Internet infrastructure
BGP, IPv4/IPv6, IS-IS, OSPF, MPLS, EVPN/VXLAN, peering, transit, address policy, RPKI/ROV and the operational bits that make a service-provider network stay useful.
NETWORK OPERATOR / SYSTEMS ENGINEER / SPEAKER
I work on Internet routing, systems infrastructure, routing security, cyber-defence exercises and local AI platforms. Most of my useful work happens where a neat diagram has already stopped explaining the problem.
01 / WORK
Operator work, architecture, escalation and teaching. I still like getting to the console when that is the shortest path to the truth.
BGP, IPv4/IPv6, IS-IS, OSPF, MPLS, EVPN/VXLAN, peering, transit, address policy, RPKI/ROV and the operational bits that make a service-provider network stay useful.
Linux and BSD, virtualisation, storage, identity, monitoring, datacenter platforms, migrations and the interfaces where “it must be the network” stops being an adequate diagnosis.
Infrastructure and organisational work around multinational cyber-defence exercises, plus security engineering from the perspective of someone who has spent a long time operating the systems being defended.
Private model serving, GPU-backed local inference, platform operations and adversarial testing. I am interested in AI when the hardware, privacy, failure modes and operating costs are real constraints.
Routing, switching, virtualisation, security and infrastructure for apprentices, students and working engineers. Talks usually come from something we actually built, broke or investigated.
Architecture, incident escalation and operational improvement for connectivity providers, datacenter operators, hosting companies and large international organisations. Some client work is intentionally anonymous here.
LOCKED SHIELDS 2025 · TALLINN · organisational / industry-partner side of the exercise.
02 / CYBER DEFENCE
For Locked Shields and Crossed Swords 2025 I worked with the organisational and industry-partner teams, supporting exercise infrastructure and operations.
My work sat around infrastructure, local AI systems and exercise operations. That is also where I tend to approach security from: understand how the system really runs, then find the places where the assumptions stop holding.
03 / FIELD LOG
A chronological view of the operator, hacker and security communities I keep ending up in.
Routing-security practice from the operator side: what is deployable now, what is changing, and where the gaps still are.
Programme ↗An operator reading of an ambitious protocol proposal, with rather more questions about deployment and operations than about the slideware.
Read at RIPE Labs ↗Back at RIPE, following the measurement and routing sessions and joining discussions around RPKI data and ASPA. Some of those questions apparently travelled further than the room.
EVENTS FOSDEM · Brussels · Disobey · Helsinki · Netnod Meeting · Stockholm · Easterhegg · Koblenz · RIPE 92 · Edinburgh · nog.fi · Tampere
Worked with the organisational and industry-partner teams on exercise infrastructure and operations, including local AI/model-serving infrastructure and adversarial testing.
Helped an Internet-measurement project with a few production routing changes and infrastructure support. The resulting ACM IMC 2025 paper includes an acknowledgement.
Paper ↗A practical local GenAI stack: model serving, self-hosting, hardware constraints and an adversarial challenge environment.
Operated the self-hosted AI platform and model-serving infrastructure behind the challenge environment, and spent a fair amount of time trying to break it through adversarial testing.
Easterhegg 2025 ↗Co-authored two pieces on adversarial testing of generative AI and on keeping some deliberate distance from it.
Hands-on adversarial testing around the local challenge platform.
EVENTS Disobey · Helsinki · Easterhegg · Hamburg · WHY2025 · Netherlands · DENOG17 · Essen · BalCCon · Novi Sad · 39C3 · Hamburg
Operator-community discussions, hallway conversations and the usual working-group sessions.
Meeting ↗A practical talk about building a home lab, using it to experiment with real systems, and why more people should learn by running and breaking their own infrastructure.
Event recap ↗EVENTS Disobey · Helsinki · Disarray · Baltic Sea · DENOG16 · Berlin · BalCCon · Novi Sad · 38C3 · Hamburg
Using exchange-point software in a service-provider network, with the compromises and operational lessons that come with doing that for real.
Programme ↗A real route leak, how we got there, what it did, and what changed afterwards.
A production routing incident, an AS-SET that did not behave as expected, and the post-mortem.
EVENTS RIPE 86 · Rotterdam · RIPE 87 · Rome · Disobey · Helsinki · Easterhegg · Hamburg · DENOG15 · Berlin · Chaos Communication Camp · Mildenberg · 37C3 · Hamburg
At MCH2022 I ran the event IXP on pyro.institute using IXP Manager, with AS58299, AS41666 and FREETRANSIT / AS41051 among the connected networks.
MCH2022 IXP wiki ↗Operational networking stories from the provider side.
nog.fi meeting ↗A hands-on evening around the information an operator can pull together from an IP address or network: RIR data, BGP, traceroutes, reverse DNS, WHOIS and the surrounding infrastructure.
Workshop notes ↗Hosted a small practical workshop with TurkuSec, building WireGuard setups on MikroTik hardware instead of stopping at a slide deck.
Workshop announcement ↗EVENTS MCH2022 · Netherlands · TurkuSec · Turku · BalCCon · Novi Sad
Stood for the RIPE NCC Executive Board with a focus on operator experience, education and bringing more people into the networking community.
EVENTS FOSDEM · Brussels · Disobey · Helsinki
Helped with a hands-on Tranalyzer traffic-mining workshop at the TurkuSec lab. A practical evening spent looking at real network traffic and what can be extracted from it.
Tranalyzer workshop archive ↗EVENTS Disobey · Helsinki · TurkuSec · Turku · Easterhegg · Vienna · GPN19 · Karlsruhe · BalCCon · Novi Sad · DENOG11 · Hamburg · Chaos Communication Camp · Mildenberg · 36C3 · Leipzig
EVENTS FOSDEM · Brussels · Disobey · Helsinki · Easterhegg · Würzburg · BalCCon · Novi Sad · 35C3 · Leipzig
/31 point-to-point networks, sixteen years after the RFC already said we could stop wasting two addresses per link.
Slides ↗EVENTS BalCCon · Novi Sad · 33C3 · Hamburg
EVENTS RIPE SEE 4 · Belgrade · Chaos Communication Camp · Mildenberg · BalCCon · Novi Sad · 32C3 · Hamburg
EVENTS BalCCon · Novi Sad · 31C3 · Hamburg
Worked as an Archangel during the event, helping keep the day-to-day operation of the Easter weekend moving.
Event ↗EVENTS Easterhegg · Basel · 29C3 · Hamburg
EVENTS RIPE 63 · Vienna · Chaos Communication Camp · Finowfurt · 28C3 · Berlin
Already active around Swiss network operators while still early in my own systems-engineering career.
04 / BUILT / OPERATED
A non-commercial routing project giving students, enthusiasts and emerging networks a way to learn BGP and operate real Internet resources rather than only drawing them on a whiteboard.
freetransit.ch ↗International backbone, peering, transit, downstreams, address policy, datacenter connectivity, monitoring and the operational responsibility that comes with running a network other people depend on.
Founding and board involvement in a Swiss Internet exchange, with work around interconnection, community and getting the less-visible operational details done.
RIPE bio ↗Operated the local AI platform and model-serving infrastructure used for challenge environments, with a lot of time spent on integration, operations and adversarial testing.
SwiNOG40 ↗Occasional infrastructure and production-routing support for Internet-measurement work, including a contribution acknowledged in an ACM IMC 2025 paper.
Paper ↗Hands-on and advisory work for network operators, datacenter providers and large multinational organisations across Europe and beyond, from southern France through Central Europe, northern Norway and Sicily, plus intercontinental assignments. Client names are omitted where they do not need to become advertising.
05 / ABOUT
Systems engineering, network operations, teaching, startups and a long-running tendency to get involved when infrastructure gets complicated.
I started in systems engineering as an apprentice, then ended up building and operating service-provider infrastructure. I have run my own infrastructure businesses since 2009, operate AS58299, and spend a lot of my time on difficult routing, systems and delivery problems for organisations that already have competent technical teams.
I have also been around the startup scene since the late 2000s, helped early companies get infrastructure off the ground, and later taught in Swiss professional and higher technical IT education. Earlier and consulting work includes external systems engineering for a major international public-health organisation, hands-on Internet-exchange operations in South Asia, and infrastructure work for large multinational enterprises across Europe and beyond.
06 / CONTACT
I am happy to join as a consultant for a one-off problem, a second opinion, an escalation, or as a regular technical engagement alongside an existing team. I also speak at operator, security and hacker events, and I am happy to submit talks, workshops or CTF material. I am quite capable of noticing a CFP deadline too late, so if there is a topic you would like me to cover, send me the link or give me a nudge.
Email me ↗Also acceptable: asking how to connect a Boston Dynamics Spot to the Internet properly.