The practice organizes around a small set of durable theses, each directed by Christopher Braccia, Founder and Director of Research. Each theme collects the research, the incidents, and the argument in one place.
How states gain, hold and use access inside critical infrastructure.
The core of the practice: how nation-state operators acquire access to critical infrastructure, maintain it quietly, and convert it into espionage, disruption or coercion. The work reads campaigns across actors rather than treating each as an isolated incident.
What adversary preparation reveals before a crisis begins.
Living-off-the-land intrusions rarely serve espionage alone. They establish persistence to be exercised at a moment of the adversary’s choosing. Reading the preparation phase — including capability incubation — is the earliest available warning of a day-one threat.
The threats that become visible only when infrastructure is studied as a connected system.
Platform vendors watch one sector at a time; the adversary does not. The most important signals sit in the movement between sectors — a technique proven in one domain, then reused across communications, energy, transportation, space and the cables beneath them.
How geography and technology reshape the next generation of infrastructure threats.
Twelve-plus years across the U.S. and Southeast Asia inform a reading of the Indo-Pacific as the proving ground for capabilities that reach Western infrastructure — where capability incubation, artificial intelligence and new satellite and quantum systems are rewriting the threat.