July 26, 2026 · 1 min read

Ten years of evidence, ten years of answers

Why I left a product career to study cybersecurity — and what this blog will be about.

For ten years I worked at the exact point where systems meet people: patient-support programs, pharmacy platforms, privacy compliance across six national brands. Again and again I watched the same thing happen — the failure was rarely technical. It was a trust failure, under pressure, between humans.

This fall I start the BEng in Cybersecurity at Concordia. This blog is the public lab notebook for that transition: write-ups on what I build, notes on what I read, and the occasional post-mortem on what breaks.

Expect three recurring themes. Usable security in real clinical workflows — why controls that are correct on paper die at the pharmacy counter. Compliance as code — what it would take for regulation like PIPEDA, PHIPA and Law 25 to compile into verifiable properties of a schema. And the security boundary of AI-agent systems — the question behind my project Conductor, and the one I plan to carry into research.

Short posts, honest ones, no growth-hacking. If you work on any of the above, my inbox is open.