid>
      <description>&lt;p&gt;Understanding the technical architecture of digital infrastructures is critically important, in particular for &lt;em&gt;non-technical&lt;/em&gt; professionals.&lt;/p&gt;
&lt;p&gt;I have spent more than a decade educating people on cloud security, for example through certifications such as the &lt;a href=&#34;https://www.clubcloudcomputing.com/ccsk/&#34;&gt;Certificate of Cloud Security Knowledge (CCSK)&lt;/a&gt;, organized by the Cloud Security Alliance (CSA), and the &lt;a href=&#34;https://www.clubcloudcomputing.com/ccsp/&#34;&gt;Certified Cloud Security Professional (CCSP)&lt;/a&gt;, as organized by (ISC)2.
These bodies of knowledge cover a lot of ground, and most of it is related to digital infrastructures at scale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Governance over IT, an example</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/governance-example/</link>
      <pubDate>Thu, 01 May 2025 11:07:46 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/governance-example/</guid>
      <description>&lt;p&gt;Shared resources can lead to conflicts.
If the capacity runs out, somebody will feel the pain at the expense of somebody else.
This conflict will be resolved in one way or another.
Without other arrangements, the stakeholder with the most power wins.
This is not necessarily the best outcome for the organization as a whole.&lt;/p&gt;
&lt;p&gt;To illustrate this, I gave ChatGPT the following prompt:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Write a business case story about the conflict over shared computing resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Three books on Zero Trust, and when you should read them</title>
      <link>https://digitalinfrastructures.nl/posts/three-books-zero-trust/</link>
      <pubDate>Wed, 30 Apr 2025 12:46:33 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/three-books-zero-trust/</guid>
      <description>&lt;p&gt;&lt;em&gt;&amp;lsquo;But where do we start?&amp;rsquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The question hung in the air of my training session, asked by many of the attendants. Mind you, these are experienced people with many years of cyber security experience.&lt;/p&gt;
&lt;p&gt;But turning Zero Trust from an abstract concept into concrete action? That&amp;rsquo;s where everyone gets stuck.&lt;/p&gt;
&lt;p&gt;I know that feeling well. Years ago, I joined my first Zero Trust working group, swimming in a sea of frameworks, agency guidelines, and vendor whitepapers. I even had the privilege of attending sessions with John Kindervag, the father of Zero Trust himself. Yet the gap between theory and implementation remained stubbornly wide.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Saas Security: the first three steps</title>
      <link>https://digitalinfrastructures.nl/posts/saas-security-simple-checklist/</link>
      <pubDate>Wed, 30 Apr 2025 10:56:37 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/saas-security-simple-checklist/</guid>
      <description>&lt;p&gt;The security of your SaaS cloud solutions starts with the review of three major areas. Practically all companies are using SaaS providers in one way or another.
SaaS includes Services such as Trello for project management, Microsoft 365, and e.g. specialized solutions for marketing intelligence services. The sky is the limit. Most companies are using hundreds of SaaS solutions.&lt;/p&gt;
&lt;p&gt;Here are 3 tips to start with.&lt;/p&gt;
&lt;h2 id=&#34;maturity-match&#34;&gt;Maturity match&lt;/h2&gt;
&lt;p&gt;The first thing to worry about is if the maturity of the provider matches your risk appetite. Are they good enough for your use case?
If you are working with a mission-critical SaaS solution, you want to make sure that the provider is mature. You can start finding out if that is the case is by looking at their certifications. An example could be the ISO 27000 series certification for IT risk management, or similar. Most mature cloud providers have dozens of certifications. On the other end of the spectrum, you may want to work with a provider that is not so mature, but that is delivering a very innovative solution of great business benefit to your company. That benefit, that competitive edge, may warrant a greater risk appetite.
So start with that maturity match first.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Great Introduction to Zero Trust</title>
      <link>https://digitalinfrastructures.nl/posts/great-introduction-to-zero-trust/</link>
      <pubDate>Wed, 30 Apr 2025 10:48:42 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/great-introduction-to-zero-trust/</guid>
      <description>&lt;p&gt;“Project Zero Trust” is a business novel by George Finney. It talks about an emerging approach to IT and Cybersecurity that attempts to reduce cyberrisk in a more fundamental way.
Zero Trust is a bit of a hype in IT these days, and both product companies and knowledge agencies are dropping lots of papers on this. But this book is in another game.&lt;/p&gt;
&lt;p&gt;What I like about it is that it paints a reasonably realistic picture of a modern enterprise, including the information technology choices that it makes. This serves as a good backdrop to a variety of Zero Trust initiatives, which are described in a bit of detail.
As an instructor I find that most of the vendor neutral training material out there lacks specific examples. This makes it hard for students to anchor the abstract concepts that they are fed to a realistic environment with some resemblance to their job situation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Key Knowledge Gaps in Cloud Security and How to Address Them</title>
      <link>https://digitalinfrastructures.nl/posts/key-knowledge-gaps-in-cloud-security/</link>
      <pubDate>Wed, 30 Apr 2025 07:41:35 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/key-knowledge-gaps-in-cloud-security/</guid>
      <description>&lt;p&gt;What are the real challenges in cloud security these days? In my recent conversations with industry practitioners, one came up consistently: the lack of knowledge and skills to adopt cloud securely.
These gaps are slowing down how teams build, manage and secure their cloud environments, and they may be affecting your teams as well.&lt;/p&gt;
&lt;h2 id=&#34;provider-specific-technical-expertise&#34;&gt;Provider specific technical expertise&lt;/h2&gt;
&lt;p&gt;Many IT professionals attempt to transfer their on-premises security knowledge directly to cloud. But this often leads to ineffective and hard to maintain solutions.
A technical example is insisting on traditional firewall architectures. These are hard to implement right in the cloud and can lead to less secure deployments than are possible with cloud native architectures.
One set of skills that is relevant to addressing this is understanding what features a specific cloud provider has for building a secure architecture. There are many courses available from the providers, even free ones, though it can sometimes be a bit challenging to select the correct ones.
However, without understanding how abstraction and automation change the IT security game, these technical skills will not result in more efficiency. And without more efficiency security efforts will be outpaced by the speed of new developments.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vibe coding an MCP Server</title>
      <link>https://digitalinfrastructures.nl/posts/vibe-mcp/</link>
      <pubDate>Sun, 27 Apr 2025 08:39:55 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/vibe-mcp/</guid>
      <description>&lt;p&gt;Model Context Protocols (MCP, see &lt;a href=&#34;https://digitalinfrastructures.nl/posts/mcp-risk/&#34;&gt;my post on their security&lt;/a&gt;) are the new glue between humans, chatbots, and old school IT.&lt;/p&gt;
&lt;p&gt;Here is the step by step approach that I followed to &amp;lsquo;&lt;a href=&#34;https://digitalinfrastructures.nl/posts/vibe-coding-real/&#34;&gt;vibe code&lt;/a&gt;&amp;rsquo; a Model Context Protocol server for my CRM and mailing list manager.&lt;/p&gt;
&lt;p&gt;I journaled this description, so I have included most of the detours and false starts.
For readability, I edited the description later, but the flow is as I went through it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Promise Theory</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/promise-theory/</link>
      <pubDate>Fri, 25 Apr 2025 21:21:54 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/promise-theory/</guid>
      <description>A café order between a customer and a waiter turns out to be the same pattern behind APIs, contracts, and IT support tickets: request, promise, delivery, acquittal.</description>
    </item>
    <item>
      <title>The moral necessity of talking about power</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/ethics-of-power/</link>
      <pubDate>Thu, 24 Apr 2025 20:30:57 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/ethics-of-power/</guid>
      <description>Power has a bad reputation, but no group survives without exercising it — from combat leadership to IETF standards, understanding it precedes resisting abuse.</description>
    </item>
    <item>
      <title>Look at MCP now to be ahead of AI risk</title>
      <link>https://digitalinfrastructures.nl/posts/mcp-risk/</link>
      <pubDate>Wed, 23 Apr 2025 06:03:44 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/mcp-risk/</guid>
      <description>&lt;p&gt;If you are in security and not fully on top of AI risk, you want to look at MCP &lt;strong&gt;now&lt;/strong&gt;, as this is going to be popular and risky.
Reach out to your development teams and beyond to offer your help in using them wisely, even if you know nothing about them yet.&lt;/p&gt;
&lt;p&gt;MCP, Model Context Protocol, was introduced in November 2024 as a standardised way to feed AI chatbots with extra information.
You can extend Claude or OpenAI desktop with MCP servers, which are basically small programs that run on the desktop and have access to all information and services that the user has.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Example: an AI-Assisted Voicebot</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/ai-voice/</link>
      <pubDate>Tue, 22 Apr 2025 09:32:32 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/ai-voice/</guid>
      <description>&lt;p&gt;Let&amp;rsquo;s look at a practical example from one of my clients.
It handles voice calls using an AI-supported chatbot.&lt;/p&gt;
&lt;pre class=&#34;mermaid&#34;&gt;architecture-beta
    group frontend(cloud)[Telecom operator]
        service telco(cloud)[Telco switches] in frontend
        service sips(internet)[SIPS Gateway] in frontend
    
    group backend(cloud)[Application Provider]
        service app_server(server)[Azure voice bot] in backend
        service twilio(internet)[Twilio] in backend
        service database(database)[FAQ Database] in backend
        service llm(server)[LLM] in backend

    group configuration(cloud)[Client]
        service faq(database)[FAQ mgt]    in configuration
    
    telco:R -- L:sips
    sips:R -- L:twilio
    twilio:R -- L:app_server
    app_server:B -- T:database
    llm:B -- T:app_server
    faq:R -- L:database
&lt;/pre&gt;
&lt;p&gt;Who is actually responsible for what?
This is important for a number of reasons:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Power Flows</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/power-mediation/</link>
      <pubDate>Sun, 20 Apr 2025 09:24:41 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/power-mediation/</guid>
      <description>&lt;p&gt;Power does not automatically flow from those that have it to those that are influenced by it.&lt;/p&gt;
&lt;p&gt;As they say in dutch, quoting the poet Willem Elsschot: &amp;ldquo;tussen droom en daad staan wetten in de weg, en praktische bezwaren&amp;rdquo;. (&amp;ldquo;between dream and deed stand laws in the way, and practical objections&amp;rdquo;).&lt;/p&gt;
&lt;p&gt;We want to understand this. If we want to exercise power, we need to understand the intermediaries. If we want to subvert power, the intermediaries are one of our disruptive points.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Execution Environments</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/execution-environments/</link>
      <pubDate>Sun, 20 Apr 2025 09:03:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/execution-environments/</guid>
      <description>&lt;p&gt;What do a laptop, a smartphone, and a smart thermostat have in common with a browser, a database, and a data center?&lt;/p&gt;
&lt;p&gt;They are all execution environments that contain software and data, and that makes them building blocks for deploying digital infrastructures.
In a diagram we often depict them as a box, or an oval.
Inside the box, software gets executed, instructions get interpreted, actions are done. Software without execution is just dead data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Control Through Feedback Loops</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/control-feedback/</link>
      <pubDate>Sat, 19 Apr 2025 20:01:07 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/control-feedback/</guid>
      <description>From braking a car to autoscaling a website to a fighter pilot&amp;#39;s OODA loop — every control system runs on feedback, and &amp;#39;agile&amp;#39; just means a faster loop.</description>
    </item>
    <item>
      <title>Things Break at Scale</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/things-break-at-scale/</link>
      <pubDate>Wed, 16 Apr 2025 21:16:12 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/things-break-at-scale/</guid>
      <description>&lt;p&gt;Computers are terribly reliable, in general. Today&amp;rsquo;s computer systems execute millions, even trillions, of instructions each second, with an error rate that is inconceivable in other technologies. Yet, if you have hundreds of thousands of machines, you do need to take care of failures.&lt;/p&gt;
&lt;p&gt;In the early days of Google growth I read an &lt;a href=&#34;https://www.cnet.com/culture/google-spotlights-data-center-inner-workings/&#34;&gt;article about their error numbers&lt;/a&gt;
(a Google cluster has several thousands of machines):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;In each cluster&amp;rsquo;s first year, it&amp;rsquo;s typical that 1,000 individual machine failures will occur; thousands of hard drive failures will occur; one power distribution unit will fail, bringing down 500 to 1,000 machines for about 6 hours; 20 racks will fail, each time causing 40 to 80 machines to vanish from the network; 5 racks will &amp;ldquo;go wonky,&amp;rdquo; with half their network packets missing in action; and the cluster will have to be rewired once, affecting 5 percent of the machines at any given moment over a 2-day span, Dean said. And there&amp;rsquo;s about a 50 percent chance that the cluster will overheat, taking down most of the servers in less than 5 minutes and taking 1 to 2 days to recover.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Applications and Infrastructures</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/applications/</link>
      <pubDate>Wed, 16 Apr 2025 21:11:32 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/applications/</guid>
      <description>&lt;p&gt;Infrastructures are nice, but the applications that they enable are where the value of information technology is.
We want to understand how this fits into this book&amp;rsquo;s understanding of value, risk, and control boundaries.&lt;/p&gt;
&lt;p&gt;Applications store and process data, so an application is roughly a data model plus a certain number of functions operating on that.
A word processor is an application. Its data model is formatted text, and the functionality allows you to manipulate that text.
Another example would be Gmail, whose data model is a set of messages, and the functionality allows you to manipulate the messages and their flow.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Who Suffers?</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/who-suffers/</link>
      <pubDate>Tue, 15 Apr 2025 21:27:25 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/who-suffers/</guid>
      <description>&lt;p&gt;I have found that no discussion on risk is going to lead anywhere if it does not make clear who suffers from it.
Make clear who has the pain.
For my phone and laptop it is easy: if I lose them, I suffer.
In a larger organization it is less clear.
Suppose a server dies.
Whose application then no longer runs?
Who has to pay for a new server?
This gets increasingly harder if we are talking about shared services, because the owner and the consumer are now decoupled.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vibe Coding in Reality</title>
      <link>https://digitalinfrastructures.nl/posts/vibe-coding-real/</link>
      <pubDate>Tue, 08 Apr 2025 14:34:54 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/vibe-coding-real/</guid>
      <description>&lt;p&gt;How does vibe coding work in the real? Vibe coding is having AI write your software. Coined by Andrej Karpathy, the hype is all over the map, with companies that are rethinking their hiring strategies for programmers. Sounds like disaster for software engineers and programmers.&lt;/p&gt;
&lt;p&gt;Not so fast.&lt;/p&gt;
&lt;p&gt;Curious to learn more about it, I reached out to an old friend who is an experienced software engineer. He was a co-founder in a SaaS company in the monitoring space. After a successful exit he now has a bit more time to pursue hobbies. But he is still professionally busy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction to Power</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/intro-power/</link>
      <pubDate>Sat, 05 Apr 2025 12:31:46 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/intro-power/</guid>
      <description>&lt;p&gt;Power is a concept that is widely used and ill defined. Many philosophers have discussed it, but not one definition really stands out.
Before we attempt to define power formally, let&amp;rsquo;s see how the word is used in everyday IT situations.&lt;/p&gt;
&lt;p&gt;Understanding power in IT is not just academic. As the examples show it is crucial in understanding how IT works and creates value and risk.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The cloud architect held significant power in deciding which platforms the organization would adopt for its digital transformation.&lt;/li&gt;
&lt;li&gt;Automated deployment pipelines gave development teams the power to release software faster and with fewer errors.&lt;/li&gt;
&lt;li&gt;Legacy systems often retain unexpected power in large organizations, simply because so many critical processes still depend on them.&lt;/li&gt;
&lt;li&gt;Regulators have the power to halt digital initiatives if data protection requirements are not met.&lt;/li&gt;
&lt;li&gt;By owning the central identity management service, the security team had the power to control access across the entire infrastructure.&lt;/li&gt;
&lt;li&gt;Outages at major cloud providers show how concentrated power in digital infrastructures can lead to systemic risk.&lt;/li&gt;
&lt;li&gt;The CIO used the power of budget approval to steer the enterprise toward adopting more secure infrastructure patterns.&lt;/li&gt;
&lt;li&gt;Power struggles between central IT and business units can delay the rollout of shared infrastructure services.&lt;/li&gt;
&lt;li&gt;With real-time observability tools, operations teams gained the power to detect and respond to incidents before users were affected.&lt;/li&gt;
&lt;li&gt;An open-source community can collectively wield more power than a single vendor when shaping the direction of a software tool.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;From these examples, we can see certain recurring features of power in the context of IT and digital infrastructures.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Big tech afhankelijkheid: wat is het echte risico?</title>
      <link>https://digitalinfrastructures.nl/posts/autonomie-van-bigtech/</link>
      <pubDate>Sat, 05 Apr 2025 09:36:33 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/autonomie-van-bigtech/</guid>
      <description>&lt;p&gt;Het nationale sentiment is negatief over de afhankelijkheid van &amp;lsquo;big tech&amp;rsquo;. Overheidsdata staat in een Amerikaanse cloud, we hebben geen eigen sociaal netwerk, enzovoort. En vergelijkbare sentimenten spelen bij andere organisaties.&lt;/p&gt;
&lt;p&gt;Terecht wordt daarom nu op overheidsniveau een initiatief in gang gezet om wat aan die afhankelijkheid te doen. Dit initiatief staat ook bekend als &lt;a href=&#34;https://berthub.eu/articles/posts/cloud-kootwijk-moties-aangenomen/&#34;&gt;Cloud Kootwijk&lt;/a&gt;. Maar met een motie in de Kamer zijn we er nog niet.&lt;/p&gt;
&lt;p&gt;Emoties zijn vaak een goede indicator, maar geen goede inhoudelijke analyse.
Ze leiden daarom nog wel eens tot beslissingen die onhandig, of zelfs contraproductief uitpakken. Hier legt de emotie wantrouwen bloot, maar waar die zich op richt moet een analyse uitwijzen.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Network Management Automation - the DHCP case</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/dhcp-automation/</link>
      <pubDate>Fri, 04 Apr 2025 14:20:26 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/dhcp-automation/</guid>
      <description>&lt;p&gt;As we mature processes, they come within reach of actual automation. Especially IT management processes. To paraphrase General Carl von Clausewitz, who said &amp;ldquo;War is the continuation of diplomacy with different means&amp;rdquo;, we can say that automation is the progression of process maturity with different means - replacing human effort with software and systems.&lt;/p&gt;
&lt;p&gt;My favorite historical example is IP address allocation. In the past, whenever there was a new computer, you would walk up to the head of the lab or data center and ask for a new IP address for that machine. You may remember that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How My Site Got Hacked</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/how-my-site-got-hacked/</link>
      <pubDate>Sat, 29 Mar 2025 15:35:53 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/how-my-site-got-hacked/</guid>
      <description>&lt;h3 id=&#34;detection&#34;&gt;Detection&lt;/h3&gt;
&lt;p&gt;I should have acted on the first signals more aggressively. But let’s talk about that later in this story.
Here is the story of my site being infected with malware, viewed by a professional cloud security expert. So I am going to apply all that cloud security theory to it.&lt;/p&gt;
&lt;p&gt;The hack led to business damage at the end of one of my webinars. In 2016, on a Friday, I did a webinar, at the end of which I had two links to my site as a call to action.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Elements of the Digital World</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/elements-of-digitalinfrastructures/</link>
      <pubDate>Thu, 27 Mar 2025 20:34:01 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/elements-of-digitalinfrastructures/</guid>
      <description>Every digital system reduces to three entangled elements — storage, networks, and processors — mapped through two simple diagrams for how data moves.</description>
    </item>
    <item>
      <title>Value in Process Improvement</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/value-in-process-improvement/</link>
      <pubDate>Thu, 27 Mar 2025 20:33:42 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/value-in-process-improvement/</guid>
      <description>&lt;p&gt;Most digital infrastructures are meant to communicate or coordinate, or are in support of other digital infrastructures that communicate or coordinate.
That is where their prime value is.&lt;/p&gt;
&lt;p&gt;The internet is a great example. It is designed to enable computers to communicate by moving data packets between them.&lt;/p&gt;
&lt;p&gt;Social media is another example, used by people to communicate with each other. Its success is a testament to the fact that communication is a fundamental human need.&lt;/p&gt;</description>
    </item>
    <item>
      <title>5 Elements of Cloud Security</title>
      <link>https://digitalinfrastructures.nl/posts/5-elements-of-cloud-security/</link>
      <pubDate>Mon, 24 Mar 2025 22:02:03 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/5-elements-of-cloud-security/</guid>
      <description>&lt;h2 id=&#34;five-elements-of-cloud-security&#34;&gt;Five elements of cloud security&lt;/h2&gt;
&lt;p&gt;Historically, IT security started with &lt;strong&gt;infrastructure security&lt;/strong&gt;. Just protecting the data center was good enough. But that was before we had data communications.&lt;/p&gt;
&lt;p&gt;When data started to escape the confines of the data center we needed to protect it. Typically through encryption. Hence we need &lt;strong&gt;data security&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;As the world wide web developed, we saw applications being exposed to it, and frankly, be vulnerable. So that is when &lt;strong&gt;application security&lt;/strong&gt; started to become more important.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How AI Can Help IT Risk Classification</title>
      <link>https://digitalinfrastructures.nl/posts/ai-risk-classification/</link>
      <pubDate>Mon, 24 Mar 2025 19:45:36 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/ai-risk-classification/</guid>
      <description>&lt;p&gt;How cool would it be to let an AI do some of the grunt work in analyzing the risk of applications and services. This has the potential to speed up the work of risk assessors.&lt;/p&gt;
&lt;p&gt;But, does it work in practice? Well, here is an example of AI-assisted risk classification. I downloaded some of the entries in the Dutch &lt;a href=&#34;https://algoritmes.overheid.nl/en&#34;&gt;algorithm register&lt;/a&gt;, which is a public register of systems that use algorithms. For each entry about 30 fields are available, including name, classification, owner, et cetera.
Some of the systems in the registry are AI-based. Indeed, we have AI to help check on AI&amp;hellip;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Systematically applying technology</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/technical-meta-model/</link>
      <pubDate>Sat, 22 Mar 2025 17:56:43 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/technical-meta-model/</guid>
      <description>&lt;p&gt;How to fix the WiFi? How to find a new phone for grandma?&lt;/p&gt;
&lt;p&gt;Applying technology follows certain rules. However, many people only have an intuitive understanding of these rules. As a result, technology is not optimally applied.
By understanding how applying technology really works, you can be more effective, more efficient, reduce waste, and overall do a better job. It takes just a few simple steps to improve any attempt at applying technology. We&amp;rsquo;ll focus on information technology here, though most principles have wider applicability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>International Actors</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/international-actors/</link>
      <pubDate>Sat, 22 Mar 2025 17:56:28 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/international-actors/</guid>
      <description>&lt;p&gt;The international arena has many actors that can influence digital infrastructures. But opinions differ on what the important ones are, or even what the relevant ones are, as we will see.
But the international arena matters, because
by the nature of scaling, very few digital infrastructures are influenced by a single national actor only.&lt;/p&gt;
&lt;p&gt;A word of clarification: I am using the word international here to mean all nations in the world, and their interrelations.
In US vernacular, the word international appears to mean all nations, except the US.
Instead, the word global is used to mean all nations, including the US.
An example implication of this is that a US company would only consider ISO standards to be relevant to them if they also have operations outside the US.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The US Air Force Zero Trust Strategy</title>
      <link>https://digitalinfrastructures.nl/posts/airforce-zero-trust-strategy/</link>
      <pubDate>Fri, 21 Mar 2025 12:26:58 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/airforce-zero-trust-strategy/</guid>
      <description>&lt;p&gt;Who is really doing Zero Trust?&lt;/p&gt;
&lt;p&gt;Well, the US Air Force is. Here is my summary, with some comments, of their strategy document for the benefit of my Certificate of Competence in Zero Trust (CCZT) learners. In fact, this is an edited version of a conversation we had during one of our classes.&lt;/p&gt;
&lt;p&gt;You can download the full strategy &lt;a href=&#34;https://www.dafcio.af.mil/Portals/64/Documents/Strategy/DAF%20API%20Reference%20Architecture%202.0.pdf&#34;&gt;here&lt;/a&gt;, and the current roadmap &lt;a href=&#34;https://www.dafcio.af.mil/Portals/64/Documents/Strategy/DAF%20Enterprise%20Zero%20Trust%20Roadmap%20and%20Release%20Notes_v2.0.pdf?ver=36cbAKNEe7JiRVAPFwWepg%3d%3d&#34;&gt;here&lt;/a&gt;, all linked from &lt;a href=&#34;https://www.dafcio.af.mil/&#34;&gt;this page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I think the fundamental first important point about the strategy document is that it exists at all. There is an actual organization of significant size that has a strategy and is implementing it. Many can learn from this.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What a lunch in Spain taught me about digital infrastructures</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/lunch-spain/</link>
      <pubDate>Sat, 15 Mar 2025 16:06:44 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/lunch-spain/</guid>
      <description>&lt;p&gt;In 2005 I visited my father in France. It turned out to be convenient to pick me up from the Gerona airport in Spain.
And as we had enough time, we had lunch in La Jonquera.&lt;/p&gt;
&lt;p&gt;At the restaurant&amp;rsquo;s checkout I noticed a peculiar array of devices: there were four payment terminals.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&#34;payment terminals&#34; loading=&#34;lazy&#34; src=&#34;https://digitalinfrastructures.nl/payterminal-716603.jpg&#34;&gt;&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;d never seen that. From what I know, a merchant works with a bank which handles all their payments. Apparently not over here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction to Risk</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/intro-to-risk/</link>
      <pubDate>Wed, 12 Mar 2025 13:13:35 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/intro-to-risk/</guid>
      <description>&lt;p&gt;Risk is the flip side of value. For everything that is of value, there can be circumstances threatening that value.
While value is realized in the past and the present, risk is what can happen with that value in the &lt;em&gt;future&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Risk in a digital world is not always easy to think through. While we can borrow a lot from the real world, certain important differences exist.&lt;/p&gt;
&lt;p&gt;At the core of every risk assessment there is the thing we worry about the most: the &amp;lsquo;&lt;strong&gt;asset&lt;/strong&gt;&amp;rsquo;.
In a digital world, this is often the &lt;strong&gt;data&lt;/strong&gt;. Think of business-critical data, like our database of customers. Think of data that we have a compliance obligation on, such as personal data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Provider Value</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/intro-to-value/</link>
      <pubDate>Tue, 11 Mar 2025 09:10:54 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/intro-to-value/</guid>
      <description>&lt;p&gt;Consumers of digital infrastructures benefit from not running them themselves, but having a provider who serves more consumers do it for them.&lt;/p&gt;
&lt;p&gt;Imagine stringing a wire to connect your PC to your neighbor&amp;rsquo;s PC in order to play a game together. People have been doing these things. How long does it take to string the wires and connect them? What is the cost? Where do you buy the cable? How are you going to run that cable? It is a lot faster to just use the internet for that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Essence of Digital Infrastructures</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/essence-digital-infrastructures/</link>
      <pubDate>Mon, 10 Mar 2025 21:34:21 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/essence-digital-infrastructures/</guid>
      <description>&lt;p&gt;What do roads, airports, the internet, the electricity network, and a search engine have in common? They are all services that are independent of a specific user or usage. They are provisioned on a longer timescale than that of an individual usage. And they are typically not owned by their users, or at least, not directly.&lt;/p&gt;
&lt;p&gt;In this book I am mostly concerned with digital infrastructures. Their services are digitally accessible. Of the above examples, the internet and the search engine are the best examples of that. Interestingly, the other services increasingly rely on digital infrastructures themselves, or even incorporate specific digital infrastructures.
Trading platforms, for example, enable the planning of electricity supply and demand.
In many countries, electricity is a market, not a monopoly, which requires coordination between the various players.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deployment Diagrams</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/deployment-diagrams/</link>
      <pubDate>Sun, 09 Mar 2025 21:19:45 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/deployment-diagrams/</guid>
      <description>A diagram of a phone, a speaker, and the cloud encodes real architecture decisions — where data lives, who&amp;#39;s responsible, and how cloud-native complicates it.</description>
    </item>
    <item>
      <title>Digital Infrastructures - the graphic novel</title>
      <link>https://digitalinfrastructures.nl/posts/graphic-novel-page1/</link>
      <pubDate>Sun, 09 Mar 2025 14:07:53 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/graphic-novel-page1/</guid>
      <description>&lt;p&gt;Here is the draft design of the graphic novel version of this book, which may or may not happen..&lt;/p&gt;
&lt;p&gt;&lt;img alt=&#34;digital world cyberpunk&#34; loading=&#34;lazy&#34; src=&#34;https://digitalinfrastructures.nl/dig-inf-front-page1.png&#34; title=&#34;With a little help from Dall-e&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Positions of Power in IT</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/positions-of-power-it/</link>
      <pubDate>Sun, 09 Mar 2025 11:06:48 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/positions-of-power-it/</guid>
      <description>&lt;p&gt;One of the key aspirations of Digital Infrastructures at Scale is to equip you with the tools to shape and drive change in your professional environment—especially when your goal is to lead a transformation.&lt;/p&gt;
&lt;p&gt;Every stakeholder has power. Here I want to highlight two important positions of influence in IT where technology meets power are architects and auditors/assessors.&lt;/p&gt;
&lt;p&gt;IT architects are builders. They design new applications, platforms, and infrastructures that enable businesses to operate more effectively. A CRM system, for example, is not just a technical solution—it transforms workflows, communication, and decision-making. Similarly, infrastructure architects create digital foundations that accelerate the deployment of such applications.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What are AI Digital Infrastructures?</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/digital-inf-ai/</link>
      <pubDate>Sat, 08 Mar 2025 17:57:16 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/digital-inf-ai/</guid>
      <description>A trained LLM is just software needing a lot of RAM — tracing AI infrastructure from training data to &amp;#39;Inference as a Service&amp;#39;, the same as any other cloud model.</description>
    </item>
    <item>
      <title>How Can We Achieve Autonomy Over Our Digital Infrastructures?</title>
      <link>https://digitalinfrastructures.nl/posts/how-can-we-achieve-autonomy/</link>
      <pubDate>Sun, 02 Mar 2025 22:04:34 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/how-can-we-achieve-autonomy/</guid>
      <description>&lt;h3 id=&#34;building-our-own-cloud-kootwijk-rethinking-digital-sovereignty&#34;&gt;Building Our Own Cloud Kootwijk: Rethinking Digital Sovereignty&lt;/h3&gt;
&lt;p&gt;In the Netherlands, we are currently engaged in a heated debate about the undesirable dominance of big tech, particularly over a significant portion of the digital infrastructure of the Dutch government. This includes email, file storage, and many other forms of digital storage and processing—most of which are handled by American big tech companies.&lt;/p&gt;
&lt;p&gt;I am sure a similar debate is going on in many other countries.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrofitting Zero Trust on an existing application: an illustration</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/retrofitting-zero-trust-existing-application/</link>
      <pubDate>Fri, 28 Feb 2025 14:15:21 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/retrofitting-zero-trust-existing-application/</guid>
      <description>&lt;p&gt;Zero Trust Architecture is an approach to better cybersecurity. To many, it seems daunting to implement. But it does not have to be hard to start.&lt;/p&gt;
&lt;p&gt;Consider this hypothetical situation.&lt;/p&gt;
&lt;p&gt;You have an application with hundreds of thousands of sensitive records, let’s say client records. We assume that in this example it seems hard to implement MFA (Multi Factor Authentication) on it. What other controls can you implement to reduce the assumed trust? We can use the Kipling method, which is at the core of Zero Trust architectures, to engineer better controls. In short, the Kipling method is about the &amp;ldquo;who&amp;rdquo;, &amp;ldquo;what&amp;rdquo;, &amp;ldquo;when&amp;rdquo;, etcetera of allowed communication.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deployment diagrams for network security; fix this</title>
      <link>https://digitalinfrastructures.nl/posts/network-diagram-fix/</link>
      <pubDate>Fri, 26 Mar 2021 17:09:20 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/network-diagram-fix/</guid>
      <description>&lt;p&gt;A while back, I introduced my take on deployment diagrams for cloud and devops infrastructure. Some of the big points there are: it starts with intuitive drawings. Many people draw these things in similar ways, even without them having formal training.
In fact, formal training in architecture diagrams will not necessarily make those drawings easier to understand for the uninitiated.
But still. There are good drawings and there are drawings that can be improved.
My other big point is that deployment diagrams can be a great tool for security analysis. I am in some conversations with friends at banks who use them.
Recently I ran into the following example. Here is an &lt;a href=&#34;https://syang.substack.com/p/security-group-and-network-acl-in&#34;&gt;explanation of the difference between VPC and security groups&lt;/a&gt;. Great story, but I have some comments on the diagram, which used to come &lt;a href=&#34;https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Security.html&#34;&gt;from AWS itself&lt;/a&gt;, by the way, but has been removed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Small Example of Cloud Native Development</title>
      <link>https://digitalinfrastructures.nl/book/act3-delegation/tutorial-cloud-native/</link>
      <pubDate>Mon, 10 Feb 2020 23:29:51 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act3-delegation/tutorial-cloud-native/</guid>
      <description>&lt;p&gt;Cloud-native software development enables new practices. But it also requires them. It is a new level of working. However, putting all these new practices together requires integrating a lot of pieces.
To illustrate this new approach, I have started to develop a minimal application. Although minimal, I run it in production. Its basic function is to regularly pull out data from an air quality sensor into a cloud-based database. Together it is a few hundred lines of code.
Here are the major features of the example:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Ways to Go Cloud</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/three-ways-to-go-cloud/</link>
      <pubDate>Sun, 03 Jun 2018 17:06:57 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/three-ways-to-go-cloud/</guid>
      <description>&lt;p&gt;Public cloud migrations come in different shapes and sizes, but I see three major approaches. Each of these brings value in its own way, and they all have very different technical and governance implications.&lt;/p&gt;
&lt;h3 id=&#34;three-approaches&#34;&gt;Three approaches&lt;/h3&gt;
&lt;p&gt;Companies dying to get rid of their data centers often get started on a &lt;strong&gt;‘lift and shift’&lt;/strong&gt; approach, where applications are moved from existing servers to equivalent servers in the cloud. The cloud service model consumed here is mainly IaaS (infrastructure as a service). Not much is outsourced to cloud providers here. Contrast that with SaaS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why lawyers need to understand cloud</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/lawyers-need-understand-tech/</link>
      <pubDate>Thu, 03 May 2018 13:54:48 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/lawyers-need-understand-tech/</guid>
      <description>&lt;p&gt;Cloud is too important to leave to technical people.&lt;/p&gt;
&lt;p&gt;Cloud distributes responsibility for IT services across an IT supply chain. This supply chain is composed of independent providers. This implies that there are these companies have &lt;strong&gt;technical boundaries&lt;/strong&gt; that are matched by organizational and &lt;strong&gt;contractual boundaries&lt;/strong&gt;. This is new, we did not have that before the digital revolution.
Amazon calls this the &lt;strong&gt;shared&lt;/strong&gt; responsibility model for cloud security.
I would simplify that as:  &lt;em&gt;what do I do, and what do you do&lt;/em&gt;? For example, who is responsible for patching the Operating System in an IaaS service model?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Agile Requires Cloud</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/agile-requires-cloud/</link>
      <pubDate>Wed, 12 Oct 2016 15:12:04 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/agile-requires-cloud/</guid>
      <description>&lt;p&gt;Getting to value quickly has value in itself.
The faster you get to value, the better it is, generally.
We&amp;rsquo;ll discuss some of the reasons for that elsewhere.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Agile development&lt;/strong&gt; is all the fashion nowadays for getting to digital value quickly.
Why is that and what kind of digital infrastructures does that require?
Back in the old days, business software was primarily written to automate &lt;strong&gt;&lt;em&gt;existing&lt;/em&gt;&lt;/strong&gt; business processes. Those processes might change somewhat as a result, but in the core processes were no different. Think accounting systems, scheduling, &amp;ldquo;customer relationship management&amp;rdquo; and so on.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Top 8 cloud risks according to ENISA</title>
      <link>https://digitalinfrastructures.nl/posts/top-8-cloud-risks-according-to-enisa/</link>
      <pubDate>Thu, 21 May 2015 09:22:07 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/posts/top-8-cloud-risks-according-to-enisa/</guid>
      <description>&lt;p&gt;Does security in the cloud ever bother you? It would be weird if it didn’t. Cloud computing has a lot of benefits, but also a lot of risks if done in the wrong way.
So what are the most important risks? The European Network Information Security Agency did extensive research on that in 2009 already, and identified 35 risk categories. This analysis is used by a number of players in the industry, including certain banking regulators. From those 35, ENISA has selected 8 as the most relevant ones. This article explains them, not in any particular order. (And by the way: ENISA is pronounced as ‘eniesa’, not ‘enaiza’).
You can also get the story on my YouTube video.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Business Model Canvas for SaaS Providers</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/business-model-canvas-saas/</link>
      <pubDate>Mon, 15 Dec 2014 11:18:17 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/business-model-canvas-saas/</guid>
      <description>&lt;p&gt;Here is a high-level overview of the SaaS provider business model and some of the strategic options that are in there.&lt;/p&gt;
&lt;h3 id=&#34;business-model-canvas&#34;&gt;Business Model Canvas&lt;/h3&gt;
&lt;p&gt;In this unit, we&amp;rsquo;ll explore examples using two hypothetical SaaS providers: one offering bookkeeping software and the other a project collaboration platform.&lt;/p&gt;
&lt;p&gt;&lt;img alt=&#34;SaaS Cloud Canvas&#34; loading=&#34;lazy&#34; src=&#34;https://digitalinfrastructures.nl/book/act2-value/business-model-canvas-saas/BusinessCanvasSaaS.png&#34;&gt;&lt;/p&gt;
&lt;h3 id=&#34;customer-segments-cs&#34;&gt;Customer segments (CS)&lt;/h3&gt;
&lt;p&gt;In the Business Model Canvas, “Customer Segments” are the groups of customers that the company ultimately serves, I.e. the ones that consume and pay for the services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Business Model Canvas for IaaS Providers</title>
      <link>https://digitalinfrastructures.nl/book/act2-value/business-model-canvas-iaas/</link>
      <pubDate>Sat, 15 Nov 2014 11:18:17 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act2-value/business-model-canvas-iaas/</guid>
      <description>Mapping AWS EC2 onto the nine blocks of the Business Model Canvas, from customer segments to cost structure, to see what actually makes an IaaS business work.</description>
    </item>
    <item>
      <title>Automate or Die: A Capacity Planner&#39;s Rules</title>
      <link>https://digitalinfrastructures.nl/book/act5-risk/automate-or-die-capacity-planning/</link>
      <pubDate>Wed, 01 Feb 2012 07:21:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act5-risk/automate-or-die-capacity-planning/</guid>
      <description>&lt;p&gt;Even in a cloud world, reducing server count is a lofty goal in itself.&lt;/p&gt;
&lt;p&gt;After all, you would be paying for all those servers anyway. Understand that sticking all your servers in a private cloud makes them more flexible, but not necessarily more efficient or cheaper.&lt;/p&gt;
&lt;p&gt;Back in 2012 I did an interview with a guy who has a full time job in keeping those server counts down. Ron Kaminski is a capacity planner at Kimberly Clark Corporation (KCC). This interview is a composite of several conversations I had with Ron at the annual Computer Measurement Group (CMG) conferences, and a number of messages Ron wrote.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Directories are also infrastructures</title>
      <link>https://digitalinfrastructures.nl/book/act1-foundations/directories-are-also-infrastructures/</link>
      <pubDate>Thu, 21 Sep 2006 10:54:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act1-foundations/directories-are-also-infrastructures/</guid>
      <description>&lt;p&gt;One of the big projects I was working a while back is directory services for identity management.
In these directories digital identities such as login names, addresses, access rights, etc. are stored. With an adequately structured directory service, the proper management of access rights becomes a lot easier, which translates into cost savings and better security.&lt;/p&gt;
&lt;p&gt;Examples of these include the internet&amp;rsquo;s Domain Name System (DNS) and Microsoft&amp;rsquo;s Active Directory.
A lot of organizations however, have requirements beyond these systems, and for these a wide range of custom solutions are used.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Who made podcasting big?</title>
      <link>https://digitalinfrastructures.nl/book/act4-power/the-tipping-point-for-podcasting/</link>
      <pubDate>Mon, 05 Sep 2005 13:35:00 +0000</pubDate>
      <guid>https://digitalinfrastructures.nl/book/act4-power/the-tipping-point-for-podcasting/</guid>
      <description>&lt;p&gt;Podcasting has its own digital infrastructures, for example in hosting them.
Let&amp;rsquo;s look at how podcasting has grown, and what made it take off anyway?
Many actors influence each other here, and the state of the art of the technology also has an impact on growth rates.&lt;/p&gt;
&lt;p&gt;Suppose a hundred people get told by an enthusiastic friend to try podcasting.
Of these, ten don’t have any hardware on which they can play the podcasts.
So the rest goes online, and tries to find interesting content, but only 50 people can find a directory in which they can even start to look for podcasts that they like. Only 40 people then find content that they sufficiently like.
Ten people drop out because they find loading the content too complicated. Of these, another ten find out that the files are too big for the hardware they have (for example in 2005, they just had a simple MP3 player, no iPod or similar).
Of the ones left, another five don’t have the patience for the downloads (we are talking dial-up internet access for a lot of people here, still).
If you have been keeping tabs: we are down to 25 people who are capable and willing to regularly listen to podcasts. Now suppose each of these tells four friends, on the average. That means we are back to a hundred.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
