Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Index

Table of Contents

A complete index of 21 long-form essays — titles, dates, reading time, and short summaries.

2026

  1. 01

    Bake the Audit Evidence Into Your AI Pipeline Before the Examiner Asks

    Jun 26, 2026 7 min 1,335 words

    Audit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its normal operation emits evidence as exhaust.

  2. 02

    The 2026 AI Regulatory Map That Fits on One Page

    Jun 24, 2026 7 min 1,236 words

    Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part that fines you 3% of global revenue turns on in August. The four 2026 rules with teeth, on one page.

  3. 03

    Design Your AI Inference Like the Model Could Vanish Tomorrow, Because One Just Did

    Jun 22, 2026 8 min 1,316 words

    A frontier model went dark three days after launch; here's how I make AI inference survivable on AWS when the provider is a dependency you don't control.

  4. 04

    Your AI Bill Is the New Cloud Bill, and Nobody Is Watching the Meter

    Jun 20, 2026 7 min 1,335 words

    We spent a decade learning cloud FinOps and are repeating every mistake with LLM spend — here's the operating model that meters, routes, and caps it.

  5. 05

    Your Agents Already Outnumber Your People. Nobody Is Governing Their Credentials.

    Jun 19, 2026 7 min 1,238 words

    Your agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.

  6. 06

    Stop Trying to Patch Prompt Injection

    Jun 17, 2026 7 min 1,291 words

    Prompt injection isn't a bug a vendor will patch — it's a property of how models read context, so design systems that stay safe even when the model is fully hijacked.

  7. 07

    The Agent Is the Easy Part. The Control Plane Is the Job.

    Jun 16, 2026 8 min 1,438 words

    Standing up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.

  8. 08

    Pick the Model Like You Size a Cluster, Not Like You Pick a Sports Team

    Jun 15, 2026 7 min 1,376 words

    Most teams pick a frontier model like a sports team and never revisit it — but model selection is a routing, capacity, and risk decision you already know how to make.

  9. 09

    Your Security Program Is a Sales Asset. Start Treating It Like One.

    Jun 9, 2026 4 min 366 words

    Why provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.

  10. 10

    The Boundary Layer Is the Actual AI Control

    May 21, 2026 5 min 665 words

    Every AI governance framework describes the same controls. The one that actually matters is a single design decision: does this output get acted on, or interpreted first?

  11. 11

    AWS Cost Levers That Actually Moved the Needle

    May 5, 2026 6 min 679 words

    Cutting ~35% off a multi-region AWS footprint with no capability loss — the levers in the order they paid back, best first.

  12. 12

    The Eight-Domain Azure Security Review for Regulated Environments

    May 3, 2026 6 min 814 words

    An automated tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in the order an audit walks them, and the evidence each one has to produce.

  13. 13

    What AI Actually Changes for Attackers (and What It Doesn't)

    Apr 17, 2026 4 min 270 words

    Cutting through the threat inflation: what genuinely shifts for attackers, what doesn't, and where to harden.

  14. 14

    The Audit Passed in March. Is It Still True?

    Mar 29, 2026 3 min 254 words

    Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits.

  15. 15

    Automate the Boring, Not the Judgment

    Mar 11, 2026 3 min 269 words

    A framework for what security work to hand to machines, and the line you should never let automation cross.

  16. 16

    How to Report Risk to People Who Don't Speak Security

    Feb 19, 2026 3 min 263 words

    Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.

  17. 17

    Security and DevOps Under One Roof: Why I Stopped Apologizing for It

    Jan 27, 2026 4 min 279 words

    The case for the dual mandate, and why org-chart distance doesn't create security.

  18. 18

    Capital Allocation Governance: The Framework Companies Build Too Late

    Jan 14, 2026 6 min 718 words

    Mid-market capital allocation is rarely a strategy — it's individual capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.

2025

  1. 01

    Board Reporting That Drives Decisions, Not Status Updates

    Aug 25, 2025 5 min 636 words

    The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.

  2. 02

    The First 100 Days: A Post-Close Cyber Integration Playbook

    Aug 4, 2025 7 min 893 words

    The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.

  3. 03

    Cloud FinOps for the Mid-Market: Where 25–40% of Spend Actually Hides

    Jul 14, 2025 6 min 824 words

    The press-release version of cloud savings cancels workloads and books compliance debt. The version that lasts is commitment management and SaaS rationalization.