Research that turns emerging risk into architecture decisions.
Our research program focuses on where security architecture is changing fastest: digital sovereignty, post-quantum migration, AI systems that can take action, and critical infrastructure where cyber events can create physical or service consequences.

Four questions guide the current research agenda.
Each theme is developed as practical architecture research rather than generic trend commentary.
Where does practical control really reside?
Research examines identity, data, cryptographic custody, supplier concentration, software provenance and recovery as the control system behind digital sovereignty.
- Administrative authority
- External dependency and jurisdiction
- Recoverability and reversibility
How can cryptography change without destabilizing the enterprise?
Research focuses on inventory, confidentiality horizon, crypto agility, supplier readiness and migration sequencing for long-lived systems.
- Cryptographic discovery
- Migration prioritization
- Agility and interoperability
What should an AI system be allowed to know and do?
Research connects model and agent security to identity, tool use, authorization, data policy, telemetry and incident containment.
- Agent identity
- Tool and data boundaries
- Runtime assurance
What happens when digital failure becomes operational failure?
Research examines IT/OT dependency, safe degradation, remote access, recovery architecture and trusted restoration in high-consequence systems.
- Operational consequence
- Safe degradation
- Trusted recovery
Architecture input, not a substitute for environment-specific assessment.
Research briefs are intended to help executives, security leaders, architects and technical teams frame decisions. They are not legal advice, regulatory determinations, certifications or a substitute for assessment of the actual systems, contracts and requirements that apply to an organization.
Cyber Safety for Critical Infrastructure: Designing for Consequence, Not Compliance
A resilience-first security model that connects cybersecurity controls to operational consequence, safe degradation, recovery, continuity and trusted restoration.
Read research ↗
Securing AI Systems: Identity, Model Integrity and Runtime Assurance
A cyber architecture for models and agents that connects AI-specific risk to identity, data security, software assurance, monitoring, control and incident response.
Read research ↗
Post-Quantum Security: Building a Cryptographic Migration Roadmap
How organizations can inventory cryptography, prioritize long-lived exposure, build crypto agility and migrate toward post-quantum standards without destabilizing critical systems.
Read research ↗
Sovereign Cybersecurity for Canada: Control, Resilience and Strategic Autonomy
A practical architecture for preserving control over identity, data, cryptography, critical workloads, technology dependencies and recovery in an interconnected digital economy.
Read research ↗