Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Index

Table of Contents

A complete index of 66 posts — titles, dates, reading time, and short summaries.

2026

  1. 01

    The IT Strategy One-Pager the CEO Actually Quotes.

    Jul 27, 2026 7 min 1,672 words

    The sixty-slide IT strategy vanishes into a shared drive. The version that survives is short, opinionated, tradeoff-explicit, and quotable by the CEO.

  2. 02

    A Roadmap Full of Projects Is a Backlog

    Jul 23, 2026 9 min 2,129 words

    A slide of thirty project names with quarters is a backlog, not a strategy. Anchor the roadmap to outcomes — and make every item name what it retires.

  3. 03

    IT Operating Model: Org Chart to Value Chain

    Jul 23, 2026 8 min 1,796 words

    IT org charts name technology towers; the customer pays for every handoff between them. Redraw the function around business capabilities and value streams.

  4. 04

    Cyber and AI Oversight From the Board Seat

    Jul 16, 2026 8 min 1,837 words

    Reporting to a board and sitting on one are different jobs. What reporting taught me about cyber and AI oversight, and what I'd ask from the director's seat.

  5. 05

    The Renewal Clock Starts the Day You Sign.

    Jul 13, 2026 7 min 1,575 words

    Vendor leverage peaks before you deploy. Negotiate the renewal at signing — cap the uplift, kill the evergreen clause, and bring your own usage data.

  6. 06

    Thinking Like a CIO, Not a Security VP

    Jul 11, 2026 8 min 1,883 words

    The jump to CIO is a change of altitude, not a bigger security job. The agenda I'd run — and the three security reflexes I'd have to consciously unlearn.

  7. 07

    Security Culture Is a Control. Audit It.

    Jul 8, 2026 8 min 1,826 words

    Security culture is usually a poster — no objective, no defined behavior, no evidence, no failure mode. Give it those four and it audits like any firewall.

  8. 08

    Fractional CIO: What 30–90 Days Actually Buy

    Jul 7, 2026 8 min 1,778 words

    A fractional CIO is not a discounted full-timer. What the first thirty, sixty, and ninety days each actually buy — and the honest limits of the seat.

  9. 09

    Rank Your AI Pilots or It's Not a Portfolio

    Jun 26, 2026 8 min 1,897 words

    Forty unranked AI pilots is a science fair with a cloud bill. Run the portfolio like a VC book: expected value, feasibility, risk, and kill criteria up front.

  10. 10

    Ransomware Recovery: A Tested-Backups Problem

    Jun 15, 2026 4 min 966 words

    Everyone has backups. Almost nobody has a restore they've actually run under fire. That gap is where ransomware turns a bad week into an existential one.

  11. 11

    70 Security Tools, 9 Controls: Consolidate

    Jun 14, 2026 8 min 1,811 words

    The license fee is the cheapest part of a security tool — integration, console staffing, and alert fatigue are the real bill. Rationalize on control coverage.

  12. 12

    Evidence as Code: Make the Next Audit Boring

    Jun 12, 2026 4 min 948 words

    Audits feel like fire drills because evidence is hunted after the fact. Machine-readable SOC reports and modern PCI rules let proof live in the pipeline.

  13. 13

    Start Post-Quantum Migration in 2026

    Jun 11, 2026 4 min 868 words

    Post-quantum cryptography stopped being research and became a config task. The teams that win aren't waiting for a quantum computer — they wait for nothing.

  14. 14

    Your Security Program Is a Sales Asset

    Jun 10, 2026 2 min 351 words

    Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.

  15. 15

    Guardrails at Scale for a Three-Person Team

    Jun 9, 2026 4 min 919 words

    A lean team can govern a sprawling cloud estate without becoming a ticket queue — but only if you put the rules in the pipeline, not in your inbox.

  16. 16

    Internal IT as a Product, or Shadow IT Wins

    Jun 8, 2026 8 min 1,720 words

    Internal platforms fail when run like monopolies. Give them product managers, roadmaps, honest adoption metrics — and let users defect to better tools.

  17. 17

    Pre-Wire Breach Disclosure Before the Breach

    Jun 7, 2026 9 min 1,919 words

    Materiality, the SEC's four-day clock, the OFAC ransom gate: decisions to pre-wire with a standing disclosure committee, not improvise at hour three.

  18. 18

    Context Lock-In Is the Next Vendor Risk

    Jun 4, 2026 4 min 966 words

    Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated the prompts, context, and memory that became the switching cost.

  19. 19

    WAF in the Agent Era: Good Bots vs. Abuse

    Jun 2, 2026 4 min 998 words

    Agents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the one that matters.

  20. 20

    Tech Due Diligence: What Data Rooms Hide

    May 30, 2026 9 min 1,952 words

    A data room is built to close the deal. Technical debt, run cost, architecture risk, and key-person risk predict integration cost — and it hides all four.

  21. 21

    Stop Charging the SSO Tax

    May 27, 2026 8 min 1,833 words

    SSO and audit logs are the controls a buyer needs to trust you — conversion features, not enterprise upsells. Paywall them and you tax your own funnel.

  22. 22

    Consolidate SecOps on OCSF, Not Aggregators

    May 21, 2026 5 min 1,013 words

    Dashboard sprawl isn't a tooling gap you fix with more tooling — it's a schema problem. Standardize on OCSF and the single pane of glass becomes real.

  23. 23

    Cluster Autoscaler to Karpenter: What Breaks

    May 14, 2026 4 min 959 words

    Karpenter is the right call for most EKS shops — but the migration breaks things unrelated to autoscaling. What to know before flipping the switch.

  24. 24

    Autonomous Pentesting in a Regulated Shop

    May 7, 2026 5 min 1,065 words

    A tool that scans and exploits your estate on its own schedule is a gift and a loaded gun. The scoping, approvals, and evidence I'd want before it runs.

  25. 25

    AWS Cost Levers That Moved the Needle

    May 6, 2026 3 min 678 words

    Cutting ~35% off a multi-region AWS footprint with no capability loss — the levers in the order they paid back, best first.

  26. 26

    The Eight-Domain Azure Security Review

    May 4, 2026 4 min 806 words

    A tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in audit order, and the evidence each has to produce.

  27. 27

    Vendor License Audits: Bring Your Own Numbers

    May 3, 2026 9 min 1,930 words

    A vendor "license review" is a revenue motion in compliance clothes. Reconcile entitlements against deployment continuously and walk in with your own number.

  28. 28

    Zero-Downtime Database Changes Are a Process

    Apr 28, 2026 4 min 939 words

    Blue/green and serverless Aurora don't make migrations safe — the runbook does. The boring discipline that keeps schema changes from becoming incidents.

  29. 29

    Cyber-Insurance Renewal Is a Second Audit

    Apr 24, 2026 9 min 1,942 words

    The underwriter's questionnaire is a prioritized controls roadmap; your renewal terms are a risk metric. Mine both and close the coverage-gap traps early.

  30. 30

    Aurora DSQL for the Ledger: Active-Active

    Apr 23, 2026 4 min 972 words

    Multi-region active-active sounds like the answer to ledger nightmares. Interrogate the consistency, recovery math, and migration before betting the books.

  31. 31

    Fine-Grained Authorization for Fintech APIs

    Apr 16, 2026 4 min 925 words

    Authorization scattered across your codebase isn't a feature — it's a liability you can't prove. The pattern multi-tenant regulated platforms actually need.

  32. 32

    MCP Is a New Attack Surface: An IAM Playbook

    Apr 14, 2026 5 min 1,051 words

    Every MCP server is a new identity reaching into your cloud. Whether that's leverage or liability comes down to least-privilege IAM on every tool call.

  33. 33

    Data Strategy Dies in the Funding Meeting

    Apr 13, 2026 8 min 1,747 words

    Data-strategy decks die in the funding meeting, not the architecture review — pitching a capability the CFO can't fund instead of a decision it changes.

  34. 34

    Fraud and Security Are One Threat Model

    Apr 8, 2026 9 min 1,940 words

    Account takeover, synthetic identity, and scams sit between fraud and security — one adversary split across two budgets. Fuse the threat model and the signal.

  35. 35

    The Integration Layer Nobody Owns

    Apr 4, 2026 8 min 1,866 words

    The org chart is a story; the point-to-point integration mesh nobody owns is your real operating model. Own it with an API platform and contracts.

  36. 36

    Operational Resilience Is Not a DR Plan

    Apr 3, 2026 8 min 1,758 words

    A DR plan brings systems back; resilience keeps the service inside a limit the board owns — impact tolerances, service mapping, testing to failure.

  37. 37

    Capex Died. Your Balance Sheet Didn't Notice.

    Apr 2, 2026 9 min 1,913 words

    SaaS and cloud moved tech spend to opex, quietly compressing EBITDA. That reopens the ASC 350-40 capitalization question — answered by engineering telemetry.

  38. 38

    Insider Risk Without Becoming Surveillance

    Mar 31, 2026 9 min 1,939 words

    Insider risk is a governance program across HR, legal, privacy, and security — not a DLP purchase. Monitor the assets that carry the loss, not the people.

  39. 39

    The Audit Passed in March. Is It Still True?

    Mar 30, 2026 1 min 243 words

    Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits — and what it takes to run it year-round.

  40. 40

    Core Modernization: Strangle, Don't Rewrite

    Mar 28, 2026 9 min 1,954 words

    A full rewrite is the most expensive way to modernize a core system, and the likeliest to fail. Sequence a strangler-fig migration — no blank check required.

  41. 41

    How to Survive an FFIEC Exam

    Mar 26, 2026 4 min 974 words

    An exam isn't a pop quiz you cram for. It's referenceable proof of control — run it right and the examiner's findings become your best sales collateral.

  42. 42

    The CISO Reporting Line Is a Risk Decision

    Mar 21, 2026 8 min 1,700 words

    Where the security leader sits decides whose incentives they inherit and how far bad news travels. The reporting line is a control the board should own.

  43. 43

    PCI DSS 4.0 Without the Last-Minute Scramble

    Mar 10, 2026 4 min 1,005 words

    PCI DSS 4.0 didn't add a longer checklist — it changed who does the thinking. Bake continuous-control expectations into engineering, not audit-week cramming.

  44. 44

    Technical Debt Is a Loan: Report the Interest

    Mar 4, 2026 8 min 1,896 words

    Engineers size technical-debt principal, never the interest. Measure the velocity tax where DORA metrics leave fingerprints; give every loan a verdict.

  45. 45

    Run a Human-Risk Program, Not Awareness

    Feb 25, 2026 8 min 1,766 words

    Training completion is the cleanest number in the board deck and the least tied to risk. Score human risk per team and measure behavior, not attendance.

  46. 46

    Report Risk to Those Who Don't Speak Security

    Feb 20, 2026 1 min 262 words

    Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.

  47. 47

    Data Privacy Is an Operations Problem

    Feb 11, 2026 4 min 999 words

    Every privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP. Treat privacy as an operating program, not an annual PDF.

  48. 48

    App Sprawl: 400 Apps and No Sunset Policy

    Feb 8, 2026 7 min 1,666 words

    You can't cut your way out of an estate that only grows. The fix: a TIME verdict on every app and a sunset policy making renewal a decision, not a reflex.

  49. 49

    An SBOM Nobody Reads Is Compliance Cosplay

    Feb 6, 2026 4 min 1,002 words

    Generating a software bill of materials is the easy part. Wiring it into the moment a change ships is where supply-chain security stops being theater.

  50. 50

    Warm Standby Is a Promise You Have to Test

    Feb 3, 2026 4 min 981 words

    A DR plan you have never exercised is a hypothesis with a logo on it. Warm standby only counts as a promise if you test the failover before you need it.

  51. 51

    Put a Dollar Figure on the Risk Register

    Feb 1, 2026 8 min 1,894 words

    A heat map's red cell is a category, not a quantity. FAIR-style quantification puts a dollar range on each risk that the CFO can weigh against controls spend.

  52. 52

    Threat Intel Your Sales Team Will Brag About

    Jan 30, 2026 5 min 1,016 words

    Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.

  53. 53

    Security and DevOps Under One Roof

    Jan 28, 2026 1 min 274 words

    The case for running security and DevOps as one mandate: org-chart distance doesn't create security, and owning the pipelines changes how you protect them.

  54. 54

    Treat Data Like a Product With an Owner

    Jan 27, 2026 9 min 1,980 words

    A data lake with no owner is deferred cost; every team that distrusts it rebuilds the same report. Domain ownership, contracts, and lineage fix that.

  55. 55

    Tabletops That Find Real Gaps

    Jan 26, 2026 4 min 872 words

    Most incident tabletops are theater confirming the runbook. The useful ones break your assumptions and expose who decides — before a real incident does.

  56. 56

    SOC Metrics Are Vanity Until Decisions Change

    Jan 22, 2026 4 min 953 words

    MTTD and MTTR look great on a slide and tell you almost nothing. The only metric that matters is whether it changed what someone did next.

  57. 57

    Third-Party Risk When You ARE the Third Party

    Jan 20, 2026 5 min 1,018 words

    Serving 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.

  58. 58

    Underwrite the Security Budget Like a Loss

    Jan 18, 2026 8 min 1,791 words

    The security budget is the line defended with emotion — and emotion gets discounted. Price the loss, count the revenue it unlocks, argue in the CFO's math.

  59. 59

    Capital Allocation Governance, Built Too Late

    Jan 15, 2026 3 min 709 words

    Mid-market capital allocation is rarely a strategy — capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.

  60. 60

    Zero Trust for Humans: Just-in-Time Access

    Jan 13, 2026 4 min 926 words

    Everyone's obsessing over non-human identity. Meanwhile your humans sit on standing admin rights — and the fix only works if people will actually use it.

  61. 61

    Stop Running IT as a Cost Center

    Jan 10, 2026 9 min 1,939 words

    IT shows up as one budget line, so the only move is "make it smaller." A P&L and price list — showback, unit economics — turn the argument to value.

  62. 62

    Incident Response: The First 24 Hours

    Jan 8, 2026 5 min 1,141 words

    Most IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.

  63. 63

    The New Security Leader's First 90 Days

    Jan 6, 2026 5 min 1,109 words

    Hired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.

2025

  1. 01

    Board Reporting That Drives Decisions

    Aug 26, 2025 3 min 619 words

    The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.

  2. 02

    Post-Close Cyber Integration: A 100-Day Plan

    Aug 5, 2025 4 min 872 words

    The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.

  3. 03

    Cloud FinOps: Where 25–40% of Spend Hides

    Jul 15, 2025 4 min 812 words

    The press-release version of cloud savings cancels workloads and books compliance debt. The durable version is commitment management and SaaS rationalization.