CRA Isn't New. OT Just Wasn't Listening.
The EU Cyber Resilience Act is panicking the OT world. Mission-critical software has shipped under stricter rules for thirty years. The standards aren't the problem. The architecture is.

Software isn't art; it's engineering. Complexity is the enemy of security. I don't look for 'intricate details'—I try to eliminate them. By keeping the code and architecture simple, I build systems that are actually robust. You can't secure what you can't understand.
I spent most of the last 15 years writing code, designing, securing and breaking systems. Some of my random thoughts are collected in my blog.
The EU Cyber Resilience Act is panicking the OT world. Mission-critical software has shipped under stricter rules for thirty years. The standards aren't the problem. The architecture is.
Coding agents made writing code fast. They did not make software fast. The bottleneck just moved.
A 12-lesson course that rebuilds the DeepLearning.AI spec-driven development tutorial on Rust + sphinx-needs — and the AgentClinic domain you build to learn it.
Short thoughts, posted occasionally.
The argument for Rust in 2026 isn’t safety. It isn’t speed. It’s that AI writes it better than it writes C++. The compiler answers fast. The model listens. Every error is a free lesson. Rust got built for this work ten years before anyone needed it to be.
trying to be a dev, DevOps, DevEx, manager, and CTO at the same time is a one way ticket to burnout town on the express lane
Agile in the Age of AI. There’s so much in there and it’s all really good. Highly recommended.
Inspiration comes from looking at the data. My career started with game hacks—poking at binaries to see what the hardware was doing. Since then, I’ve worked across different domains and languages, always looking for the simplest way to make the computer do the work.





