Alex Rudolph

122 Followers
180 Following
135 Posts

I research and publish on Canadian cyber defence policy, with a focus on CAFCYBERCOM. CGAI/Triple Helix & NAADSN Fellow.

Carleton University PhD(ABD): State behavior, doctrine, and force structures of cyber conflict.

I run Canadian Cyber in Context: cyberincontext.ca

Blueskyhttps://bsky.app/profile/cyberincontext.ca
CGAI Fellowhttps://www.cgai.ca/Alexander_Rudolph
Linktreehttps://linktr.ee/alexfrudolph
Websitewww.cyberincontext.ca

I have another new paper out with the Canadian Global Affairs Institute about the Canadian Armed Forces Cyber Forces, this time specifically about CAFCYBERCOM.

https://www.cgai.ca/th_pp_everything_you_should_know_about_caf_cyber_command

I have a new oped out with Digital Journal. I argue that in the face of vibecoding and AI's impact on software development, the Canadian government needs a secure-coding. Luckily, @SheHacksPurple already has one: https://www.ourcommons.ca/petitions/en/Petition/Details?Petition=e-7115

https://www.digitaljournal.com/tech-science/canada-needs-a-secure-coding-policy-and-ai-is-making-that-more-urgent

Petition e-7115 - Petitions

The latest Canadian Cyber in Context Canadian Cyber News Rewire is now out. I bring together cyber-related news concerning Canada from the past week. A lot is going on, including a new data centre, Bill C-22, and phishing emails to journalists with IP tracers.

https://www.cyberincontext.ca/p/canadian-cyber-news-rewire-210326

Canadian Cyber News Rewire - 21/03/26

Wiring you into the cyber news relevant to Canada the week ending March 21

Canadian Cyber in Context

My new article on the history of the Canadian Armed Forces cyber defence program is finally out! Come read the paper that the Canadian Security Intelligence Service was too scared to publish.

https://www.cgai.ca/th_pp_following_the_digital_snail_s_trail_the_short_history_of_canadian_armed_forces_cyber_operations

Canadian Program for Cyber Security Certification (CPCSC) is going to really disrupt Canadian defence procurement. It is the Canadian CMMC. My friend Andrew, a CMMC and compliance expert, wrote a good introduction for SMEs.

https://www.cyberincontext.ca/p/compliance-is-cash-where-to-begin

Compliance is Cash - Where to Begin with CPCSC

The Canadian Program for Cyber Security Certification can be overwhelming, so let us start with the basics

Canadian Cyber in Context

The Government of Canada hints at where it is taking sovereign cloud with the latest updates to the RFI.

https://www.cyberincontext.ca/p/canadian-government-provides-next

Government Provide Next Steps to Canadian Sovereign Cloud

Is the Government of Canada headed towards true sovereign cloud?

Canadian Cyber in Context

My latest paper about the Canadian Armed Forces and its efforts to achieve digital transformation and pan-domain capabilities.

The CAF has started its most important force and doctrinal change in decades, and few realize it.

https://www.cgai.ca/digital_transformation_and_pan_domain_the_cafs_quiet_revolution_in_military_affairs

I was invited by @VVX7 to speak in the @PreludeSecurity Discord on June 22 at 7 PM EST.

I'll be giving my talk "Global Affairs? In my Threat Model?" on ways to understand threats in global affairs.

Some of you may remember this talk as "Everyone is wrong about Cyber Warfare (Except me)."

I have since expanded on this talk and will specifically be discussing how to understand the role of global affairs in risk/threat models.

Looking forward to seeing you there! http://discord.gg/fZbfdUQM4A

Join the Prelude Security Discord Server!

Check out the Prelude Security community on Discord - hang out with 2,201 other members and enjoy free voice and text chat.

Discord
If Canadian military and its members would please move to anywhere but Twitter.

Ah yes, another high profile bug bounty forcing non-disclosure — even for fixed bugs.
🤦🏻‍♀️
It’s the bugs they won’t fix that will put users at risk.
All orgs need a vulnerability disclosure program that doesn’t ban Disclosure.
But what do I know.
I just coauthored the standard
#GPT

“But it’s a bug bounty & they are paying so it’s fair to ask for non disclosure”
That’s fine if everything submitted is paid work, like a penetration test.
Oh, only paying selectively & only the first of any duplicates?
That’s labor abuse & the worst gig economy deal out there.

“But pen tests don’t get you all the eyeballs”

Neither do bug bounties - you get a random number of eyeballs willing to sign NDAs.

If orgs actually care about security, they cast as wide a net s as possible to get the best researchers - especially those who won’t sign NDAs.

“This is better than no bug bounty”

No, it isn’t.

It breeds a false sense of security for users & the org itself, while actively excluding the highest skilled researchers who will never sign an NDA for speculative pay or who want to see the bugs FIXED as their motivation.