Can the Market Move Governance?
Policy is not the only thing that creates change. Once external actors — insurers, customers, supply chains, evaluation services, security SaaS — start pricing the cost, governance eventually follows.
Representative Foreword
The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.
This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

Detection, Method, Governance
Policy is not the only thing that creates change. Once external actors — insurers, customers, supply chains, evaluation services, security SaaS — start pricing the cost, governance eventually follows.
To move from compliance capability to adaptive capability, what do we measure? This post proposes MTTA, MTTP, MTRS, and a minimal execution template for the field.
A game-theoretic analysis of why Korean security governance stays stuck when NIS, KISA, the Board of Audit, the security industry, CISOs, and policy agencies are each acting rationally.
Korean security governance in the AI era needs to change not the title of any one agency, but the behavior that evaluation rewards.
A deep dive into why common SSRF defense code is often incomplete, real-world bypasses, and practical, layered mitigation strategies for developers and security engineers.
Mitigation guide for CVE-2022-24434 in the Dicer module affecting Multer and Express, with practical dependency chain fixes.
Automating Snyk vulnerability alert management with Google Apps Script and Gmail when official API access falls short.
The CVE system nearly collapsed in 2025. Who should fund public cybersecurity infrastructure when free-riding is no longer sustainable?
Debunking developer security myths around responsibility deflection, tech overconfidence, and risk underestimation with real-world examples.
Comprehensive analysis of XML-RPC security flaws including RCE, XXE, and DDoS, with mitigation strategies and a Python PoC exploit.