The vulnerability was real. The attack was not.
One word in Microsoft’s revision note caught my eye: “informational.” The underlying change was anything but routine. Microsoft had published CVE-2026-69836 as an exploited…
Read the essayRegional Field CTO at DigiCert
I write about the decisions behind secure devices, trusted software, and AI systems—and the evidence teams need to get them right.
Latest writing
One word in Microsoft’s revision note caught my eye: “informational.” The underlying change was anything but routine. Microsoft had published CVE-2026-69836 as an exploited…
Read the essayThe question after the July 29, 2026 2026 Minimum Elements for a Software Bill of Materials update is not whether every software company must sign an SBOM. The joint guidance,…
Read the essayOn Thursday, the FBI gave the water-sector cyberattack story its first national count. Utilities in at least seven states had reported incidents since July 27, and some had…
Read the essayFour connected subjects
Practical guides, field notes, and questions for your team. A personal perspective on the decisions that connect these subjects.
Identify, update, isolate, and recover the systems you operate.
Explore this subjectConnect product evidence with what buyers and regulators need.
Explore this subjectFind the dependencies before certificates and algorithms change.
Know what an agent can do, what constrains it, and what can be proved.
Explore this subjectThe dates do not move
The regulatory deadlines and standards transitions reshaping enterprise digital trust between 2026 and 2030. Know what is adopted, who it affects, and what to ask your team.
Manufacturers must report actively exploited vulnerabilities and severe security incidents. Early warning is due within 24 hours of awareness; the next notification is due within 72 hours. Final reports follow separate clocks.
Certain providers of synthetic-content AI systems placed on the market before 2 August 2026 must meet Article 50(2) marking requirements by this date.
New acquisitions for U.S. National Security Systems must be CNSA 2.0 compliant unless an exception applies. Deployment requirements also depend on the relevant validation profile.
Reviewed September 2026 · Quarterly review cadence · Primary sources linked in the full calendar.
Guides & resources
Practical reading from the archive, with questions and frameworks to use in your own environment.
A starting point for testing whether one compromised device can be isolated without disrupting the rest of the fleet.
Find where public certificates are used for client authentication, and identify what needs to change.
A security review framework and reusable prompt for examining an AI coding assistant’s access.
About Tim
I’m Regional Field CTO at DigiCert. My work connects PKI, device identity, software assurance, and AI with the engineering and operating decisions organizations face.
This is my personal publication. Views are my own.
More about my workSpeaking & collaboration
Keynotes, panels, and workshops on device trust, cryptographic change, software assurance, and the authority we give AI systems.
Past speaking includes Embedded World, CES, and RSA Conference.