From SecurityBlanket to SecurityNet

After SecurityBlanket was successfully deployed within ING, I naturally assumed the next challenge would be finding other organisations that needed it.

Technically, I knew it worked.

It was protecting real banking systems across Europe.

Surely that would make it easy to sell.

It didn't.

Like many engineers, I believed that if you built a better solution, people would naturally recognise its value.

I was wrong.

Looking back, I found myself facing exactly the same problem that we had experienced years earlier with Integrated Solutions.

Finding a genuine problem was one thing.

Building a working solution was another.

Explaining why people needed it proved to be the hardest part of all.

That lesson would stay with me for many years.


Although I continued working on banking projects, SecurityBlanket never really left my mind.

Every contract taught me something new about how organisations handled sensitive information.

The technology changed.

Networks became faster.

The Internet became central to almost every business.

New messaging platforms appeared.

But one thing never changed.

Information was still moving from one computer to another.

And every movement still created an opportunity for that information to be exposed.


Eventually I found myself back in investment banking, this time working at Bank of America Merrill Lynch.

By then I had spent decades designing systems for some of the world's largest financial institutions.

When the bank announced a reduction in contractor rates, I found myself asking a simple question.

Did I really want another contract?

Or was it finally time to build something of my own?

I chose the second option.


I already had a starting point.

SecurityBlanket had proved the architecture.

Rather than beginning with a blank screen, I once again reused what I had already built.

I removed everything that was specific to banking and kept the parts that still solved a universal problem.

That became the foundation of SecurityNet.

It wasn't a rewrite.

It was an evolution.


Just as I had done with SecurityBlanket, I looked for proven building blocks rather than trying to invent everything myself.

This time I needed something different.

The challenge was no longer encrypting files.

The challenge was helping two computers find each other across the Internet.

I eventually discovered a development toolkit for P2P operations.

It already provided secure peer-to-peer communications, automatic AES encryption, connection discovery and mediation between computers that could not establish a direct connection.

Those were exactly the capabilities I needed.

Once again, I wasn't trying to reinvent mature technology.

I wanted to integrate proven components into a larger architecture.


Integrating the P2P component turned out to be far harder than I expected.

The toolkit was designed around events.

SecurityNet was designed around a defined business process.

The two didn't naturally fit together.

I eventually solved the problem by writing my own control loops, allowing SecurityNet to wait for the appropriate events before moving to the next stage of the process.

From the user's perspective, everything appeared straightforward.

Behind the scenes, a considerable amount of orchestration was taking place.


At first, SecurityNet concentrated on secure file transfer.

That seemed the obvious place to begin.

But while studying the market I noticed something interesting.

People weren't simply transferring files any more.

They were communicating.

Signal.

WhatsApp.

Telegram.

Microsoft Teams.

Secure messaging had become part of everyday life.

The more I studied those products, the more another question began to form.

Were they really solving the privacy problem?

Or were they simply encrypting messages while still generating enormous amounts of metadata?


That question changed the direction of the project.

I stopped thinking purely about encryption.

I started thinking about privacy.

The two are related.

They are not the same thing.

Encryption protects content.

Metadata reveals behaviour.

Who communicated with whom.

When.

How often.

Using which device.

Sometimes that information is almost as revealing as the message itself.


That realisation led to one of the most important design decisions I have ever made.

I deliberately chose not to build a phone app.

At first glance, that probably seems like a commercial mistake.

From a privacy perspective, I believed it was exactly the opposite.

Modern smartphones generate extraordinary amounts of metadata simply by existing.

They know where they are.

Who they belong to.

Who they communicate with.

Often they reveal information before an application has even started.

I wanted SecurityNet to begin from a different assumption.

Reduce unnecessary metadata wherever possible.

That decision continues to shape the product today.


Looking back, I can now see that SecurityNet wasn't really the successor to SecurityBlanket.

It was the continuation of a much longer journey.

For over thirty years I had been asking essentially the same question.

How do you protect information while it is moving?

Eventually I realised there was a second question that mattered just as much.

How do you protect the information about the information?

That question is still shaping SecurityNet today.


Next: Why protecting the information itself isn't enough—and why security and privacy are not the same thing.