Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Field Notes

Writing

Searchable posts on AI governance, security, leadership, and platform engineering.

More posts

7/23/2026 8 min

A Roadmap Full of Projects Is a Backlog, Not a Strategy.

A slide of thirty project names with quarters beside them is a backlog wearing a Gantt chart's confidence — not a strategy. The roadmap that survives reprioritization is anchored to business outcomes and durable capabilities, and every item on it names what it retires.

Technology RoadmapIT StrategyPortfolio ManagementBusiness Alignment
7/23/2026 9 min

Your IT Operating Model Is an Org Chart. It Should Be a Value Chain.

The IT org chart names technology towers, and the customer pays for the handoff at every seam between them. Redraw the function around business capabilities and value streams — the same collapse I already ran, on purpose, at the scale of two towers.

IT Operating ModelOrg DesignValue StreamsBusiness Alignment
7/16/2026 9 min

Cyber and AI Oversight From the Board Seat

Reporting to a board and sitting on one are different jobs. What the reporting side taught me about cyber and AI oversight — and the questions I would ask from the director's seat.

Board GovernanceOversightRisk ManagementFintech
7/13/2026 7 min

The Renewal Clock Starts the Day You Sign.

Your leverage over a vendor is highest before you deploy and lowest at renewal. So negotiate next year's renewal at signing — cap the uplift, kill the evergreen clause, co-terminate the portfolio, and show up with your own usage data.

Vendor ManagementContract NegotiationRenewalsProcurement
7/11/2026 9 min

Thinking Like a CIO, Not a Security VP: The Agenda I’d Run (and What I’d Unlearn)

The jump to CIO is a change of altitude, not a bigger security job. Here's the agenda I'd run — and the three reflexes that made me good at security that I'd have to consciously unlearn.

LeadershipCIO TrackStrategyCareer
7/8/2026 9 min

Culture Is a Control. Start Auditing It Like One.

Most programs treat security culture as a poster, not a control — no objective, no defined behavior, no evidence, no failure mode. Give it those four and it becomes as auditable as any firewall.

Security CultureGRCGovernanceCompliance
7/7/2026 9 min

The Fractional CIO Engagement: What the First 30–90 Days Actually Buy

A fractional CIO is not a discounted full-timer. Here is what the first thirty, sixty, and ninety days each actually buy — and the honest limits of a seat you do not permanently hold.

LeadershipAdvisoryFractional LeadershipGovernance
6/26/2026 9 min

You Can't Run a Portfolio of 40 Pilots You Refuse to Rank.

Forty AI pilots, all alive and none ranked, is a science fair with a cloud bill — not a portfolio. Run enterprise AI the way a VC runs a book: expected value, feasibility, and risk on every use case, with graduation gates and kill criteria written up front.

Portfolio ManagementOperating ModelLeadershipFinOps
6/15/2026 5 min

Ransomware Recovery Is a Backups-You've-Tested Problem

Everyone has backups. Almost nobody has a restore they've actually run under fire. That gap is where ransomware turns a bad week into an existential one.

Cyber ResilienceRansomwareAWSDisaster Recovery
6/14/2026 9 min

You Have 70 Security Tools and 9 Controls. Consolidate to the Controls.

The license fee is the cheapest part of a security tool; the integration engineering, console staffing, and alert fatigue are the real bill. Map the stack to the controls it delivers, and rationalize on coverage and integration cost — not feature lists.

Vendor ManagementTool ConsolidationSecurity ArchitectureFinOps
6/12/2026 5 min

Make the Next Audit Boring: PCI and SOC Evidence as Code

Audits feel like fire drills because we treat evidence as something we go find later. Machine-readable SOC reports and modern PCI cryptography requirements finally let us wire proof into the pipeline instead.

ComplianceDevSecOpsFintechGRC
6/11/2026 5 min

Start Your Post-Quantum Migration in 2026, Not 2030

Post-quantum cryptography stopped being a research project and became a config task. The teams that win aren't waiting for a quantum computer — they're waiting for nothing.

CryptographySecurityComplianceFintech
6/9/2026 5 min

Thousands of Accounts, a Three-Person Platform Team: Guardrails at Scale

A lean team can govern a sprawling cloud estate without becoming a ticket queue — but only if you put the rules in the pipeline, not in your inbox.

Platform EngineeringCloud GovernanceAWSFintech
6/8/2026 8 min

Run Internal IT Like a Product, or Shadow IT Will Out-Ship You.

Internal platforms fail when they're run like monopolies. Give them product managers, roadmaps, and honest adoption metrics — and let your users defect. The paved road should win by being better, not by being mandated.

Product-Centric ITPlatform EngineeringInternal Developer ExperienceAdoption
6/7/2026 9 min

Decide the Breach-Disclosure Questions Before You Have a Breach.

The tactical runbook is a comparatively solved problem. Materiality, the SEC's four-day clock, the OFAC ransom gate, and the external message are executive decisions to pre-wire with a standing disclosure committee — not to improvise at hour three.

Incident ResponseDisclosureGovernanceCrisis Leadership
6/4/2026 5 min

Context Lock-In Is the Next Vendor-Risk Line Item

Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated for the prompts, context, and memory that quietly became the real switching cost.

Vendor RiskProcurementExit StrategyGovernance
6/2/2026 5 min

WAF in the Agent Era: Telling Good Bots From Abuse Without Blocking Customers

Agents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the question that actually matters.

Cloud SecurityWeb Application FirewallBot ManagementFintech
5/30/2026 10 min

Tech Due Diligence Before the Deal: What the Data Room Won't Show You.

A data room is an argument assembled to close the deal, not a description of the company you're buying. The four things that actually predict post-close integration cost — technical debt, run cost, architecture risk, and key-person risk — are the ones it's built not to show.

M&ATechnology Due DiligenceTechnical DebtIT Strategy
5/27/2026 9 min

Stop Charging the SSO Tax: Security Features Belong in the Funnel, Not the Enterprise Tier.

SSO and audit logs are the controls a buyer needs in order to trust you — conversion and retention features, not enterprise upsells. Paywall them and you tax your own funnel, teach your most security-conscious customers to route around you, and turn your best advocates into critics.

Product SecurityGrowthTrustFintech
5/21/2026 5 min

One Pane, Many Clouds: Consolidate SecOps on OCSF Instead of Buying Another Aggregator

Dashboard sprawl isn't a tooling gap you fix by buying more tooling. It's a schema problem. Standardize the data, and the single pane of glass stops being a slide and starts being real.

Cloud SecuritySecOpsSecurity ArchitectureFinTech
5/14/2026 5 min

From Cluster Autoscaler to Karpenter Across a Fleet: What Actually Breaks

Karpenter is the right call for most EKS shops. But the migration breaks things that have nothing to do with autoscaling — and a lean platform team should know exactly what those are before flipping the switch.

Platform EngineeringKubernetesCloud CostReliability
5/7/2026 5 min

Autonomous Pentesting Went GA. Should a Regulated Shop Turn It Loose?

A tool that scans and exploits your own estate on its own schedule is a gift and a loaded gun. Here's the scoping, approvals, and evidence I'd want before I let one run.

Cloud SecurityRisk ManagementPenetration TestingFintech
5/4/2026 6 min

The Eight-Domain Azure Security Review for Regulated Environments

An automated tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in the order an audit walks them, and the evidence each one has to produce.

Cloud SecurityAzureAuditCompliance
5/3/2026 9 min

The Software Vendor Is Coming to Audit You. Have Your Numbers First.

A vendor "license review" is a revenue motion wearing compliance clothes. The defense is continuous entitlement-vs-deployment reconciliation, so you walk into the true-up carrying your own number instead of arguing against theirs.

License ComplianceVendor AuditSoftware Asset ManagementProcurement
4/28/2026 5 min

Zero-Downtime Database Changes Are a Process, Not a Feature

AWS will sell you blue/green and serverless Aurora as if they make migrations safe. They don't. The runbook does. Here's the boring discipline that keeps schema changes from becoming incidents.

DevOpsDatabase MigrationsAuroraReliability
4/24/2026 9 min

Your Cyber-Insurance Renewal Is a Second Audit. Treat It Like One.

The underwriter's questionnaire is a controls roadmap someone paid to prioritize, and the renewal terms are a risk metric you don't get to choose. Mine the first, report the second, and close the coverage-gap traps before a claim gets denied.

Cyber InsuranceRisk TransferBoard ReportingFintech
4/23/2026 5 min

Aurora DSQL for the Ledger: Active-Active Without the War Stories

Multi-region active-active sounds like the answer to every ledger nightmare. Before you bet the books on it, interrogate the consistency, the recovery math, and the migration you are actually signing up for.

AWSFintechDatabasesResilience
4/16/2026 5 min

Get Authorization Out of Your App Code: Fine-Grained Authz for Fintech APIs

Authorization scattered across your codebase isn't a feature — it's a liability you can't prove. Here's the pattern multi-tenant regulated platforms actually need.

FintechAWSAuthorizationPlatform Security
4/14/2026 5 min

MCP Is a New Attack Surface: An Operator's IAM Playbook

Every MCP server you stand up is a new identity reaching into your cloud. The control that decides whether that's leverage or liability isn't the model — it's least-privilege IAM on every tool call.

Cloud SecurityIAMAWSDevOps
4/13/2026 8 min

Your Data Strategy Dies in the Funding Meeting, Not the Architecture Review.

Data-strategy decks don't die in the architecture review. They die in the funding meeting — because they pitch a capability the CFO can't fund instead of a decision it changes or a cost it removes.

Data StrategyLeadershipFinOpsBoard Reporting
4/8/2026 9 min

Fraud and Security Are the Same Threat Model. Stop Running Two Teams.

Account takeover, synthetic identity, and scams live on the line between fraud and security — one adversary and one signal split across two budgets. Fuse the threat model, the signal, and the case, and the attacker stops getting to arbitrage the seam between two half-blind teams.

FraudFintechSecurity OperationsIdentity
4/4/2026 9 min

Your Real Architecture Is the Integration Layer Nobody Owns.

Your org chart is a story you tell. The point-to-point integration mesh nobody owns is the operating model you're actually running — so own it deliberately, with an API platform and contracts, instead of paying the integration tax by accident.

Integration StrategyAPI PlatformMiddlewareTechnical Debt
4/3/2026 8 min

Operational Resilience Is a Business-Service Discipline, Not a DR Plan.

A DR plan brings the systems back. Operational resilience proves the service the customer buys stays inside a limit the board owns — through critical-service mapping, impact tolerances, and testing to failure across people, process, and third parties.

Operational ResilienceDORAThird-Party RiskFintech
4/2/2026 9 min

Capex Died and Your Balance Sheet Didn't Get the Memo.

SaaS and cloud moved nearly all technology spend to opex — emptying the asset column and quietly compressing reported EBITDA for the same economic activity. That reopens the ASC 350-40 software-capitalization question most tech leaders would rather duck, and the answer isn't in the ledger. It's in engineering telemetry only the platform org can produce.

Capex vs OpexIT FinanceCFO PartnershipSoftware Capitalization
3/31/2026 10 min

The Insider-Risk Program That Doesn't Turn You Into the Surveillance Department.

The budget line says buy the insider-threat tool, but insider risk is a cross-functional governance program — HR, legal, privacy, and security together — not a DLP purchase. Monitor the assets that carry the loss, not the people who touch them, and instrument the exit as a universal routine rather than a suspicion pointed at anyone. The control no vendor sells is the trust that keeps a colleague still willing to raise a concern.

Insider RiskData ProtectionHRFintech
3/30/2026 3 min

The Audit Passed in March. Is It Still True?

Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits.

ComplianceGRCAuditFintech
3/28/2026 9 min

Modernize the Core Without the Big-Bang: Strangle It Instead.

The full rewrite is the most expensive way to modernize a core system, and the one most likely to fail. Grow the new platform around the old one instead — how to sequence a strangler-fig migration, fund it without a two-year blank check, and keep the ledger running while you do it.

Legacy ModernizationStrangler PatternCore SystemsMigration
3/26/2026 5 min

How to Survive an FFIEC Exam (and Make Your Banking Partners Trust You)

An exam isn't a pop quiz you cram for. It's a referenceable proof of control — and if you run it right, your examiner's findings become your best sales collateral.

Fintech RiskComplianceBanking PartnershipsGovernance
3/21/2026 8 min

Who the CISO Reports To Is a Risk Decision, Not an Org-Chart Convenience.

Where the security leader sits on the org chart decides whose incentives they inherit and how far bad news has to travel. That makes the reporting line a control the board should own, not a convenience.

Org DesignGovernanceLeadershipBoard
3/10/2026 5 min

PCI DSS 4.0 Without the Last-Minute Scramble

PCI DSS 4.0 didn't add a longer checklist — it changed who has to do the thinking. Here's how to bake the new continuous-control expectations into engineering instead of cramming for the audit.

ComplianceFintechSecurity EngineeringAudit
3/4/2026 9 min

Technical Debt Is a Loan. Report the Interest to the Board.

Engineers estimate the principal of technical debt obsessively and never quantify the interest, so they ask the board to retire a balance instead of reporting a carrying cost the business is already paying. Measure the velocity tax where DORA metrics already leave fingerprints, roll it into a single debt-service ratio that trends, and give every loan one verdict: refinance, pay down, or default.

Technical DebtEngineering EconomicsBoard ReportingIT Finance
2/25/2026 8 min

Stop Running Security Awareness. Run a Human-Risk Program.

The annual training completion rate is the cleanest number in the board deck and the least connected to risk. Treat human risk like a portfolio — scored per team, with interventions matched to exposure — and measure behavior change, not attendance.

Human RiskSecurity CultureBehavior ChangeFintech
2/20/2026 3 min

How to Report Risk to People Who Don't Speak Security

Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.

LeadershipRisk ManagementCommunicationBoard Reporting
2/11/2026 5 min

Data Privacy Is an Operations Problem, Not a Policy PDF

Every AI privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP — that someone has to actually run. Treat privacy like an operating program, not a document you renew once a year.

Data PrivacySecurity OperationsComplianceFintech
2/8/2026 8 min

You Don't Have a Budget Problem. You Have 400 Apps and No Sunset Policy.

You can't cut your way out of an estate that only grows. The fix isn't a smaller budget — it's a TIME verdict on every app and a sunset policy that makes renewal a decision instead of a reflex.

Application PortfolioSaaS RationalizationRun-vs-GrowTechnical Debt
2/6/2026 5 min

An SBOM Nobody Reads Is Just Compliance Cosplay

Generating a software bill of materials is the easy part. Wiring it into the moment a change actually ships is where supply-chain security stops being theater and starts being a control.

Supply Chain SecurityDevOpsSoftware ProvenanceRisk Management
2/3/2026 5 min

Warm Standby Is a Promise You Have to Test

A disaster recovery plan you have never exercised is not a plan. It is a hypothesis with a logo on it.

ResilienceDisaster RecoveryCloud ArchitectureFintech
2/1/2026 8 min

Stop Coloring the Risk Register Red. Put a Dollar Figure on It.

A heat map's red cell is a category, not a quantity — two risks that differ by three orders of magnitude sit in the same shade of red. FAIR-style quantification replaces the color with a dollar figure and a range the CFO and board can weigh against controls spend and cyber-insurance premiums.

Risk QuantificationFAIRBoard ReportingFinance
1/30/2026 5 min

Build a Threat-Intelligence Program Your Sales Team Will Brag About

Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team actually wants to put in front of a customer.

Threat IntelligenceSecurity LeadershipFintechSecurity Operations
1/28/2026 4 min

Security and DevOps Under One Roof: Why I Stopped Apologizing for It

The case for the dual mandate, and why org-chart distance doesn't create security.

DevOpsSecurityLeadershipOrg Design
1/27/2026 9 min

Treat Data Like a Product With an Owner, or Pay for the Same Report Twice.

A data lake with no owner isn't a strategic asset — it's deferred cost, and every team that doesn't trust it quietly rebuilds the same report. Domain ownership, data contracts, and lineage turn data into a product the whole company trusts enough to reuse.

Data GovernanceData as a ProductData LineageBusiness Alignment
1/26/2026 5 min

Tabletops That Find Real Gaps, Not Ones That Flatter the Plan

Most incident tabletops are theater that confirms what the runbook already says. The useful ones break your assumptions and expose who actually gets to decide — before a real incident does it for you.

Incident ResponseSecurity OperationsLeadershipResilience
1/22/2026 5 min

Your SOC Metrics Are Vanity Until They Change a Decision

MTTD and MTTR look great on a slide and tell you almost nothing. The only metric that matters is whether it changed what someone did next.

Detection EngineeringSecurity OperationsSIEMMetrics
1/20/2026 5 min

Third-Party Risk When You ARE the Third Party

Serving 1,500+ financial institutions means their vendor-risk teams audit you constantly. Done right, that scrutiny stops being overhead and becomes the fastest way to close your next deal.

TPRMVendor RiskFintechSecurity Leadership
1/18/2026 8 min

Underwrite the Security Budget Like a Loss, Not a Line Item.

The security budget is the one line on the operating plan defended with an emotion — and emotions get discounted. Price the loss, count the revenue it unlocks, and defend it in the CFO's math instead.

Security StrategyRisk QuantificationBudgetLeadership
1/15/2026 6 min

Capital Allocation Governance: The Framework Companies Build Too Late

Mid-market capital allocation is rarely a strategy — it's individual capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.

LeadershipGovernanceBoard ReportingRisk Management
1/13/2026 5 min

Zero Trust for Humans: Just-in-Time Access Without the Help-Desk Revolt

Everyone's obsessing over non-human identity right now. Meanwhile your actual humans are sitting on standing admin rights — and the fix only works if people will actually use it.

IdentityZero TrustSecurity OperationsFintech
1/10/2026 9 min

Stop Running IT as a Cost Center. Give It a P&L and a Price List.

IT shows up to the budget meeting as one line, so the only conversation available is "make it smaller." Give the function a P&L and a price list — showback, unit economics per capability, run-vs-grow — and the CFO argues about value instead of headcount.

Technology Business ManagementIT FinanceShowbackRun-vs-Grow
1/8/2026 6 min

The First 24 Hours: An Incident Response Runbook You'll Actually Use

Most incident response plans are binders nobody opens at 2 a.m. Here's what actually has to happen in the opening day of a breach — roles, decision rights, evidence, and a comms cadence that keeps the grown-ups out of your way.

Incident ResponseSecurity OperationsCrisis LeadershipFintech
1/6/2026 5 min

The First 90 Days as a New Security Leader (When There's No Program Yet)

You were hired to build a security function from nothing. The trap isn't moving too slow — it's freezing the business while you try to make it perfect. Here's how to triage, ship quick wins, and earn the budget to actually build.

LeadershipSecurity ProgramFintechRisk Management
8/26/2025 5 min

Board Reporting That Drives Decisions, Not Status Updates

The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.

LeadershipBoard ReportingGovernanceCommunication
8/5/2025 7 min

The First 100 Days: A Post-Close Cyber Integration Playbook

The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.

SecurityM&ACloud SecurityLeadership
7/15/2025 6 min

Cloud FinOps for the Mid-Market: Where 25–40% of Spend Actually Hides

The press-release version of cloud savings cancels workloads and books compliance debt. The version that lasts is commitment management and SaaS rationalization.

FinOpsAWSAzureCloud Cost