Engineering resilience for cyber-physical systems

When the adversary is already in your system, what prevents a catastrophe?

I help engineers and operators redesign critical systems so that compromise, bad information, or loss of control does not become catastrophe.

Tell me the problem
Critical infrastructure · OT · automation · safety-critical systems
What I do

I work on the part of resilience that happens after prevention fails.

Cybersecurity can reduce access and improve detection. Engineering can change what that access is capable of producing. I look for the conditions that turn a compromise or failure into an unacceptable physical or operational consequence—and redesign those conditions.

01

Find the consequence

Define the outcome that matters, not simply the attack or failure that precedes it.

02

Trace the path

Work backward through controls, dependencies, data, energy, materials, people, and assumptions to find what makes that outcome possible.

03

Break the path

Use engineering changes, physical constraints, independent controls, simplification, redundancy, passive behavior, or controlled fallback modes to deny the consequence.

How an engagement works
01

Name what cannot happen.

Rupture. Contamination. Collision. Uncontrolled energy. Loss of a critical function. Whatever the actual boundary is, start there.

02

Find what crosses the boundary.

Identify the small set of conditions, commands, dependencies, and trusted assumptions that can carry the system from normal operation to that consequence.

03

Change the system.

Redesign the path so the consequence is eliminated, bounded, redirected, or recoverable—even when the digital layer cannot be trusted.

The question

Sensors can lie. Commands can be compromised. Automation can fail. What remains?

Physical constraint

Limit the effect.

Put a hard boundary around a dangerous variable, quantity, force, pressure, speed, or energy source so software cannot simply command its way past it.

Independence

Separate the backstop.

A second safeguard only helps when the same compromised dependency cannot defeat both pathways.

Graceful degradation

Keep the mission alive.

Design for constrained, manual, passive, or recoverable operation when trustworthy automation disappears.

Start here

What’s your problem?

Bring me the system, the consequence you cannot tolerate, or the design decision you do not trust. I can start there.

Tell me the problem