Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Fintech · Banking · FinServ

Finance & fintech expertise

Security, DevOps, and AI governance leadership for fintech platforms, banks, and regulated financial services.

1,500+
Financial institutions served at SavvyMoney
SOC 2 Type II
Independent attestation maintained
CSA STAR Level II
Continuous-audit assurance
NIST CSF
Program scored above industry average

Pillars

Fintech & banking platforms

Security and DevOps for platforms serving 1,500+ financial institutions — built for regulators, not just users.

Regulatory frameworks

PCI DSS, SOX, GLBA, NYDFS 500, FFIEC, CCPA, GDPR — and the operating cadence that keeps them current, not crammed.

Working with regulators

Hands-on experience walking examiners and auditors through controls, exceptions, and remediation plans.

Revenue-aligned security

Reframing security as a deal accelerator — faster questionnaires, cleaner attestations, shorter procurement cycles.

AI governance for financial services

Model risk, bias, explainability, and the audit artifacts your regulator actually asks for.

Third-party risk at scale

Vendor tiering, continuous monitoring, and the controls that survive a 500-vendor portfolio.

Frameworks & regulations

Frameworks
  • PCI DSS
  • SOX ITGC
  • SOC 2 Type II
  • CSA STAR Level II
  • NIST CSF
  • ISO 27001
Financial regs
  • GLBA
  • NYDFS Part 500
  • FFIEC CAT
  • CFPB guidance
  • Reg E / Reg Z context
Privacy
  • CCPA / CPRA
  • GDPR
  • GLBA Safeguards Rule
AI / model risk
  • NIST AI RMF
  • SR 11-7 patterns
  • EU AI Act readiness

Related writing

All fintech posts
Jul 8, 2026 · 8 min

Security Culture Is a Control. Audit It.

Security culture is usually a poster — no objective, no defined behavior, no evidence, no failure mode. Give it those four and it audits like any firewall.

GRCCompliance
May 27, 2026 · 8 min

Stop Charging the SSO Tax

SSO and audit logs are the controls a buyer needs to trust you — conversion features, not enterprise upsells. Paywall them and you tax your own funnel.

Fintech
Apr 24, 2026 · 9 min

Cyber-Insurance Renewal Is a Second Audit

The underwriter's questionnaire is a prioritized controls roadmap; your renewal terms are a risk metric. Mine both and close the coverage-gap traps early.

Fintech
Apr 8, 2026 · 9 min

Fraud and Security Are One Threat Model

Account takeover, synthetic identity, and scams sit between fraud and security — one adversary split across two budgets. Fuse the threat model and the signal.

Fintech
Apr 3, 2026 · 8 min

Operational Resilience Is Not a DR Plan

A DR plan brings systems back; resilience keeps the service inside a limit the board owns — impact tolerances, service mapping, testing to failure.

Fintech
Mar 31, 2026 · 9 min

Insider Risk Without Becoming Surveillance

Insider risk is a governance program across HR, legal, privacy, and security — not a DLP purchase. Monitor the assets that carry the loss, not the people.

Fintech
Feb 25, 2026 · 8 min

Run a Human-Risk Program, Not Awareness

Training completion is the cleanest number in the board deck and the least tied to risk. Score human risk per team and measure behavior, not attendance.

Fintech
Feb 1, 2026 · 8 min

Put a Dollar Figure on the Risk Register

A heat map's red cell is a category, not a quantity. FAIR-style quantification puts a dollar range on each risk that the CFO can weigh against controls spend.

Finance
Jul 22, 2026 · 8 min

Fair Lending: The Real AI Governance Problem

Mapping models to AI frameworks isn't governance for credit. The binding constraint is fair-lending law — ECOA/Reg B, FCRA adverse action, SR 11-7 model risk.

Fintech
Jul 20, 2026 · 9 min

A Convincing Voice Is Not Authenticated

A cloned voice with matching caller-ID is recognition, not authentication. Move trust onto channels you control: callback on record, dual authorization.

Fintech
Jul 16, 2026 · 8 min

Cyber and AI Oversight From the Board Seat

Reporting to a board and sitting on one are different jobs. What reporting taught me about cyber and AI oversight, and what I'd ask from the director's seat.

Fintech
Jul 21, 2026 · 9 min

'We Don't Train on Your Data' Is Not Enough

An agent told to open no files obeyed — while the product uploaded the whole repo, canary included. "We don't train on your data" answers the wrong question.

Fintech
Jul 18, 2026 · 8 min

Your Prompt Is the Approval. That's the Gap.

An MCP connector executes writes with no approval screen — your prompt becomes the one boundary nobody governed. That missing gate is a control-plane gap.

Fintech
Jul 15, 2026 · 10 min

Your AI Policy Is a PDF. Agents Can't Read It

A model given thousands of extra words wrote better prose — and failed the delivery contract two runs in three. Rules agents can ignore fail audits.

GRC
Jul 12, 2026 · 9 min

Prove You Need the Agent Before the Swarm

Token spend explained ~80% of variance in multi-agent runs; most "AI failures" are provisioning mistakes. Treat a swarm as segregation of duties.

GRC
Jul 9, 2026 · 9 min

Shadow AI: Your "Personal Tool" Is Production

A coding agent stands up a data-touching tool in an afternoon. The moment it needs a login or gets shared, it's a production system nobody reviewed.

GRC
Jul 1, 2026 · 9 min

Context Custody Is a Concentration Risk

Intelligence went cheap, yet enterprise buyers expect to pay more for Claude. You're not paying for the brain — you're paying for where your context lives.

Fintech
Jun 28, 2026 · 12 min

Why We Built AgentOS

One model scored 78% in one agent harness and 42% in another. In regulated fintech the harness is where governance lives, so we built our own: AgentOS.

Fintech
Jun 10, 2026 · 2 min

Your Security Program Is a Sales Asset

Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.

FintechGRC
Mar 30, 2026 · 1 min

The Audit Passed in March. Is It Still True?

Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits — and what it takes to run it year-round.

ComplianceGRCFintech
Jun 25, 2026 · 5 min

The 2026 AI Regulatory Map on One Page

Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part fining 3% of global revenue turns on in August. The four 2026 rules with teeth.

Compliance
May 4, 2026 · 4 min

The Eight-Domain Azure Security Review

A tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in audit order, and the evidence each has to produce.

Compliance
Jan 6, 2026 · 5 min

The New Security Leader's First 90 Days

Hired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.

Fintech
Jan 8, 2026 · 5 min

Incident Response: The First 24 Hours

Most IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.

Fintech
Jan 13, 2026 · 4 min

Zero Trust for Humans: Just-in-Time Access

Everyone's obsessing over non-human identity. Meanwhile your humans sit on standing admin rights — and the fix only works if people will actually use it.

Fintech
Jan 20, 2026 · 5 min

Third-Party Risk When You ARE the Third Party

Serving 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.

Fintech
Jan 30, 2026 · 5 min

Threat Intel Your Sales Team Will Brag About

Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.

Fintech
Feb 3, 2026 · 4 min

Warm Standby Is a Promise You Have to Test

A DR plan you have never exercised is a hypothesis with a logo on it. Warm standby only counts as a promise if you test the failover before you need it.

Fintech
Feb 11, 2026 · 4 min

Data Privacy Is an Operations Problem

Every privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP. Treat privacy as an operating program, not an annual PDF.

ComplianceFintech
Feb 13, 2026 · 6 min

Agent Onboarding Was Easy. Offboarding Isn't.

Every team shipped an agent in a weekend. Almost none can say how it gets fired, what credentials it still holds, or who would notice if it went rogue.

Fintech
Feb 17, 2026 · 5 min

Anchoring Bias Is Already in Your KYC Agent

The failure modes that made medical LLMs unsafe sit inside your fraud, dispute, and onboarding agents. They don't announce themselves — you have to hunt.

Fintech
Feb 24, 2026 · 5 min

Agent Memory Is a Data-Residency Problem

Give every agent a durable, MCP-connected brain and you've stood up a new data lake of PII and PCI scope nobody classified, encrypted, or can purge.

Fintech
Feb 26, 2026 · 5 min

Your Browser Agent Has Your Cookies

Browser AI agents don't request access to your systems — they inherit it from the authenticated sessions in your tabs. A threat model nobody provisioned for.

Fintech
Mar 3, 2026 · 5 min

Agent Safety: Engineer the Blast Radius

Most agent "safety" is a politely worded request to a model that need not honor it. The only controls that count still hold after the model goes wrong.

Fintech
Mar 5, 2026 · 5 min

An AI Agent Dropped Prod: The Change Playbook

Coding agents are committing real change to real systems. The question isn't whether to let them — it's how to give them speed without a SOC 2-fatal mistake.

ComplianceFintech
Mar 10, 2026 · 4 min

PCI DSS 4.0 Without the Last-Minute Scramble

PCI DSS 4.0 didn't add a longer checklist — it changed who does the thinking. Bake continuous-control expectations into engineering, not audit-week cramming.

ComplianceFintech
Mar 17, 2026 · 6 min

Shadow-Agent Discovery for Regulated FIs

Unsanctioned AI agents already run in your environment with your credentials. Find, classify, and gate them before they touch member data or an exam does.

Fintech
Mar 19, 2026 · 5 min

Source-Map Leaks: Your Pipeline's Confession

One packaging mistake can publish hundreds of thousands of lines of internals. The leak is a confession: release controls never caught up to release velocity.

Fintech
Mar 24, 2026 · 5 min

AI Found 271 Bugs in Firefox. Now Your Repos?

AI-assisted fuzzing found hundreds of bugs in hardened open-source code. The question is whether you run it before someone else runs it against you.

Fintech
Mar 26, 2026 · 4 min

How to Survive an FFIEC Exam

An exam isn't a pop quiz you cram for. It's referenceable proof of control — run it right and the examiner's findings become your best sales collateral.

Compliance
Apr 7, 2026 · 5 min

Dark Code Is a Control Failure, Not Tech Debt

AI is filling repos with code nobody can explain. We call it tech debt; it's a control failure — and it should fail CI like a missing approver does.

Fintech
Apr 9, 2026 · 5 min

Make Your Enterprise Agent-Readable First

Everyone is racing to buy agents; almost no one builds the substrate that lets them act safely. The productivity is real — so is the blast radius.

Fintech
Apr 16, 2026 · 4 min

Fine-Grained Authorization for Fintech APIs

Authorization scattered across your codebase isn't a feature — it's a liability you can't prove. The pattern multi-tenant regulated platforms actually need.

Fintech
Apr 23, 2026 · 4 min

Aurora DSQL for the Ledger: Active-Active

Multi-region active-active sounds like the answer to ledger nightmares. Interrogate the consistency, recovery math, and migration before betting the books.

Fintech
May 7, 2026 · 5 min

Autonomous Pentesting in a Regulated Shop

A tool that scans and exploits your estate on its own schedule is a gift and a loaded gun. The scoping, approvals, and evidence I'd want before it runs.

Fintech
May 12, 2026 · 5 min

Three Token Counts, Zero You Can Attest To

Codex says one number, Claude another, your gateway a third. That isn't a metering problem — it's an attestation problem regulated industries can't afford.

Fintech
May 19, 2026 · 6 min

Shadow AI Is the New Shadow IT

Every abandoned notebook and weekend prototype is a credential-bearing asset nobody owns. The fix isn't a ban — it's discovery, demotion, and real sunsets.

Fintech
May 21, 2026 · 5 min

Consolidate SecOps on OCSF, Not Aggregators

Dashboard sprawl isn't a tooling gap you fix with more tooling — it's a schema problem. Standardize on OCSF and the single pane of glass becomes real.

FinTech
May 26, 2026 · 5 min

Your Agent Dashboard Is Green and Lying

Uptime tiles tell you the service answered — nothing about whether the answer was right. That gap is where a model-risk review will eat you alive.

Fintech
Jun 2, 2026 · 4 min

WAF in the Agent Era: Good Bots vs. Abuse

Agents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the one that matters.

Fintech
Jun 9, 2026 · 4 min

Guardrails at Scale for a Three-Person Team

A lean team can govern a sprawling cloud estate without becoming a ticket queue — but only if you put the rules in the pipeline, not in your inbox.

Fintech
Jun 11, 2026 · 4 min

Start Post-Quantum Migration in 2026

Post-quantum cryptography stopped being research and became a config task. The teams that win aren't waiting for a quantum computer — they wait for nothing.

ComplianceFintech
Jun 12, 2026 · 4 min

Evidence as Code: Make the Next Audit Boring

Audits feel like fire drills because evidence is hunted after the fact. Machine-readable SOC reports and modern PCI rules let proof live in the pipeline.

ComplianceFintechGRC

Building or scaling a fintech platform?

I advise fintechs, banks, and regulated SaaS on security programs, regulator readiness, and AI governance that ships.