Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Topic

Fintech & Risk

Writing on fintech security and risk: board-level cyber reporting, PCI and SOC compliance, vendor and concentration risk, and IT finance for platforms.

Writing at the intersection of fintech and risk: board-level cyber reporting, PCI and SOC evidence, vendor and concentration risk, and what security programs cost and return. It's the operator's view from a fintech platform serving 1,500+ financial institutions, where compliance is a sales asset rather than overhead.

35 posts, newest first

Jul 16, 2026 9 min

Cyber and AI Oversight From the Board Seat

Reporting to a board and sitting on one are different jobs. What reporting taught me about cyber and AI oversight, and what I'd ask from the director's seat.

Board GovernanceOversightRisk ManagementFintech
Jun 12, 2026 5 min

Evidence as Code: Make the Next Audit Boring

Audits feel like fire drills because evidence is hunted after the fact. Machine-readable SOC reports and modern PCI rules let proof live in the pipeline.

ComplianceDevSecOpsFintechGRC
Jun 11, 2026 5 min

Start Post-Quantum Migration in 2026

Post-quantum cryptography stopped being research and became a config task. The teams that win aren't waiting for a quantum computer — they wait for nothing.

CryptographySecurityComplianceFintech
Jun 10, 2026 4 min

Your Security Program Is a Sales Asset

Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.

Security StrategyFintechGRCLeadership
Jun 9, 2026 5 min

Guardrails at Scale for a Three-Person Team

A lean team can govern a sprawling cloud estate without becoming a ticket queue — but only if you put the rules in the pipeline, not in your inbox.

Platform EngineeringCloud GovernanceAWSFintech
Jun 4, 2026 5 min

Context Lock-In Is the Next Vendor Risk

Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated the prompts, context, and memory that became the switching cost.

Vendor RiskProcurementExit StrategyGovernance
Jun 2, 2026 5 min

WAF in the Agent Era: Good Bots vs. Abuse

Agents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the one that matters.

Cloud SecurityWeb Application FirewallBot ManagementFintech
May 27, 2026 9 min

Stop Charging the SSO Tax

SSO and audit logs are the controls a buyer needs to trust you — conversion features, not enterprise upsells. Paywall them and you tax your own funnel.

Product SecurityGrowthTrustFintech
May 21, 2026 5 min

Consolidate SecOps on OCSF, Not Aggregators

Dashboard sprawl isn't a tooling gap you fix with more tooling — it's a schema problem. Standardize on OCSF and the single pane of glass becomes real.

Cloud SecuritySecOpsSecurity ArchitectureFinTech
May 7, 2026 5 min

Autonomous Pentesting in a Regulated Shop

A tool that scans and exploits your estate on its own schedule is a gift and a loaded gun. The scoping, approvals, and evidence I'd want before it runs.

Cloud SecurityRisk ManagementPenetration TestingFintech
Apr 24, 2026 9 min

Cyber-Insurance Renewal Is a Second Audit

The underwriter's questionnaire is a prioritized controls roadmap; your renewal terms are a risk metric. Mine both and close the coverage-gap traps early.

Cyber InsuranceRisk TransferBoard ReportingFintech
Apr 23, 2026 5 min

Aurora DSQL for the Ledger: Active-Active

Multi-region active-active sounds like the answer to ledger nightmares. Interrogate the consistency, recovery math, and migration before betting the books.

AWSFintechDatabasesResilience
Apr 16, 2026 5 min

Fine-Grained Authorization for Fintech APIs

Authorization scattered across your codebase isn't a feature — it's a liability you can't prove. The pattern multi-tenant regulated platforms actually need.

FintechAWSAuthorizationPlatform Security
Apr 8, 2026 9 min

Fraud and Security Are One Threat Model

Account takeover, synthetic identity, and scams sit between fraud and security — one adversary split across two budgets. Fuse the threat model and the signal.

FraudFintechSecurity OperationsIdentity
Apr 3, 2026 8 min

Operational Resilience Is Not a DR Plan

A DR plan brings systems back; resilience keeps the service inside a limit the board owns — impact tolerances, service mapping, testing to failure.

Operational ResilienceDORAThird-Party RiskFintech
Apr 2, 2026 9 min

Capex Died. Your Balance Sheet Didn't Notice.

SaaS and cloud moved tech spend to opex, quietly compressing EBITDA. That reopens the ASC 350-40 capitalization question — answered by engineering telemetry.

Capex vs OpexIT FinanceCFO PartnershipSoftware Capitalization
Mar 31, 2026 10 min

Insider Risk Without Becoming Surveillance

Insider risk is a governance program across HR, legal, privacy, and security — not a DLP purchase. Monitor the assets that carry the loss, not the people.

Insider RiskData ProtectionHRFintech
Mar 30, 2026 3 min

The Audit Passed in March. Is It Still True?

Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits — and what it takes to run it year-round.

ComplianceGRCAuditFintech
Mar 26, 2026 5 min

How to Survive an FFIEC Exam

An exam isn't a pop quiz you cram for. It's referenceable proof of control — run it right and the examiner's findings become your best sales collateral.

Fintech RiskComplianceBanking PartnershipsGovernance
Mar 10, 2026 5 min

PCI DSS 4.0 Without the Last-Minute Scramble

PCI DSS 4.0 didn't add a longer checklist — it changed who does the thinking. Bake continuous-control expectations into engineering, not audit-week cramming.

ComplianceFintechSecurity EngineeringAudit
Mar 4, 2026 9 min

Technical Debt Is a Loan: Report the Interest

Engineers size technical-debt principal, never the interest. Measure the velocity tax where DORA metrics leave fingerprints; give every loan a verdict.

Technical DebtEngineering EconomicsBoard ReportingIT Finance
Feb 25, 2026 8 min

Run a Human-Risk Program, Not Awareness

Training completion is the cleanest number in the board deck and the least tied to risk. Score human risk per team and measure behavior, not attendance.

Human RiskSecurity CultureBehavior ChangeFintech
Feb 20, 2026 3 min

Report Risk to Those Who Don't Speak Security

Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.

LeadershipRisk ManagementCommunicationBoard Reporting
Feb 11, 2026 5 min

Data Privacy Is an Operations Problem

Every privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP. Treat privacy as an operating program, not an annual PDF.

Data PrivacySecurity OperationsComplianceFintech
Feb 6, 2026 5 min

An SBOM Nobody Reads Is Compliance Cosplay

Generating a software bill of materials is the easy part. Wiring it into the moment a change ships is where supply-chain security stops being theater.

Supply Chain SecurityDevOpsSoftware ProvenanceRisk Management
Feb 3, 2026 5 min

Warm Standby Is a Promise You Have to Test

A DR plan you have never exercised is a hypothesis with a logo on it. Warm standby only counts as a promise if you test the failover before you need it.

ResilienceDisaster RecoveryCloud ArchitectureFintech
Feb 1, 2026 8 min

Put a Dollar Figure on the Risk Register

A heat map's red cell is a category, not a quantity. FAIR-style quantification puts a dollar range on each risk that the CFO can weigh against controls spend.

Risk QuantificationFAIRBoard ReportingFinance
Jan 30, 2026 5 min

Threat Intel Your Sales Team Will Brag About

Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.

Threat IntelligenceSecurity LeadershipFintechSecurity Operations
Jan 20, 2026 5 min

Third-Party Risk When You ARE the Third Party

Serving 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.

TPRMVendor RiskFintechSecurity Leadership
Jan 18, 2026 8 min

Underwrite the Security Budget Like a Loss

The security budget is the line defended with emotion — and emotion gets discounted. Price the loss, count the revenue it unlocks, argue in the CFO's math.

Security StrategyRisk QuantificationBudgetLeadership
Jan 15, 2026 6 min

Capital Allocation Governance, Built Too Late

Mid-market capital allocation is rarely a strategy — capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.

LeadershipGovernanceBoard ReportingRisk Management
Jan 13, 2026 5 min

Zero Trust for Humans: Just-in-Time Access

Everyone's obsessing over non-human identity. Meanwhile your humans sit on standing admin rights — and the fix only works if people will actually use it.

IdentityZero TrustSecurity OperationsFintech
Jan 10, 2026 9 min

Stop Running IT as a Cost Center

IT shows up as one budget line, so the only move is "make it smaller." A P&L and price list — showback, unit economics — turn the argument to value.

Technology Business ManagementIT FinanceShowbackRun-vs-Grow
Jan 8, 2026 6 min

Incident Response: The First 24 Hours

Most IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.

Incident ResponseSecurity OperationsCrisis LeadershipFintech
Jan 6, 2026 5 min

The New Security Leader's First 90 Days

Hired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.

LeadershipSecurity ProgramFintechRisk Management