RSSAmplifier

Blog

Digital Promises on Digital Infrastructures at Scale

Recent content in Digital Promises on Digital Infrastructures at Scale

digitalinfrastructures.nlRSS feed ↗107 posts

Latest posts

The Real Story Behind the OpenAI 'Escape'

An unnamed OpenAI model allegedly ‘broke out’ and ’escaped into the wild’ from its ‘highly isolated sandbox’ and then hacked Hugging Face. The story is all over the internet warning about the power of current day LLMs. But that is not what happened. Don’t let popular trade press stories confuse you. They can be nice cyberpunk narratives, they may be…

Why we signed the cloud deal

Let’s look at a realistic and uncommon story of cloud and outsourcing. It illustrates what value a customer got and how they got there. Aegon Levensverzekering N.V. is a life insurance company that needed to comply with what’s called the Solvency II regulation, which required reporting the net-present-value (NPV) estimate of its entire life-policy portfolio, millions of policies across…

Software Dissemination

How software grows A lot of software begins its life as the project of an individual, but ends up being used widely in organizations, or even society at large. I have seen many Excel files that started out as a small set of notes and grew to be the operational backbone of entire departments. Examples I have seen include complete bookkeeping ledgers, customer relationship systems, and planning…

Counting the copies: how an AI wiki helped me read my father's digital legacy

The root cause In the 1990s my father’s health deteriorated as a result of what was later thought to be some immune system related disease. He found out that living in warm climates with little pollution and no need to stay indoors for very long helped him maintain his health. So he took a bold move, sold his house, and became a traveling academic. In the summers he would stay in the south…

Benchmarking Local Coding Models

Can IBM’s Granite 4.1 code? I ran it against other local models to find out Full transparency : Except for some initial prompting, most of this blog and the research behind it was AI generated. I did check everything manually though. While I tried to include all relevant files in this repo , reproducibility may be hampered by some of my older Claude contexts leaking into this process (e.g.…

Digital autonomy: Controls

Suppose you are a government, a regulator, or a concerned cloud consumer. What can you actually do to mitigate sovereignty risks and achieve adequate autonomy? The honest starting point is that full digital autonomy, autarky, is not achievable, and not worth pursuing. Read here for more on that . No well-developed country is fully independent of others. The goal is not independence, but…

The Prisoner's Dilemma

The game of trust How do people establish trust under the most adverse circumstances? How can sworn enemies get into a position that it makes sense for them to help each other. In game theory, this is the surprising phenomenon that the prisoner’s dilemma aims to explain. Imagine two suspects held by the police who don’t have enough evidence against them. Their choices (game moves) are…

Digital autonomy: Autarky

Autarky Implicit in many discussions on digital autonomy is the quest for “autarky”, being completely independent from other actors, for example those actors whose objectives may be in conflict with ours. This is driving the call for national cloud providers, local manufacturing, and more open source, to name just a few. Autarky, however, is just one tool for establishing autonomy, and…

Digital autonomy: The risks

Many people think we are overly dependent on big tech, and we should be more autonomous and sovereign. Fewer can say what exactly is the risk here. Digital autonomy and sovereignty form a wicked problem: its parts are intertwined with many other issues and conflicting interests, so there is no clean solution. Before reaching for solutions, it pays to be precise about the risk. At risk is our power…

Digital Autonomy: the Actors

Achieving some form of digital autonomy or sovereignty is a wicked problem , too large to handle in one go. Let’s start therefore with the main actors, and what is at stake for them. We can then talk about how digital autonomy allows these actors to collaborate and compete, and therefore impacts the risks they see. Elsewhere, I write about international actors , and this story builds on…

A badge on the wall

A badge on the wall: repurposing hacker camp hardware as a home energy display I wanted a wall display for my house’s energy. Not an app, but something glanceable, always on, no clicks required. Apparently that’s harder to buy than it sounds. On a sunny day, it makes sense to turn on energy-intensive appliances such as washing machines, because the energy surplus from our solar panels…

Why You Work: Amateur, Professional, or Passionate?

Have you ever been called an amateur? It stings. It shouldn’t be. Amateurs The label ‘amateur’ has a negative feel, it refers to unskilled workers, hobbyists, and poor results. But the word actually derives from the Latin ‘amare’, meaning to love. So an amateur is somebody who is doing it for the love of it. They come to their work for play, for fun, and discovery.…

Local AI inferencing or cloud based?

I am trying to figure out where the pendulum for AI LLM inference hosting will swing to. Will we have more cloud service usage of the cloud hyperscalers, or will inferencing be on local devices such as laptops or in corporate datacenter? Here is my thinking. I believe Moore’s law will be relevant for a few more years, implying that an affordable supply of local capacity will grow. I also believe…

Architectural Integrity, Angkor Wat, and open source

Angkor Wat (Cambodia) is the world’s largest religious building and site. Built in the 12th century, it is still a stunning building, featuring high symmetry and perfect north-south alignment. As I was visiting this and other temples, I got to think about architectural integrity. For example, Angkor Wat has 4 major towers around a central tower. I call that an architectural feature. Symmetry…

How are AI Agents Self Aware?

I was chatting with an AI agent about its own configuration, and it answered with surprising confidence. Then I thought: wait. How would it even know that? This post is about what I found when I went looking. Nanobot is a deliberately simpler version of OpenClaw . If you haven’t heard about it, OpenClaw is an AI agent running on your behalf 24/7, potentially having all your credentials. This…

Securing my AI travel mail bot

I wanted to experiment with AI automation while also paying particular attention to security concerns. Security is something I take seriously (I delivered cloud security training for more than 10 years), and the power that AI has is very scary. There are lots of frameworks related to AI security, and I feel that it is hard to apply them to the real world. For example how would you mitigate LLM06 –…

Wicked problems in 2026

As 2025 ends, I reflected on the major topics that I see evolving in my practice. They are digital sovereignty and AI security, in particular the security of AI agent systems. These are systems where AI is not just used as an advanced data processor, but is undertaking autonomous actions. I focus specifically on so-called wicked problems: problems that do not have simple solution because they are…

What certificate to pursue

A question I often get is “what certification or knowledge should I pursue to get me a better job?”. Or variants such as “which cert is going to get me employed?”. Here is my opinion on it. Certificates only bring you so far. Most companies aren’t looking for people with knowledge. They are looking for the results that the knowledge brings, such as improved processes,…

Non-Monetary Values

Money isn't the only currency of value. Belonging, identity, and professional pride shape IT decisions as much as budgets do — and are a source of power in their own right.

AR newsletter Nov9 25

(sent nov 11. How to make AI work for you) By now, you probably had your first encounters with AI. What did you run into? Would love to know about that. While I am currently on a sabbatical, these things are top of mind for me. For me, I am focussing on two AI directions. Given my background in cloud security, I cannot help but think about AI security and governance.

How Claude Flow helped me create my next tool

After coding a demo application with Claude Flow it was time to do a larger project. Claude Flow allows the distribution of coding work over a variety of agents. Each of the agents has a specific role in the project, such as coder, tester, analyst, and others. These agents create stuff, inform each other, and check each other’s results. But even after a few projects, I still find it…

Cloud Security and AI

How can you use cloud security lessons to better secure AI? This is what is keeping some of my clients busy recently. Arguably the most important concept in cloud security is the allocation of responsibilities across the independent actors that contribute to any digital service. Often referred to as ‘shared responsibility’, this is about ‘who does what?’. For example, in an…

Data, Risk, or Controls: where to start?

Where do you start your IT security journey? It is important, but it can be confusing. For many organizations, the trigger is a compliance obligation to show that confidential information remains confidential. Maybe their customers are asking for an ISO/IEC 27001 certification, demonstrating that an IT risk management system is in place. Maybe they are handling credit cards and therefore need to…

Testing RSS updates

Testing RSS

OWASP LLM Risk Allocation

Applications based on LLMs (Large Language Models) have risks too. The OWASP Top 10 for LLM Applications risks are a good start for analyzing the risks of such a system. These types of applications, like many others, are also cloud applications. This means that there is a variety of parties responsible for controlling those risks. But, who is supposed to do each control? And which role do they…

AI Roles and Responsibilities

Six roles run every AI system, from customer to data provider, each bound by its own promise. Based on the CSA AI Controls Matrix.

Agentic coding, the next level

My AI coding journey continues. My first version of the Tic-Tac-Toe game took some time to get right even though I already applied some serious automated top-down design. As explained, understanding feedback loops is crucial for correcting errors. Part of this is using explicit tests for desirable outcomes. A process for test-driven design would be even better. The main question from that…

Compliance is a Risk

For people who care about risk in IT, compliance is a mixed blessing. Compliance regulations can lead to better risk management, but sometimes it is more of a hindrance than a help. Compliance in IT generally means compliance with regulations that are set up to reduce risk, for example, across a chain of actors. A great example is the PCI/DSS regulation, which governs everybody who touches a…

Promise to Update

An important part of managing digital infrastructures is updating various software components. It does not matter if we are talking about operating systems, applications, AI models, configurations, software libraries, and so on. What matters is: who is going to do that? Updates happen for many reasons, but the major ones are: new functionality better security. As you can imagine, there are…

Games of value and power

A great way to look at how value is created in interactions between autonomous actors is game theory. How do autonomous actors respond to other actors? This is the core question here. How do you respond to an offer from a service provider? But also, how do they respond to you? I have found game theory to be an effective model to think about the outcomes of sequences of interactions. This is…

Why 2025 resources

Digital Power: The book For the book and my blog, here is the link: https://digitalinfrastructures.nl . Coaching for professionals I run a group coaching program for senior IT professionals. This addresses knowledge and skills in technology, governance, and your own career objectives. Read more on this page . Presentations at WHY 2025 PDF: How to bluff your way into Zero Trust PDF: Using…

Cloud Computing

Cloud Computing is an important and big set of digital infrastructures. Between 2000 and 2010, as the internet was growing in reach, it also became a vehicle for the delivery of compute services. Back in the day, Application Services Providers, as they were known, offered software remotely, so it was no longer necessary to install it in a company’s datacenter. I could tell horror stories…

AI Coding: "Look Ma, no hands!"

Here is how I AI-coded a fully functional Tic-Tac-Toe web game without looking at a single line of code or manually identifying a GUI or logic error. I ran Claude Code (Pro) in VS Code without any other IDE/AI tooling. But it takes some effort and discipline to get there. The core idea is to be very specific and use an opinionated environment that includes extensive automated testing. The Agentic…

AI coding rabbit holes

The approach People call LLMs statistical completion engines and that they therefore cannot write computer code. While the first may be true, the conclusion not necessarily follows. My answer to this question: let’s try this out! Inspired by modern discoveries in, for example, context engineering and swarm coding (references to come) I decided to give AI assisted coding a shot. I had a…

A guide to digital sovereignty, autonomy, and business resilience

Imagine that you are part of the government of an average nation, and you have just realized that IT has become a substantial factor in your operation. Or you have a similar position in a manufacturing industry, or in the financial sector. As IT increased in volume, you have tried to keep its costs down, it was just a facility. Outsourcing to more experienced partners was an option, and so was the…

The Automation Business Case

Automation is a big part of IT, but not all automation brings value. Automation takes time and effort, upfront, and any benefits come later. Think of the IT projects you were involved in, most of those aimed at providing a measurable benefit somewhere. This diagram (from xkcd, a series of webcomics) illustrates when automating repetitive tasks, or even just parts of them, brings benefit. In other…

Can AI automate compliance?

My AI-supported risk analysis assistant mirrors a common pitfall in risk management: focusing on irrelevant controls rather than genuine threats. I have created a risk analyst AI based on industry best practices, or so I assume. This is part of a quest toward more compliance automation, because as an industry we are falling behind in security. I am running through a simple example of a chatbot…

How I Got Started in Computer Networks

My first interest in networking came in the early 80s, as I was in the final years of my mathematics and computer science master’s program. At the time, dial-up terminal networking was about the most advanced there was. And if you were lucky, you’d get 1200 baud (transmitting approximately 120 characters per second). My current fiber-optic home links are 1 Gigabit/sec, which is about 1…

Shared Services Lead to Conflicts

Digital infrastructures serve, nearly always, multiple customers. These customers therefore share the resources provided by these digital infrastructures. With that sharing comes the potential for conflicts over those resources. When I talk to my friend over the phone, we share a connection, and that is exactly when sharing is part of the value of that infrastructure. But when multiple users draw…

Zero Trust Myths

What is the problem with the image that Zero Trust based information security brings along? Once you understand the principles, and they are not really difficult, it is obvious that only ZT can lead us to a more secure cyber future. So, what is holding us back? Here are some of the misconceptions: “It is a boatload of work, so let’s not start.” Truth: yes, fully securing your IT…

The AI Coding Age

This is the dawn of a new age. I have been observing software development for more than fifty years, ever since I wrote my first computer program. In that entire time, I have never witnessed a development that has changed the profession deeper, faster, or more pervasively than now. AI-assisted coding has escaped from the lab, and is impacting the work of every software developer. In the…

Lean Risk and Economics

From the moment a security vulnerability is discovered, it represents a negative value to its potential victims. When it gets exploited, it can lead to loss of data or loss of integrity of the data. This in turn impacts the victim’s business processes. For example, if personal data is leaked, reputations will be damaged, financial losses and fines can be expected. Credit card abuse forms…

AI will replace coders, not software engineers

If you build software for a living, generative AI may be a scary development, as it has the potential to take over a lot of software creation. But I think it depends on what you see as the job of creating software. A coder in the world of IT is somebody who writes code in some programming language. More typically they modify code instead of writing it from scratch. This is in response to bugs,…

Vibe OPSing with MCP: proof of concept

Here is the story of how I started to use AI to help with running and securing my home network. I call it vibe ops, in analogy to vibe programming. This post is going to be obsolete very soon, even though it is already the second version … My home network plays an additional role as a nice lab, and in the process of better securing it, preferably with Zero Trust Architectures, I am doing…

Where the buck stops

The US president Harry S. Truman famously had a sign on his desk that said: The buck stops here. This refers to the process of “passing up the buck”, meaning to escalate decisions to the next higher level in the organization. Truman implied that he took responsibility but also that this is where power comes from. This is an essential part of governance, and this vertical line of…

Contracts are complementary promises

Once we understand promises, contracts between agents now become really simple to express. They are a set of complementary conditional promises: “If you do this, I will promise that”. In our example this looks like the following. “If you promise to pay me, I will promise to bring you coffee.” “If you promise to bring me coffee, I will promise to pay you.” If one…

A Unified Framework

The units so far have explored quite a few, seemingly unrelated, concepts and observations. Here we’ll embed them in a unified framework that illustrates how they fit together. From the title of this book you can see that the main pillars of that framework include value, power, and risk. To get there, we need a fourth pillar: change. For now, we’ll call these pillars layers, though…

Information Security Assets

Let’s dive a little deeper into assets. The most relevant asset in information security is data. That is what users of information care about most. In addition, we can also see the processing power that we need as an asset. Here are some examples of data assets: A customer record in a business system An MRI scan A browser cookie (on the server) A logfile entry As you can guess from these…

What is the value of information?

What is information really? If we know that, we can try to understand how we can judge its value, or even start to understand how we can create value with information. In Claude Shannon’s theory of communication, information is about reducing uncertainty. Another way is to say that more information means less noise because if you add noise to information, that information will have more…

Why Organization Size Determines Who You Trust

Below 150 people you know who to trust by name. Above it, Dunbar's number kicks in — trust gives way to roles, processes, and bureaucracy.