Representative Foreword

After the Code, the Structure Remains

The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.

This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

After the Code, the Structure Remains

Detection, Method, Governance

🔥 A Mind That Dissects Systems

🔥 Trust and Culture Beyond Technology

🔥 Code That Fixes, Not Just Runs

A Critical Reading of Structural Ethics in Cybersecurity Policy: Korea's 2025 Whole-of-Government Information Protection Plan

A reading of Korea’s 2025 whole-of-government information protection plan through the structural parallel between the Nightingale myth and the white-hacker discourse. Policy is moving from dependence on individual ethics toward structural accountability, but the transition is not complete.

May 24, 2026 · 15 min · 2991 words

The Moment AI Truly Becomes New: Not When It Finds the Answer, but When It Rewrites the Problem

Through the Nightingale myth, the white-hacker discourse, the Sterbenz lemma, and browser exploit reasoning, this essay argues that the real change LLMs bring lies not in knowledge retrieval but in problem reframing.

May 24, 2026 · 19 min · 3933 words

The Real Battleground of National AI Strategy Is Not Just GPU Count

The decisive front in national AI strategy is not GPU count alone, but who controls and can prove the flow of data, models, agents, permissions, logs, and verification running on top of those GPUs.

May 24, 2026 · 11 min · 2212 words

Supply Chain Security Does Not End with SBOM: Governing AI Development Tools and Automation Connections

AI IDEs, MCP, and automation connectors are not merely developer convenience tools. They are supply-chain assets that affect the trust path of how code is written, reviewed, and shipped.

May 2, 2026 · 8 min · 1685 words

Why Security Knowledge Transfer Fails — and What to Design Instead

An organizational design report that reframes the security–DevOps problem from failed knowledge transfer to default design, interfaces, exception handling, and alignment.

April 21, 2026 · 25 min · 5279 words

Contracts vs Security Governance — Contracts Enforce. Governance Decides.

Why security governance must drive decisions before contracts enforce them—a structural reframing for security leadership.

February 13, 2026 · 4 min · 784 words

eIDAS 2.0 vs. Korea’s Digital Identity System: A Comparative Analysis

Comparative analysis of EU eIDAS 2.0 wallet-based identity and Korea’s mobile ID system across governance, privacy, and operations.

January 19, 2026 · 8 min · 1657 words

The Visibility Principle: How Internal Vulnerability Visibility Shapes Remediation Behavior

How transparent internal vulnerability visibility drives remediation through accountability and deterrence without formal punishment.

December 29, 2025 · 6 min · 1080 words

Attack Surface Management in 2025: Why Continuous Visibility is Essential

Why continuous attack surface management is critical in 2025, covering AI-driven discovery, shadow IT, and zero trust integration.

December 22, 2025 · 11 min · 2330 words

Is Your Data in the Cat's Paws?

Analysis of the 2025 KakaoPay breach exposing 40M users’ data, and why formal consent fails without AI-based DPIA and civic oversight.

April 21, 2025 · 6 min · 1156 words