Cybersecurity is one of the most consequential fields in the world. The people working in it protect hospitals, elections, financial systems, critical infrastructure, and the personal data of billions. They do this work largely in anonymity, often under extraordinary pressure, and the hardest lessons from that work usually stay locked inside the organizations that lived them.
Aviation learns from its disasters because someone writes the report. When a plane goes down, an independent board pieces together the timeline, names the causes, and publishes findings the whole industry absorbs. Cybersecurity has been asking for that same function for more than three decades. Plenty of incident analysis gets done today, but it lives in vendor reports, private post-mortems, and government documents that can disappear when an administration changes. What has yet to emerge is a lasting public institution: one that assembles the full record of a major cyber incident, cites every claim, admits every gap, and gives everyone the same account to learn from.
The Obsidia Project is built on the model of the safety board. It is an independent 501(c)(3) nonprofit producing Casebooks, citable public case studies of the incidents that shaped the field, from Colonial Pipeline to Salt Typhoon. Every report draws only on the public record, follows the evidence wherever it leads, answers to no vendor or government, and cares more about the lesson than the villain.
The Obsidia Project is built to be that institution.
Fields of Activities