Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Topic

Technology Leadership

Essays on technology leadership: operating models, strategy versus project backlogs, board reporting, org design, and the shift from VP to CIO thinking.

Essays on technology leadership from a working VP: turning project backlogs into actual strategy, IT operating models as value chains, ranking a pilot portfolio, and what a fractional CIO engagement buys in the first 90 days. Less framework worship, more of what survives contact with a real org chart.

23 posts, newest first

Jul 23, 2026 8 min

A Roadmap Full of Projects Is a Backlog

A slide of thirty project names with quarters is a backlog, not a strategy. Anchor the roadmap to outcomes — and make every item name what it retires.

Technology RoadmapIT StrategyPortfolio ManagementBusiness Alignment
Jul 23, 2026 9 min

IT Operating Model: Org Chart to Value Chain

IT org charts name technology towers; the customer pays for every handoff between them. Redraw the function around business capabilities and value streams.

IT Operating ModelOrg DesignValue StreamsBusiness Alignment
Jul 11, 2026 9 min

Thinking Like a CIO, Not a Security VP

The jump to CIO is a change of altitude, not a bigger security job. The agenda I'd run — and the three security reflexes I'd have to consciously unlearn.

LeadershipCIO TrackStrategyCareer
Jul 7, 2026 9 min

Fractional CIO: What 30–90 Days Actually Buy

A fractional CIO is not a discounted full-timer. What the first thirty, sixty, and ninety days each actually buy — and the honest limits of the seat.

LeadershipAdvisoryFractional LeadershipGovernance
Jun 26, 2026 9 min

Rank Your AI Pilots or It's Not a Portfolio

Forty unranked AI pilots is a science fair with a cloud bill. Run the portfolio like a VC book: expected value, feasibility, risk, and kill criteria up front.

Portfolio ManagementOperating ModelLeadershipFinOps
Jun 10, 2026 4 min

Your Security Program Is a Sales Asset

Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.

Security StrategyFintechGRCLeadership
Jun 7, 2026 9 min

Pre-Wire Breach Disclosure Before the Breach

Materiality, the SEC's four-day clock, the OFAC ransom gate: decisions to pre-wire with a standing disclosure committee, not improvise at hour three.

Incident ResponseDisclosureGovernanceCrisis Leadership
Jun 4, 2026 5 min

Context Lock-In Is the Next Vendor Risk

Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated the prompts, context, and memory that became the switching cost.

Vendor RiskProcurementExit StrategyGovernance
May 30, 2026 10 min

Tech Due Diligence: What Data Rooms Hide

A data room is built to close the deal. Technical debt, run cost, architecture risk, and key-person risk predict integration cost — and it hides all four.

M&ATechnology Due DiligenceTechnical DebtIT Strategy
Apr 13, 2026 8 min

Data Strategy Dies in the Funding Meeting

Data-strategy decks die in the funding meeting, not the architecture review — pitching a capability the CFO can't fund instead of a decision it changes.

Data StrategyLeadershipFinOpsBoard Reporting
Apr 4, 2026 9 min

The Integration Layer Nobody Owns

The org chart is a story; the point-to-point integration mesh nobody owns is your real operating model. Own it with an API platform and contracts.

Integration StrategyAPI PlatformMiddlewareTechnical Debt
Mar 21, 2026 8 min

The CISO Reporting Line Is a Risk Decision

Where the security leader sits decides whose incentives they inherit and how far bad news travels. The reporting line is a control the board should own.

Org DesignGovernanceLeadershipBoard
Feb 20, 2026 3 min

Report Risk to Those Who Don't Speak Security

Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.

LeadershipRisk ManagementCommunicationBoard Reporting
Jan 30, 2026 5 min

Threat Intel Your Sales Team Will Brag About

Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team wants to put in front of customers.

Threat IntelligenceSecurity LeadershipFintechSecurity Operations
Jan 28, 2026 4 min

Security and DevOps Under One Roof

The case for running security and DevOps as one mandate: org-chart distance doesn't create security, and owning the pipelines changes how you protect them.

DevOpsSecurityLeadershipOrg Design
Jan 26, 2026 5 min

Tabletops That Find Real Gaps

Most incident tabletops are theater confirming the runbook. The useful ones break your assumptions and expose who decides — before a real incident does.

Incident ResponseSecurity OperationsLeadershipResilience
Jan 20, 2026 5 min

Third-Party Risk When You ARE the Third Party

Serving 1,500+ financial institutions means vendor-risk teams audit you constantly. Done right, that scrutiny becomes the fastest way to close your next deal.

TPRMVendor RiskFintechSecurity Leadership
Jan 18, 2026 8 min

Underwrite the Security Budget Like a Loss

The security budget is the line defended with emotion — and emotion gets discounted. Price the loss, count the revenue it unlocks, argue in the CFO's math.

Security StrategyRisk QuantificationBudgetLeadership
Jan 15, 2026 6 min

Capital Allocation Governance, Built Too Late

Mid-market capital allocation is rarely a strategy — capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.

LeadershipGovernanceBoard ReportingRisk Management
Jan 8, 2026 6 min

Incident Response: The First 24 Hours

Most IR plans are binders nobody opens at 2 a.m. What has to happen in the first day of a breach — roles, decision rights, evidence, and a comms cadence.

Incident ResponseSecurity OperationsCrisis LeadershipFintech
Jan 6, 2026 5 min

The New Security Leader's First 90 Days

Hired to build a security function from nothing? The trap isn't moving too slow — it's freezing the business. How to triage, ship quick wins, and earn budget.

LeadershipSecurity ProgramFintechRisk Management
Aug 26, 2025 5 min

Board Reporting That Drives Decisions

The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.

LeadershipBoard ReportingGovernanceCommunication
Aug 5, 2025 7 min

Post-Close Cyber Integration: A 100-Day Plan

The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.

SecurityM&ACloud SecurityLeadership