Networks and accountability

The notice does not go to your IT company. It comes to your counter.

Somewhere in India this week, a message went out that should not have. A threat, a demand, something aimed at somebody senior enough that it will be taken seriously and traced.

It will be traced to an address. The address will belong to a building, and the building will belong to somebody. Not to the person who sent it. To whoever owns the connection it left from.

Three buildings below. In each of them the network worked exactly as designed, nobody was negligent, and the question that arrives afterwards has no answer.

A Tuesday afternoon, and then a Tuesday morning

The café

Somebody buys a coffee and joins your Wi-Fi. There is no password, or there is one printed on the wall. Either way, joining is meant to be easy: that is the entire point of offering it.

They are there for thirty-five minutes. From your network, they send something. A threat to a public figure. A demand to a company. Something serious enough that it will not be ignored.

They finish the coffee and leave.


Six days later, two officers walk into the store at half past ten in the morning.

They are polite. They have a date, a time, and your public IP address. They want to know who was using it.

Your duty manager is twenty-six years old. He has been in the job four months. He does not know what a public IP address is, and nobody has ever told him what to say. He calls the area manager, who calls the IT vendor, who says he will look into it.

Meanwhile the officers are still standing at the counter, in front of customers.

Everyone who joined your Wi-Fi that day shared one address. Which one of them was it?

A Thursday night

The hotel

Your Wi-Fi has a login. You are not one of the places that leaves it open. Reception issues an access code at check-in, and the guest types it in. It works.

The code goes to the guest. It also goes, over the next two days, to the guest’s colleague, to a visitor who came up to the room, and to the person waiting in the lobby who asked politely at the desk. Codes are shared because they are meant to be convenient, and nobody at reception is going to refuse.

Every one of those people is now on your network. Every session they open is logged against the same room.


Something is done from that room’s connection. Later, somebody asks who did it.

You have a record. The record says room 704. Room 704 says a name, an address and a passport number, because that is the guest you checked in, and that is the person your system believes was online.

He was in a meeting on the other side of the city at the time. He will say so, and he will be telling the truth.

Your log names your guest. You never captured who was actually using it. Which of those two facts will be believed?

An ordinary Wednesday

The plant

There is a network socket behind the printer in the corridor outside the production office. It has been there since the fit-out. Nobody thinks about it, because it is a printer.

A man comes to service the air conditioning. He is expected, he is signed in, and he is exactly who he says he is. He needs somewhere to sit for twenty minutes while he waits for a part, so he sits at the empty desk in the corridor and plugs his laptop into the socket behind the printer.

The network does not ask who he is. It never had to: a printer has never had to prove anything.


From that socket he can see the recording system, the access control server and the plant network.

He may do nothing at all. He probably does nothing at all. But nothing alarms, nothing is logged as unusual, and nobody in the building knows the port was ever used by anything other than a printer.

The same is true of the socket in the meeting room, the one behind the reception desk, and the four in the training room that nobody has used since 2019.

Every one of those ports still works. When did you last find out what is plugged into them?

In none of these did anything break.

The network worked. The systems worked. Nobody was negligent, and every one of these buildings would pass an inspection on the day. They share one gap: the network can say what happened, and cannot say who.

That gap used to be tolerable. It is becoming less so. The DPDP framework names a Data Fiduciary, an organisation accountable for personal data including the record of who did what on a network. It does not name an IT department, and it does not name your vendor.

In your building, who is that? The owner, the operator, the tenant, or the contractor who installed the system?

If four people would give four different answers, that is the finding. Not a technical one.

If you cannot answer that quickly, you are not unusual. Almost no network can. They were built to connect people, and they do that well.

We work on the other question.

It is a conversation, not a product. Start it and we will tell you what we would look at first.