How can organisations systematically integrate forensic readiness, incident management, and risk governance into their operational IT environments? As regulatory frameworks such as DORA impose new requirements on digital operational resilience, there is a growing need for technical mechanisms that not only detect and respond to incidents, but proactively ensure that systems are verifiable and auditable before incidents occur.
A key area of interest is how automated cryptographic verification can strengthen forensic readiness in critical infrastructure — enabling organisations to demonstrate compliance empirically rather than contractually. This connects dependable and safety-critical systems, where logging, fault tolerance, and verification under resource constraints are foundational concerns, with the sociotechnical domain of how organisations, regulatory structures, and technical architectures interact to produce — or inhibit — resilience.
Hur kan organisationer systematiskt integrera forensisk beredskap, incidenthantering och riskstyrning i sin operativa IT-miljö? I takt med att regelverk som DORA ställer nya krav på digital operativ motståndskraft ökar behovet av tekniska mekanismer som inte bara upptäcker och hanterar incidenter, utan proaktivt säkerställer att system är verifierbara och granskningsbara innan incidenter inträffar.
Ett centralt intresseområde är hur automatiserad kryptografisk verifiering kan stärka forensisk beredskap i kritisk infrastruktur — och möjliggöra för organisationer att demonstrera efterlevnad empiriskt snarare än kontraktuellt. Detta kopplar samman tillförlitliga och säkerhetskritiska system, där loggning, feltolerans och verifiering under resursbegränsningar utgör centrala frågor, med den sociotekniska domänen om hur organisationer, regulatoriska strukturer och tekniska arkitekturer samverkar för att skapa — eller hindra — motståndskraft.