Trey Darley
Trey is an independent adviser, recovering sysadmin, facilitator, and writer based in Brussels.
He has spent more than twenty-five years working on systems that matter beyond the organisations that operate them.
He began close to the machinery: embedded computers, telecommunications equipment, networks, test laboratories, and infrastructure expected to keep working in difficult conditions. Over time, the work moved outward—from individual systems to the organisations responsible for them, and then to the standards, institutions, and communities that allow many organisations to act together.
The seams are where the information is. They are not hidden. They are simply not pointed at, because pointing at them was nobody’s job.
The recurring work has been to understand the technical reality, notice where knowledge and responsibility have become separated, and help the relevant people reach a defensible way forward.
Proper Tools gives that work an independent home.
Close to the machinery
Trey began his career working on embedded Linux for telecommunications-grade network equipment. The work involved low-level software, reproducible firmware builds, interoperability testing, and the mixed collection of computers and operating systems needed to prove that equipment would behave outside the laboratory.
He later directed and supported technical work for NATO systems, including architecture, qualification testing, deployment, documentation, and long-term sustainment across multinational environments.
Those years taught a durable lesson: reliability does not live only in the clever part of a design. It also lives in testing, documentation, maintenance, handover, and the supposedly ordinary details that let a system survive the departure of the people who first understood it.
Before cybersecurity became the category
Trey also worked in media and film: as an IT director for an advertising and publicity company, as CTO of a Prague-based media intelligence firm, and as a technical consultant on The Chronicles of Narnia: Prince Caspian.
Complex productions bring together specialists with different vocabularies, tools, incentives, and deadlines. The work succeeds only when information travels and people can coordinate without first becoming experts in one another’s disciplines.
Making systems share what people know
Cybersecurity organisations often see different parts of the same threat. One team may recognise a malicious file, another a network address, another a campaign, and another the person or organisation behind it. For years, their tools described and stored that knowledge in incompatible ways.
At Splunk, Trey prototyped early connections between a widely used security platform and emerging formats for machine-readable threat information.
At Soltra, a joint venture of DTCC and FS-ISAC, he helped build systems through which financial institutions, national cyber teams, and other trusted communities could exchange that information.
He later co-chaired the international OASIS committee responsible for STIX and TAXII: a shared language and exchange mechanism designed so that organisations and security tools can describe threats consistently and pass what they know between them.
At Belgium’s national cybersecurity centre, Trey helped establish the country’s threat-intelligence capability and architected the Belgian Anti-Phishing Shield: national infrastructure that uses the domain-name system to steer people away from known malicious sites, even after a convincing message has persuaded them to click.
It was an early national example of protective DNS—an approach later reflected at European scale in the EU’s DNS4EU initiative.
Helping institutions act together
Technical understanding is rarely enough when responsibility is spread among suppliers, operators, regulators, standards bodies, governments, and the people who must ultimately approve a decision.
Trey served an elected term on the board of FIRST, the global community of computer-security and incident-response teams.
While there, he helped establish a group connecting the practical experience of those teams with the organisations that write international standards. That group became the FIRST Standards SIG, building working relationships across institutions including ITU-T, OASIS, IETF, ETSI, and ISO.
He also helped establish FIRST’s DNS Abuse SIG and founded and now co-chairs its Standards and Time Security SIGs.
The names matter because the institutions matter. But the underlying task is simpler to describe: find the people who each hold part of the problem, create a language they can use together, preserve useful disagreement, and help the room decide what follows.
Current public work
A significant part of Trey’s current public-interest work concerns the 2036–2038 timestamp rollovers.
Many computers represent time using counters or fixed-width numbers. Some of those representations have an end date. When it arrives, a system may wrap around to an earlier date, produce a value it cannot handle, or fail in some less predictable way.
The individual technical defects have been understood for years. The harder problem is that they are distributed across software, devices, supply chains, sectors, jurisdictions, and timescales. No single supplier, operator, regulator, or standards body can resolve the whole problem alone.
Trey is the primary drafter and a co-editor of ITU-T Technical Paper XSTP.epoch , co-chair of the FIRST Time Security SIG , and a contributor to related coordination through the Epochalypse Project and IEEE.
Timestamp resilience is the present example, not the whole practice. What makes it characteristic is the shape of the problem: a known technical risk, distributed ownership, long lead times, and a need for institutions to create a shared map before they can act.
The thread
Seen together, these are not quite separate careers. The pattern is visible in retrospect; the route could not have been planned.
The medium changed. The question did not: what must be made legible so that people can act?
A degree in Comparative Literature has proven more useful than it may first appear. It trained close reading: attention to framing, context, omission, and the way the same account changes as it moves between audiences.
Later training in ICA Technologies of Participation supplied practical methods for working in rooms where several reasonable accounts must become a shared decision.
The Field Notes try to practise the same discipline: read closely enough to find what is load-bearing, remove what is not, and leave the reader with more room to reflect and act.
Selected work and credentials
- Founder of Proper Tools, an independent advisory and research practice based in Brussels.
- Former Security Senior Manager at Accenture Belgium, leading work across cyber resilience, threat intelligence, incident readiness, and the early development of an AI security and testing laboratory.
- Former systems and security architect and threat-intelligence strategist at Belgium’s national cybersecurity centre.
- Elected member of the FIRST Board of Directors from 2022 to 2024.
- Former co-chair of the OASIS Cyber Threat Intelligence Technical Committee, responsible for stewardship of STIX and TAXII.
- CISSP and regular speaker at conferences including BruCON, BSides Lisbon, hack.lu, FIRST, RSA, and USENIX.
Selected publication
Beyond Planted Bugs in “Trusting Trust”: The Input-Processing
Frontier
IEEE Security & Privacy, January/February 2014.
Co-authored with Sergey Bratus, Michael Locasto, Meredith L. Patterson, Rebecca “bx” Shapiro, and Anna Shubina.
Patron saints
Grace Hopper , Evi Nemeth , Felix “FX” Lindner , Jocelyn Bell Burnell , Dan Kaminsky , Paul Erdős , and Gilda Radner , whose Roseanne Roseannadanna supplied the durable operating principle that it is always something: if it is not one thing, it is another.
Not a canon, exactly. More like a working committee: people who did the work, told the truth, built things that lasted, stayed curious, and made the people around them better.
Working together
Proper Tools maintains a small portfolio of continuing advisory relationships and undertakes a limited number of focused assignments.
Read about the practice and terms →
Start a conversation →