Compliance
Compliance as architecture: not a checklist at the end of the project but a design decision on day one, and it fails for lack of inventory.
There is one thesis here and I’ve been repeating it for years: compliance is architecture, not a legal appendix. Reporting an exploited vulnerability within 24 hours, producing an SBOM, proving what a given software version did on a given day are properties that exist only if the system was built to have them. When an organisation fails, it is almost never for lack of rules: it is because it doesn’t know what it has in the house. These essays are about that work, with names, dates and articles of law.