Technology Leadership
Essays on technology leadership: operating models, strategy versus project backlogs, board reporting, org design, and the shift from VP to CIO thinking.
Essays on technology leadership from a working VP: turning project backlogs into actual strategy, IT operating models as value chains, ranking a pilot portfolio, and what a fractional CIO engagement buys in the first 90 days. Less framework worship, more of what survives contact with a real org chart.
23 posts, newest first
A Roadmap Full of Projects Is a Backlog
A slide of thirty project names with quarters is a backlog, not a strategy. Anchor the roadmap to outcomes — and make every item name what it retires.
IT Operating Model: Org Chart to Value Chain
IT org charts name technology towers; the customer pays for every handoff between them. Redraw the function around business capabilities and value streams.
Thinking Like a CIO, Not a Security VP
The jump to CIO is a change of altitude, not a bigger security job. The agenda I'd run — and the three security reflexes I'd have to consciously unlearn.
Fractional CIO: What 30–90 Days Actually Buy
A fractional CIO is not a discounted full-timer. What the first thirty, sixty, and ninety days each actually buy — and the honest limits of the seat.
Rank Your AI Pilots or It's Not a Portfolio
Forty unranked AI pilots is a science fair with a cloud bill. Run the portfolio like a VC book: expected value, feasibility, risk, and kill criteria up front.
Your Security Program Is a Sales Asset
Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.
Pre-Wire Breach Disclosure Before the Breach
Materiality, the SEC's four-day clock, the OFAC ransom gate: decisions to pre-wire with a standing disclosure committee, not improvise at hour three.
Context Lock-In Is the Next Vendor Risk
Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated the prompts, context, and memory that became the switching cost.
Tech Due Diligence: What Data Rooms Hide
A data room is built to close the deal. Technical debt, run cost, architecture risk, and key-person risk predict integration cost — and it hides all four.
Data Strategy Dies in the Funding Meeting
Data-strategy decks die in the funding meeting, not the architecture review — pitching a capability the CFO can't fund instead of a decision it changes.
The Integration Layer Nobody Owns
The org chart is a story; the point-to-point integration mesh nobody owns is your real operating model. Own it with an API platform and contracts.
The CISO Reporting Line Is a Risk Decision
Where the security leader sits decides whose incentives they inherit and how far bad news travels. The reporting line is a control the board should own.
Report Risk to Those Who Don't Speak Security
Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.
Threat Intel Your Sales Team Will Brag About
Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.
Security and DevOps Under One Roof
The case for running security and DevOps as one mandate: org-chart distance doesn't create security, and owning the pipelines changes how you protect them.
Tabletops That Find Real Gaps
Most incident tabletops are theater confirming the runbook. The useful ones break your assumptions and expose who decides — before a real incident does.
Third-Party Risk When You ARE the Third Party
Serving 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.
Underwrite the Security Budget Like a Loss
The security budget is the line defended with emotion — and emotion gets discounted. Price the loss, count the revenue it unlocks, argue in the CFO's math.
Capital Allocation Governance, Built Too Late
Mid-market capital allocation is rarely a strategy — capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.
Incident Response: The First 24 Hours
Most IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.
The New Security Leader's First 90 Days
Hired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.
Board Reporting That Drives Decisions
The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.
Post-Close Cyber Integration: A 100-Day Plan
The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.