<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Michael York — Field Notes</title>
    <link>https://ypro.dev/</link>
    <atom:link href="https://ypro.dev/rss.xml" rel="self" type="application/rss+xml" />
    <description>Security, DevOps, and AI governance — what's actually working.</description>
    <language>en-us</language>
    <item>
      <title>Your Security Program Is a Sales Asset. Start Treating It Like One.</title>
      <link>https://ypro.dev/writing/security-program-is-a-sales-asset</link>
      <guid isPermaLink="true">https://ypro.dev/writing/security-program-is-a-sales-asset</guid>
      <pubDate>Wed, 10 Jun 2026 12:00:00 GMT</pubDate>
      <description>Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.</description>
    </item>
    <item>
      <title>The Boundary Layer Is the Actual AI Control</title>
      <link>https://ypro.dev/writing/the-boundary-layer-is-the-actual-ai-control</link>
      <guid isPermaLink="true">https://ypro.dev/writing/the-boundary-layer-is-the-actual-ai-control</guid>
      <pubDate>Fri, 22 May 2026 12:00:00 GMT</pubDate>
      <description>Every AI governance framework describes the same controls. The one that actually matters is a single design decision: does this output get acted on, or interpreted first?</description>
    </item>
    <item>
      <title>AWS Cost Levers That Actually Moved the Needle</title>
      <link>https://ypro.dev/writing/aws-cost-levers-that-moved-the-needle</link>
      <guid isPermaLink="true">https://ypro.dev/writing/aws-cost-levers-that-moved-the-needle</guid>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <description>Cutting ~35% off a multi-region AWS footprint with no capability loss — the levers in the order they paid back, best first.</description>
    </item>
    <item>
      <title>What AI Actually Changes for Attackers (and What It Doesn't)</title>
      <link>https://ypro.dev/writing/what-ai-changes-for-attackers</link>
      <guid isPermaLink="true">https://ypro.dev/writing/what-ai-changes-for-attackers</guid>
      <pubDate>Sat, 18 Apr 2026 12:00:00 GMT</pubDate>
      <description>Cutting through the threat inflation: what genuinely shifts for attackers, what doesn't, and where to harden.</description>
    </item>
    <item>
      <title>The Audit Passed in March. Is It Still True?</title>
      <link>https://ypro.dev/writing/the-audit-passed-in-march</link>
      <guid isPermaLink="true">https://ypro.dev/writing/the-audit-passed-in-march</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <description>Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits.</description>
    </item>
    <item>
      <title>Automate the Boring, Not the Judgment</title>
      <link>https://ypro.dev/writing/automate-the-boring-not-the-judgment</link>
      <guid isPermaLink="true">https://ypro.dev/writing/automate-the-boring-not-the-judgment</guid>
      <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
      <description>A framework for what security work to hand to machines, and the line you should never let automation cross.</description>
    </item>
    <item>
      <title>How to Report Risk to People Who Don't Speak Security</title>
      <link>https://ypro.dev/writing/report-risk-to-people-who-dont-speak-security</link>
      <guid isPermaLink="true">https://ypro.dev/writing/report-risk-to-people-who-dont-speak-security</guid>
      <pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate>
      <description>Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.</description>
    </item>
    <item>
      <title>Security and DevOps Under One Roof: Why I Stopped Apologizing for It</title>
      <link>https://ypro.dev/writing/security-and-devops-under-one-roof</link>
      <guid isPermaLink="true">https://ypro.dev/writing/security-and-devops-under-one-roof</guid>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <description>The case for the dual mandate, and why org-chart distance doesn't create security.</description>
    </item>
    <item>
      <title>Pick the Model Like You Size a Cluster, Not Like You Pick a Sports Team</title>
      <link>https://ypro.dev/writing/model-selection-is-capacity-planning</link>
      <guid isPermaLink="true">https://ypro.dev/writing/model-selection-is-capacity-planning</guid>
      <pubDate>Tue, 16 Jun 2026 12:00:00 GMT</pubDate>
      <description>Most teams pick a frontier model like a sports team and never revisit it — but model selection is a routing, capacity, and risk decision you already know how to make.</description>
    </item>
    <item>
      <title>The Agent Is the Easy Part. The Control Plane Is the Job.</title>
      <link>https://ypro.dev/writing/the-control-plane-is-the-job</link>
      <guid isPermaLink="true">https://ypro.dev/writing/the-control-plane-is-the-job</guid>
      <pubDate>Wed, 17 Jun 2026 12:00:00 GMT</pubDate>
      <description>Standing up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.</description>
    </item>
    <item>
      <title>Stop Trying to Patch Prompt Injection</title>
      <link>https://ypro.dev/writing/stop-trying-to-patch-prompt-injection</link>
      <guid isPermaLink="true">https://ypro.dev/writing/stop-trying-to-patch-prompt-injection</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <description>Prompt injection isn't a bug a vendor will patch — it's a property of how models read context, so design systems that stay safe even when the model is fully hijacked.</description>
    </item>
    <item>
      <title>Your Agents Already Outnumber Your People. Nobody Is Governing Their Credentials.</title>
      <link>https://ypro.dev/writing/governing-non-human-identity</link>
      <guid isPermaLink="true">https://ypro.dev/writing/governing-non-human-identity</guid>
      <pubDate>Sat, 20 Jun 2026 12:00:00 GMT</pubDate>
      <description>Your agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.</description>
    </item>
    <item>
      <title>Your AI Bill Is the New Cloud Bill, and Nobody Is Watching the Meter</title>
      <link>https://ypro.dev/writing/your-ai-bill-is-the-new-cloud-bill</link>
      <guid isPermaLink="true">https://ypro.dev/writing/your-ai-bill-is-the-new-cloud-bill</guid>
      <pubDate>Sun, 21 Jun 2026 12:00:00 GMT</pubDate>
      <description>We spent a decade learning cloud FinOps and are repeating every mistake with LLM spend — here's the operating model that meters, routes, and caps it.</description>
    </item>
    <item>
      <title>Design Your AI Inference Like the Model Could Vanish Tomorrow, Because One Just Did</title>
      <link>https://ypro.dev/writing/design-ai-inference-for-disappearance</link>
      <guid isPermaLink="true">https://ypro.dev/writing/design-ai-inference-for-disappearance</guid>
      <pubDate>Tue, 23 Jun 2026 12:00:00 GMT</pubDate>
      <description>A frontier model went dark three days after launch; here's how I make AI inference survivable on AWS when the provider is a dependency you don't control.</description>
    </item>
    <item>
      <title>The 2026 AI Regulatory Map That Fits on One Page</title>
      <link>https://ypro.dev/writing/the-2026-ai-regulatory-map</link>
      <guid isPermaLink="true">https://ypro.dev/writing/the-2026-ai-regulatory-map</guid>
      <pubDate>Thu, 25 Jun 2026 12:00:00 GMT</pubDate>
      <description>Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part that fines you 3% of global revenue turns on in August. The four 2026 rules with teeth, on one page.</description>
    </item>
    <item>
      <title>Bake the Audit Evidence Into Your AI Pipeline Before the Examiner Asks</title>
      <link>https://ypro.dev/writing/audit-defensible-ai-pipeline</link>
      <guid isPermaLink="true">https://ypro.dev/writing/audit-defensible-ai-pipeline</guid>
      <pubDate>Sat, 27 Jun 2026 12:00:00 GMT</pubDate>
      <description>Audit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its normal operation emits evidence as exhaust.</description>
    </item>
    <item>
      <title>The Eight-Domain Azure Security Review for Regulated Environments</title>
      <link>https://ypro.dev/writing/azure-security-review-eight-domains</link>
      <guid isPermaLink="true">https://ypro.dev/writing/azure-security-review-eight-domains</guid>
      <pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate>
      <description>An automated tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in the order an audit walks them, and the evidence each one has to produce.</description>
    </item>
    <item>
      <title>Cloud FinOps for the Mid-Market: Where 25–40% of Spend Actually Hides</title>
      <link>https://ypro.dev/writing/cloud-finops-recovering-cloud-spend</link>
      <guid isPermaLink="true">https://ypro.dev/writing/cloud-finops-recovering-cloud-spend</guid>
      <pubDate>Tue, 15 Jul 2025 12:00:00 GMT</pubDate>
      <description>The press-release version of cloud savings cancels workloads and books compliance debt. The version that lasts is commitment management and SaaS rationalization.</description>
    </item>
    <item>
      <title>Board Reporting That Drives Decisions, Not Status Updates</title>
      <link>https://ypro.dev/writing/board-reporting-decisions-not-status</link>
      <guid isPermaLink="true">https://ypro.dev/writing/board-reporting-decisions-not-status</guid>
      <pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
      <description>The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.</description>
    </item>
    <item>
      <title>The First 100 Days: A Post-Close Cyber Integration Playbook</title>
      <link>https://ypro.dev/writing/100-day-post-close-cyber-integration-playbook</link>
      <guid isPermaLink="true">https://ypro.dev/writing/100-day-post-close-cyber-integration-playbook</guid>
      <pubDate>Tue, 05 Aug 2025 12:00:00 GMT</pubDate>
      <description>The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.</description>
    </item>
    <item>
      <title>Capital Allocation Governance: The Framework Companies Build Too Late</title>
      <link>https://ypro.dev/writing/capital-allocation-governance-board-framework</link>
      <guid isPermaLink="true">https://ypro.dev/writing/capital-allocation-governance-board-framework</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <description>Mid-market capital allocation is rarely a strategy — it's individual capex, M&amp;A, and debt decisions made in isolation. The governance framework that makes it programmatic.</description>
    </item>
  </channel>
</rss>