Table of Contents
A complete index of 66 posts — titles, dates, reading time, and short summaries.
2026
- 01
The IT Strategy One-Pager the CEO Actually Quotes.
Jul 27, 2026 7 min 1,672 wordsThe sixty-slide IT strategy vanishes into a shared drive. The version that survives is short, opinionated, tradeoff-explicit, and quotable by the CEO.
- 02
A Roadmap Full of Projects Is a Backlog
Jul 23, 2026 9 min 2,129 wordsA slide of thirty project names with quarters is a backlog, not a strategy. Anchor the roadmap to outcomes — and make every item name what it retires.
- 03
IT Operating Model: Org Chart to Value Chain
Jul 23, 2026 8 min 1,796 wordsIT org charts name technology towers; the customer pays for every handoff between them. Redraw the function around business capabilities and value streams.
- 04
Cyber and AI Oversight From the Board Seat
Jul 16, 2026 8 min 1,837 wordsReporting to a board and sitting on one are different jobs. What reporting taught me about cyber and AI oversight, and what I'd ask from the director's seat.
- 05
The Renewal Clock Starts the Day You Sign.
Jul 13, 2026 7 min 1,575 wordsVendor leverage peaks before you deploy. Negotiate the renewal at signing — cap the uplift, kill the evergreen clause, and bring your own usage data.
- 06
Thinking Like a CIO, Not a Security VP
Jul 11, 2026 8 min 1,883 wordsThe jump to CIO is a change of altitude, not a bigger security job. The agenda I'd run — and the three security reflexes I'd have to consciously unlearn.
- 07
Security Culture Is a Control. Audit It.
Jul 8, 2026 8 min 1,826 wordsSecurity culture is usually a poster — no objective, no defined behavior, no evidence, no failure mode. Give it those four and it audits like any firewall.
- 08
Fractional CIO: What 30–90 Days Actually Buy
Jul 7, 2026 8 min 1,778 wordsA fractional CIO is not a discounted full-timer. What the first thirty, sixty, and ninety days each actually buy — and the honest limits of the seat.
- 09
Rank Your AI Pilots or It's Not a Portfolio
Jun 26, 2026 8 min 1,897 wordsForty unranked AI pilots is a science fair with a cloud bill. Run the portfolio like a VC book: expected value, feasibility, risk, and kill criteria up front.
- 10
Ransomware Recovery: A Tested-Backups Problem
Jun 15, 2026 4 min 966 wordsEveryone has backups. Almost nobody has a restore they've actually run under fire. That gap is where ransomware turns a bad week into an existential one.
- 11
70 Security Tools, 9 Controls: Consolidate
Jun 14, 2026 8 min 1,811 wordsThe license fee is the cheapest part of a security tool — integration, console staffing, and alert fatigue are the real bill. Rationalize on control coverage.
- 12
Evidence as Code: Make the Next Audit Boring
Jun 12, 2026 4 min 948 wordsAudits feel like fire drills because evidence is hunted after the fact. Machine-readable SOC reports and modern PCI rules let proof live in the pipeline.
- 13
Start Post-Quantum Migration in 2026
Jun 11, 2026 4 min 868 wordsPost-quantum cryptography stopped being research and became a config task. The teams that win aren't waiting for a quantum computer — they wait for nothing.
- 14
Your Security Program Is a Sales Asset
Jun 10, 2026 2 min 351 wordsWhy provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.
- 15
Guardrails at Scale for a Three-Person Team
Jun 9, 2026 4 min 919 wordsA lean team can govern a sprawling cloud estate without becoming a ticket queue — but only if you put the rules in the pipeline, not in your inbox.
- 16
Internal IT as a Product, or Shadow IT Wins
Jun 8, 2026 8 min 1,720 wordsInternal platforms fail when run like monopolies. Give them product managers, roadmaps, honest adoption metrics — and let users defect to better tools.
- 17
Pre-Wire Breach Disclosure Before the Breach
Jun 7, 2026 9 min 1,919 wordsMateriality, the SEC's four-day clock, the OFAC ransom gate: decisions to pre-wire with a standing disclosure committee, not improvise at hour three.
- 18
Context Lock-In Is the Next Vendor Risk
Jun 4, 2026 4 min 966 wordsEveryone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated the prompts, context, and memory that became the switching cost.
- 19
WAF in the Agent Era: Good Bots vs. Abuse
Jun 2, 2026 4 min 998 wordsAgents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the one that matters.
- 20
Tech Due Diligence: What Data Rooms Hide
May 30, 2026 9 min 1,952 wordsA data room is built to close the deal. Technical debt, run cost, architecture risk, and key-person risk predict integration cost — and it hides all four.
- 21
Stop Charging the SSO Tax
May 27, 2026 8 min 1,833 wordsSSO and audit logs are the controls a buyer needs to trust you — conversion features, not enterprise upsells. Paywall them and you tax your own funnel.
- 22
Consolidate SecOps on OCSF, Not Aggregators
May 21, 2026 5 min 1,013 wordsDashboard sprawl isn't a tooling gap you fix with more tooling — it's a schema problem. Standardize on OCSF and the single pane of glass becomes real.
- 23
Cluster Autoscaler to Karpenter: What Breaks
May 14, 2026 4 min 959 wordsKarpenter is the right call for most EKS shops — but the migration breaks things unrelated to autoscaling. What to know before flipping the switch.
- 24
Autonomous Pentesting in a Regulated Shop
May 7, 2026 5 min 1,065 wordsA tool that scans and exploits your estate on its own schedule is a gift and a loaded gun. The scoping, approvals, and evidence I'd want before it runs.
- 25
AWS Cost Levers That Moved the Needle
May 6, 2026 3 min 678 wordsCutting ~35% off a multi-region AWS footprint with no capability loss — the levers in the order they paid back, best first.
- 26
The Eight-Domain Azure Security Review
May 4, 2026 4 min 806 wordsA tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in audit order, and the evidence each has to produce.
- 27
Vendor License Audits: Bring Your Own Numbers
May 3, 2026 9 min 1,930 wordsA vendor "license review" is a revenue motion in compliance clothes. Reconcile entitlements against deployment continuously and walk in with your own number.
- 28
Zero-Downtime Database Changes Are a Process
Apr 28, 2026 4 min 939 wordsBlue/green and serverless Aurora don't make migrations safe — the runbook does. The boring discipline that keeps schema changes from becoming incidents.
- 29
Cyber-Insurance Renewal Is a Second Audit
Apr 24, 2026 9 min 1,942 wordsThe underwriter's questionnaire is a prioritized controls roadmap; your renewal terms are a risk metric. Mine both and close the coverage-gap traps early.
- 30
Aurora DSQL for the Ledger: Active-Active
Apr 23, 2026 4 min 972 wordsMulti-region active-active sounds like the answer to ledger nightmares. Interrogate the consistency, recovery math, and migration before betting the books.
- 31
Fine-Grained Authorization for Fintech APIs
Apr 16, 2026 4 min 925 wordsAuthorization scattered across your codebase isn't a feature — it's a liability you can't prove. The pattern multi-tenant regulated platforms actually need.
- 32
MCP Is a New Attack Surface: An IAM Playbook
Apr 14, 2026 5 min 1,051 wordsEvery MCP server is a new identity reaching into your cloud. Whether that's leverage or liability comes down to least-privilege IAM on every tool call.
- 33
Data Strategy Dies in the Funding Meeting
Apr 13, 2026 8 min 1,747 wordsData-strategy decks die in the funding meeting, not the architecture review — pitching a capability the CFO can't fund instead of a decision it changes.
- 34
Fraud and Security Are One Threat Model
Apr 8, 2026 9 min 1,940 wordsAccount takeover, synthetic identity, and scams sit between fraud and security — one adversary split across two budgets. Fuse the threat model and the signal.
- 35
The Integration Layer Nobody Owns
Apr 4, 2026 8 min 1,866 wordsThe org chart is a story; the point-to-point integration mesh nobody owns is your real operating model. Own it with an API platform and contracts.
- 36
Operational Resilience Is Not a DR Plan
Apr 3, 2026 8 min 1,758 wordsA DR plan brings systems back; resilience keeps the service inside a limit the board owns — impact tolerances, service mapping, testing to failure.
- 37
Capex Died. Your Balance Sheet Didn't Notice.
Apr 2, 2026 9 min 1,913 wordsSaaS and cloud moved tech spend to opex, quietly compressing EBITDA. That reopens the ASC 350-40 capitalization question — answered by engineering telemetry.
- 38
Insider Risk Without Becoming Surveillance
Mar 31, 2026 9 min 1,939 wordsInsider risk is a governance program across HR, legal, privacy, and security — not a DLP purchase. Monitor the assets that carry the loss, not the people.
- 39
The Audit Passed in March. Is It Still True?
Mar 30, 2026 1 min 243 wordsPoint-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits — and what it takes to run it year-round.
- 40
Core Modernization: Strangle, Don't Rewrite
Mar 28, 2026 9 min 1,954 wordsA full rewrite is the most expensive way to modernize a core system, and the likeliest to fail. Sequence a strangler-fig migration — no blank check required.
- 41
How to Survive an FFIEC Exam
Mar 26, 2026 4 min 974 wordsAn exam isn't a pop quiz you cram for. It's referenceable proof of control — run it right and the examiner's findings become your best sales collateral.
- 42
The CISO Reporting Line Is a Risk Decision
Mar 21, 2026 8 min 1,700 wordsWhere the security leader sits decides whose incentives they inherit and how far bad news travels. The reporting line is a control the board should own.
- 43
PCI DSS 4.0 Without the Last-Minute Scramble
Mar 10, 2026 4 min 1,005 wordsPCI DSS 4.0 didn't add a longer checklist — it changed who does the thinking. Bake continuous-control expectations into engineering, not audit-week cramming.
- 44
Technical Debt Is a Loan: Report the Interest
Mar 4, 2026 8 min 1,896 wordsEngineers size technical-debt principal, never the interest. Measure the velocity tax where DORA metrics leave fingerprints; give every loan a verdict.
- 45
Run a Human-Risk Program, Not Awareness
Feb 25, 2026 8 min 1,766 wordsTraining completion is the cleanest number in the board deck and the least tied to risk. Score human risk per team and measure behavior, not attendance.
- 46
Report Risk to Those Who Don't Speak Security
Feb 20, 2026 1 min 262 wordsTranslating security for boards and investors — the three questions leadership actually asks, and how to answer them.
- 47
Data Privacy Is an Operations Problem
Feb 11, 2026 4 min 999 wordsEvery privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP. Treat privacy as an operating program, not an annual PDF.
- 48
App Sprawl: 400 Apps and No Sunset Policy
Feb 8, 2026 7 min 1,666 wordsYou can't cut your way out of an estate that only grows. The fix: a TIME verdict on every app and a sunset policy making renewal a decision, not a reflex.
- 49
An SBOM Nobody Reads Is Compliance Cosplay
Feb 6, 2026 4 min 1,002 wordsGenerating a software bill of materials is the easy part. Wiring it into the moment a change ships is where supply-chain security stops being theater.
- 50
Warm Standby Is a Promise You Have to Test
Feb 3, 2026 4 min 981 wordsA DR plan you have never exercised is a hypothesis with a logo on it. Warm standby only counts as a promise if you test the failover before you need it.
- 51
Put a Dollar Figure on the Risk Register
Feb 1, 2026 8 min 1,894 wordsA heat map's red cell is a category, not a quantity. FAIR-style quantification puts a dollar range on each risk that the CFO can weigh against controls spend.
- 52
Threat Intel Your Sales Team Will Brag About
Jan 30, 2026 5 min 1,016 wordsMost threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.
- 53
Security and DevOps Under One Roof
Jan 28, 2026 1 min 274 wordsThe case for running security and DevOps as one mandate: org-chart distance doesn't create security, and owning the pipelines changes how you protect them.
- 54
Treat Data Like a Product With an Owner
Jan 27, 2026 9 min 1,980 wordsA data lake with no owner is deferred cost; every team that distrusts it rebuilds the same report. Domain ownership, contracts, and lineage fix that.
- 55
Tabletops That Find Real Gaps
Jan 26, 2026 4 min 872 wordsMost incident tabletops are theater confirming the runbook. The useful ones break your assumptions and expose who decides — before a real incident does.
- 56
SOC Metrics Are Vanity Until Decisions Change
Jan 22, 2026 4 min 953 wordsMTTD and MTTR look great on a slide and tell you almost nothing. The only metric that matters is whether it changed what someone did next.
- 57
Third-Party Risk When You ARE the Third Party
Jan 20, 2026 5 min 1,018 wordsServing 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.
- 58
Underwrite the Security Budget Like a Loss
Jan 18, 2026 8 min 1,791 wordsThe security budget is the line defended with emotion — and emotion gets discounted. Price the loss, count the revenue it unlocks, argue in the CFO's math.
- 59
Capital Allocation Governance, Built Too Late
Jan 15, 2026 3 min 709 wordsMid-market capital allocation is rarely a strategy — capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.
- 60
Zero Trust for Humans: Just-in-Time Access
Jan 13, 2026 4 min 926 wordsEveryone's obsessing over non-human identity. Meanwhile your humans sit on standing admin rights — and the fix only works if people will actually use it.
- 61
Stop Running IT as a Cost Center
Jan 10, 2026 9 min 1,939 wordsIT shows up as one budget line, so the only move is "make it smaller." A P&L and price list — showback, unit economics — turn the argument to value.
- 62
Incident Response: The First 24 Hours
Jan 8, 2026 5 min 1,141 wordsMost IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.
- 63
The New Security Leader's First 90 Days
Jan 6, 2026 5 min 1,109 wordsHired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.
2025
- 01
Board Reporting That Drives Decisions
Aug 26, 2025 3 min 619 wordsThe fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.
- 02
Post-Close Cyber Integration: A 100-Day Plan
Aug 5, 2025 4 min 872 wordsThe post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.
- 03
Cloud FinOps: Where 25–40% of Spend Hides
Jul 15, 2025 4 min 812 wordsThe press-release version of cloud savings cancels workloads and books compliance debt. The durable version is commitment management and SaaS rationalization.