Table of Contents
A complete index of 21 long-form essays — titles, dates, reading time, and short summaries.
2026
- 01
Bake the Audit Evidence Into Your AI Pipeline Before the Examiner Asks
Jun 26, 2026 7 min 1,335 wordsAudit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its normal operation emits evidence as exhaust.
- 02
The 2026 AI Regulatory Map That Fits on One Page
Jun 24, 2026 7 min 1,236 wordsEveryone read 'EU AI Act deferred to 2027' and exhaled — but the part that fines you 3% of global revenue turns on in August. The four 2026 rules with teeth, on one page.
- 03
Design Your AI Inference Like the Model Could Vanish Tomorrow, Because One Just Did
Jun 22, 2026 8 min 1,316 wordsA frontier model went dark three days after launch; here's how I make AI inference survivable on AWS when the provider is a dependency you don't control.
- 04
Your AI Bill Is the New Cloud Bill, and Nobody Is Watching the Meter
Jun 20, 2026 7 min 1,335 wordsWe spent a decade learning cloud FinOps and are repeating every mistake with LLM spend — here's the operating model that meters, routes, and caps it.
- 05
Your Agents Already Outnumber Your People. Nobody Is Governing Their Credentials.
Jun 19, 2026 7 min 1,238 wordsYour agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.
- 06
Stop Trying to Patch Prompt Injection
Jun 17, 2026 7 min 1,291 wordsPrompt injection isn't a bug a vendor will patch — it's a property of how models read context, so design systems that stay safe even when the model is fully hijacked.
- 07
The Agent Is the Easy Part. The Control Plane Is the Job.
Jun 16, 2026 8 min 1,438 wordsStanding up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.
- 08
Pick the Model Like You Size a Cluster, Not Like You Pick a Sports Team
Jun 15, 2026 7 min 1,376 wordsMost teams pick a frontier model like a sports team and never revisit it — but model selection is a routing, capacity, and risk decision you already know how to make.
- 09
Your Security Program Is a Sales Asset. Start Treating It Like One.
Jun 9, 2026 4 min 366 wordsWhy provable security closes deals in regulated industries — and why the next budget conversation should lead with revenue, not fear.
- 10
The Boundary Layer Is the Actual AI Control
May 21, 2026 5 min 665 wordsEvery AI governance framework describes the same controls. The one that actually matters is a single design decision: does this output get acted on, or interpreted first?
- 11
AWS Cost Levers That Actually Moved the Needle
May 5, 2026 6 min 679 wordsCutting ~35% off a multi-region AWS footprint with no capability loss — the levers in the order they paid back, best first.
- 12
The Eight-Domain Azure Security Review for Regulated Environments
May 3, 2026 6 min 814 wordsAn automated tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in the order an audit walks them, and the evidence each one has to produce.
- 13
What AI Actually Changes for Attackers (and What It Doesn't)
Apr 17, 2026 4 min 270 wordsCutting through the threat inflation: what genuinely shifts for attackers, what doesn't, and where to harden.
- 14
The Audit Passed in March. Is It Still True?
Mar 29, 2026 3 min 254 wordsPoint-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits.
- 15
Automate the Boring, Not the Judgment
Mar 11, 2026 3 min 269 wordsA framework for what security work to hand to machines, and the line you should never let automation cross.
- 16
How to Report Risk to People Who Don't Speak Security
Feb 19, 2026 3 min 263 wordsTranslating security for boards and investors — the three questions leadership actually asks, and how to answer them.
- 17
Security and DevOps Under One Roof: Why I Stopped Apologizing for It
Jan 27, 2026 4 min 279 wordsThe case for the dual mandate, and why org-chart distance doesn't create security.
- 18
Capital Allocation Governance: The Framework Companies Build Too Late
Jan 14, 2026 6 min 718 wordsMid-market capital allocation is rarely a strategy — it's individual capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.
2025
- 01
Board Reporting That Drives Decisions, Not Status Updates
Aug 25, 2025 5 min 636 wordsThe fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.
- 02
The First 100 Days: A Post-Close Cyber Integration Playbook
Aug 4, 2025 7 min 893 wordsThe post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.
- 03
Cloud FinOps for the Mid-Market: Where 25–40% of Spend Actually Hides
Jul 14, 2025 6 min 824 wordsThe press-release version of cloud savings cancels workloads and books compliance debt. The version that lasts is commitment management and SaaS rationalization.
