Writing
Searchable posts on AI governance, security, leadership, and platform engineering.
Featured
Your Security Program Is a Sales Asset. Start Treating It Like One.
Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.
AWS Cost Levers That Actually Moved the Needle
Cutting ~35% off a multi-region AWS footprint with no capability loss — the levers in the order they paid back, best first.
More posts
Your IT Operating Model Is an Org Chart. It Should Be a Value Chain.
The IT org chart names technology towers, and the customer pays for the handoff at every seam between them. Redraw the function around business capabilities and value streams — the same collapse I already ran, on purpose, at the scale of two towers.
Cyber and AI Oversight From the Board Seat
Reporting to a board and sitting on one are different jobs. What the reporting side taught me about cyber and AI oversight — and the questions I would ask from the director's seat.
The Renewal Clock Starts the Day You Sign.
Your leverage over a vendor is highest before you deploy and lowest at renewal. So negotiate next year's renewal at signing — cap the uplift, kill the evergreen clause, co-terminate the portfolio, and show up with your own usage data.
Thinking Like a CIO, Not a Security VP: The Agenda I’d Run (and What I’d Unlearn)
The jump to CIO is a change of altitude, not a bigger security job. Here's the agenda I'd run — and the three reflexes that made me good at security that I'd have to consciously unlearn.
Culture Is a Control. Start Auditing It Like One.
Most programs treat security culture as a poster, not a control — no objective, no defined behavior, no evidence, no failure mode. Give it those four and it becomes as auditable as any firewall.
The Fractional CIO Engagement: What the First 30–90 Days Actually Buy
A fractional CIO is not a discounted full-timer. Here is what the first thirty, sixty, and ninety days each actually buy — and the honest limits of a seat you do not permanently hold.
You Can't Run a Portfolio of 40 Pilots You Refuse to Rank.
Forty AI pilots, all alive and none ranked, is a science fair with a cloud bill — not a portfolio. Run enterprise AI the way a VC runs a book: expected value, feasibility, and risk on every use case, with graduation gates and kill criteria written up front.
Ransomware Recovery Is a Backups-You've-Tested Problem
Everyone has backups. Almost nobody has a restore they've actually run under fire. That gap is where ransomware turns a bad week into an existential one.
You Have 70 Security Tools and 9 Controls. Consolidate to the Controls.
The license fee is the cheapest part of a security tool; the integration engineering, console staffing, and alert fatigue are the real bill. Map the stack to the controls it delivers, and rationalize on coverage and integration cost — not feature lists.
Make the Next Audit Boring: PCI and SOC Evidence as Code
Audits feel like fire drills because we treat evidence as something we go find later. Machine-readable SOC reports and modern PCI cryptography requirements finally let us wire proof into the pipeline instead.
Start Your Post-Quantum Migration in 2026, Not 2030
Post-quantum cryptography stopped being a research project and became a config task. The teams that win aren't waiting for a quantum computer — they're waiting for nothing.
Thousands of Accounts, a Three-Person Platform Team: Guardrails at Scale
A lean team can govern a sprawling cloud estate without becoming a ticket queue — but only if you put the rules in the pipeline, not in your inbox.
Run Internal IT Like a Product, or Shadow IT Will Out-Ship You.
Internal platforms fail when they're run like monopolies. Give them product managers, roadmaps, and honest adoption metrics — and let your users defect. The paved road should win by being better, not by being mandated.
Decide the Breach-Disclosure Questions Before You Have a Breach.
The tactical runbook is a comparatively solved problem. Materiality, the SEC's four-day clock, the OFAC ransom gate, and the external message are executive decisions to pre-wire with a standing disclosure committee — not to improvise at hour three.
Context Lock-In Is the Next Vendor-Risk Line Item
Everyone negotiated data egress and capacity in their AI contracts. Almost nobody negotiated for the prompts, context, and memory that quietly became the real switching cost.
WAF in the Agent Era: Telling Good Bots From Abuse Without Blocking Customers
Agents are now real customers hitting your edge with real economics. The old bot question — human or machine? — is the wrong one. Here's the question that actually matters.
Tech Due Diligence Before the Deal: What the Data Room Won't Show You.
A data room is an argument assembled to close the deal, not a description of the company you're buying. The four things that actually predict post-close integration cost — technical debt, run cost, architecture risk, and key-person risk — are the ones it's built not to show.
Stop Charging the SSO Tax: Security Features Belong in the Funnel, Not the Enterprise Tier.
SSO and audit logs are the controls a buyer needs in order to trust you — conversion and retention features, not enterprise upsells. Paywall them and you tax your own funnel, teach your most security-conscious customers to route around you, and turn your best advocates into critics.
One Pane, Many Clouds: Consolidate SecOps on OCSF Instead of Buying Another Aggregator
Dashboard sprawl isn't a tooling gap you fix by buying more tooling. It's a schema problem. Standardize the data, and the single pane of glass stops being a slide and starts being real.
From Cluster Autoscaler to Karpenter Across a Fleet: What Actually Breaks
Karpenter is the right call for most EKS shops. But the migration breaks things that have nothing to do with autoscaling — and a lean platform team should know exactly what those are before flipping the switch.
Autonomous Pentesting Went GA. Should a Regulated Shop Turn It Loose?
A tool that scans and exploits your own estate on its own schedule is a gift and a loaded gun. Here's the scoping, approvals, and evidence I'd want before I let one run.
The Eight-Domain Azure Security Review for Regulated Environments
An automated tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in the order an audit walks them, and the evidence each one has to produce.
The Software Vendor Is Coming to Audit You. Have Your Numbers First.
A vendor "license review" is a revenue motion wearing compliance clothes. The defense is continuous entitlement-vs-deployment reconciliation, so you walk into the true-up carrying your own number instead of arguing against theirs.
Zero-Downtime Database Changes Are a Process, Not a Feature
AWS will sell you blue/green and serverless Aurora as if they make migrations safe. They don't. The runbook does. Here's the boring discipline that keeps schema changes from becoming incidents.
Your Cyber-Insurance Renewal Is a Second Audit. Treat It Like One.
The underwriter's questionnaire is a controls roadmap someone paid to prioritize, and the renewal terms are a risk metric you don't get to choose. Mine the first, report the second, and close the coverage-gap traps before a claim gets denied.
Aurora DSQL for the Ledger: Active-Active Without the War Stories
Multi-region active-active sounds like the answer to every ledger nightmare. Before you bet the books on it, interrogate the consistency, the recovery math, and the migration you are actually signing up for.
Get Authorization Out of Your App Code: Fine-Grained Authz for Fintech APIs
Authorization scattered across your codebase isn't a feature — it's a liability you can't prove. Here's the pattern multi-tenant regulated platforms actually need.
MCP Is a New Attack Surface: An Operator's IAM Playbook
Every MCP server you stand up is a new identity reaching into your cloud. The control that decides whether that's leverage or liability isn't the model — it's least-privilege IAM on every tool call.
Your Data Strategy Dies in the Funding Meeting, Not the Architecture Review.
Data-strategy decks don't die in the architecture review. They die in the funding meeting — because they pitch a capability the CFO can't fund instead of a decision it changes or a cost it removes.
Fraud and Security Are the Same Threat Model. Stop Running Two Teams.
Account takeover, synthetic identity, and scams live on the line between fraud and security — one adversary and one signal split across two budgets. Fuse the threat model, the signal, and the case, and the attacker stops getting to arbitrage the seam between two half-blind teams.
Your Real Architecture Is the Integration Layer Nobody Owns.
Your org chart is a story you tell. The point-to-point integration mesh nobody owns is the operating model you're actually running — so own it deliberately, with an API platform and contracts, instead of paying the integration tax by accident.
Operational Resilience Is a Business-Service Discipline, Not a DR Plan.
A DR plan brings the systems back. Operational resilience proves the service the customer buys stays inside a limit the board owns — through critical-service mapping, impact tolerances, and testing to failure across people, process, and third parties.
Capex Died and Your Balance Sheet Didn't Get the Memo.
SaaS and cloud moved nearly all technology spend to opex — emptying the asset column and quietly compressing reported EBITDA for the same economic activity. That reopens the ASC 350-40 software-capitalization question most tech leaders would rather duck, and the answer isn't in the ledger. It's in engineering telemetry only the platform org can produce.
The Insider-Risk Program That Doesn't Turn You Into the Surveillance Department.
The budget line says buy the insider-threat tool, but insider risk is a cross-functional governance program — HR, legal, privacy, and security together — not a DLP purchase. Monitor the assets that carry the loss, not the people who touch them, and instrument the exit as a universal routine rather than a suspicion pointed at anyone. The control no vendor sells is the trust that keeps a colleague still willing to raise a concern.
The Audit Passed in March. Is It Still True?
Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits.
Modernize the Core Without the Big-Bang: Strangle It Instead.
The full rewrite is the most expensive way to modernize a core system, and the one most likely to fail. Grow the new platform around the old one instead — how to sequence a strangler-fig migration, fund it without a two-year blank check, and keep the ledger running while you do it.
How to Survive an FFIEC Exam (and Make Your Banking Partners Trust You)
An exam isn't a pop quiz you cram for. It's a referenceable proof of control — and if you run it right, your examiner's findings become your best sales collateral.
Who the CISO Reports To Is a Risk Decision, Not an Org-Chart Convenience.
Where the security leader sits on the org chart decides whose incentives they inherit and how far bad news has to travel. That makes the reporting line a control the board should own, not a convenience.
PCI DSS 4.0 Without the Last-Minute Scramble
PCI DSS 4.0 didn't add a longer checklist — it changed who has to do the thinking. Here's how to bake the new continuous-control expectations into engineering instead of cramming for the audit.
Technical Debt Is a Loan. Report the Interest to the Board.
Engineers estimate the principal of technical debt obsessively and never quantify the interest, so they ask the board to retire a balance instead of reporting a carrying cost the business is already paying. Measure the velocity tax where DORA metrics already leave fingerprints, roll it into a single debt-service ratio that trends, and give every loan one verdict: refinance, pay down, or default.
Stop Running Security Awareness. Run a Human-Risk Program.
The annual training completion rate is the cleanest number in the board deck and the least connected to risk. Treat human risk like a portfolio — scored per team, with interventions matched to exposure — and measure behavior change, not attendance.
How to Report Risk to People Who Don't Speak Security
Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.
Data Privacy Is an Operations Problem, Not a Policy PDF
Every AI privacy promise rests on unglamorous plumbing — consumer-rights workflows, retention, DLP — that someone has to actually run. Treat privacy like an operating program, not a document you renew once a year.
You Don't Have a Budget Problem. You Have 400 Apps and No Sunset Policy.
You can't cut your way out of an estate that only grows. The fix isn't a smaller budget — it's a TIME verdict on every app and a sunset policy that makes renewal a decision instead of a reflex.
An SBOM Nobody Reads Is Just Compliance Cosplay
Generating a software bill of materials is the easy part. Wiring it into the moment a change actually ships is where supply-chain security stops being theater and starts being a control.
Warm Standby Is a Promise You Have to Test
A disaster recovery plan you have never exercised is not a plan. It is a hypothesis with a logo on it.
Stop Coloring the Risk Register Red. Put a Dollar Figure on It.
A heat map's red cell is a category, not a quantity — two risks that differ by three orders of magnitude sit in the same shade of red. FAIR-style quantification replaces the color with a dollar figure and a range the CFO and board can weigh against controls spend and cyber-insurance premiums.
Build a Threat-Intelligence Program Your Sales Team Will Brag About
Most threat intel dies as a PDF nobody reads. Done right, it sharpens your defense and becomes something your account team actually wants to put in front of a customer.
Security and DevOps Under One Roof: Why I Stopped Apologizing for It
The case for the dual mandate, and why org-chart distance doesn't create security.
Treat Data Like a Product With an Owner, or Pay for the Same Report Twice.
A data lake with no owner isn't a strategic asset — it's deferred cost, and every team that doesn't trust it quietly rebuilds the same report. Domain ownership, data contracts, and lineage turn data into a product the whole company trusts enough to reuse.
Tabletops That Find Real Gaps, Not Ones That Flatter the Plan
Most incident tabletops are theater that confirms what the runbook already says. The useful ones break your assumptions and expose who actually gets to decide — before a real incident does it for you.
Your SOC Metrics Are Vanity Until They Change a Decision
MTTD and MTTR look great on a slide and tell you almost nothing. The only metric that matters is whether it changed what someone did next.
Third-Party Risk When You ARE the Third Party
Serving 1,500+ financial institutions means their vendor-risk teams audit you constantly. Done right, that scrutiny stops being overhead and becomes the fastest way to close your next deal.
Underwrite the Security Budget Like a Loss, Not a Line Item.
The security budget is the one line on the operating plan defended with an emotion — and emotions get discounted. Price the loss, count the revenue it unlocks, and defend it in the CFO's math instead.
Capital Allocation Governance: The Framework Companies Build Too Late
Mid-market capital allocation is rarely a strategy — it's individual capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.
Zero Trust for Humans: Just-in-Time Access Without the Help-Desk Revolt
Everyone's obsessing over non-human identity right now. Meanwhile your actual humans are sitting on standing admin rights — and the fix only works if people will actually use it.
Stop Running IT as a Cost Center. Give It a P&L and a Price List.
IT shows up to the budget meeting as one line, so the only conversation available is "make it smaller." Give the function a P&L and a price list — showback, unit economics per capability, run-vs-grow — and the CFO argues about value instead of headcount.
The First 24 Hours: An Incident Response Runbook You'll Actually Use
Most incident response plans are binders nobody opens at 2 a.m. Here's what actually has to happen in the opening day of a breach — roles, decision rights, evidence, and a comms cadence that keeps the grown-ups out of your way.
The First 90 Days as a New Security Leader (When There's No Program Yet)
You were hired to build a security function from nothing. The trap isn't moving too slow — it's freezing the business while you try to make it perfect. Here's how to triage, ship quick wins, and earn the budget to actually build.
Board Reporting That Drives Decisions, Not Status Updates
The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.
The First 100 Days: A Post-Close Cyber Integration Playbook
The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.
Cloud FinOps for the Mid-Market: Where 25–40% of Spend Actually Hides
The press-release version of cloud savings cancels workloads and books compliance debt. The version that lasts is commitment management and SaaS rationalization.
