Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Field Notes

Writing

Searchable essays on AI governance, security, leadership, and platform engineering.

More posts

6/26/2026 7 min

Bake the Audit Evidence Into Your AI Pipeline Before the Examiner Asks

Audit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its normal operation emits evidence as exhaust.

AIAI ComplianceAuditNIST AI RMF
6/24/2026 7 min

The 2026 AI Regulatory Map That Fits on One Page

Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part that fines you 3% of global revenue turns on in August. The four 2026 rules with teeth, on one page.

AIAI GovernanceComplianceNIST AI RMF
6/22/2026 8 min

Design Your AI Inference Like the Model Could Vanish Tomorrow, Because One Just Did

A frontier model went dark three days after launch; here's how I make AI inference survivable on AWS when the provider is a dependency you don't control.

AIAWSResilienceAI Infrastructure
6/20/2026 7 min

Your AI Bill Is the New Cloud Bill, and Nobody Is Watching the Meter

We spent a decade learning cloud FinOps and are repeating every mistake with LLM spend — here's the operating model that meters, routes, and caps it.

AIFinOpsCloud CostLLMOps
6/19/2026 7 min

Your Agents Already Outnumber Your People. Nobody Is Governing Their Credentials.

Your agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.

AINon-Human IdentityIAMCloud Security
6/17/2026 7 min

Stop Trying to Patch Prompt Injection

Prompt injection isn't a bug a vendor will patch — it's a property of how models read context, so design systems that stay safe even when the model is fully hijacked.

AIAI SecurityPrompt InjectionAppSec
6/16/2026 8 min

The Agent Is the Easy Part. The Control Plane Is the Job.

Standing up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.

AIAI AgentsSecurityPlatform Engineering
6/15/2026 7 min

Pick the Model Like You Size a Cluster, Not Like You Pick a Sports Team

Most teams pick a frontier model like a sports team and never revisit it — but model selection is a routing, capacity, and risk decision you already know how to make.

AIModel SelectionFinOpsInfrastructure
5/3/2026 6 min

The Eight-Domain Azure Security Review for Regulated Environments

An automated tool scores your Azure posture; an assessor walks your architecture. The eight domains I review, in the order an audit walks them, and the evidence each one has to produce.

Cloud SecurityAzureAuditCompliance
4/17/2026 4 min

What AI Actually Changes for Attackers (and What It Doesn't)

Cutting through the threat inflation: what genuinely shifts for attackers, what doesn't, and where to harden.

AIThreat IntelligencePhishingDefense
3/29/2026 3 min

The Audit Passed in March. Is It Still True?

Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits.

ComplianceGRCAuditFintech
3/11/2026 3 min

Automate the Boring, Not the Judgment

A framework for what security work to hand to machines, and the line you should never let automation cross.

Security OperationsAutomationAITeam Building
2/19/2026 3 min

How to Report Risk to People Who Don't Speak Security

Translating security for boards and investors — the three questions leadership actually asks, and how to answer them.

LeadershipRisk ManagementCommunicationBoard Reporting
1/27/2026 4 min

Security and DevOps Under One Roof: Why I Stopped Apologizing for It

The case for the dual mandate, and why org-chart distance doesn't create security.

DevOpsSecurityLeadershipOrg Design
1/14/2026 6 min

Capital Allocation Governance: The Framework Companies Build Too Late

Mid-market capital allocation is rarely a strategy — it's individual capex, M&A, and debt decisions made in isolation. The governance framework that makes it programmatic.

LeadershipGovernanceBoard ReportingRisk Management
8/25/2025 5 min

Board Reporting That Drives Decisions, Not Status Updates

The fifty-page board pre-read is the artifact most responsible for meetings that produce no decisions. Three sections fix it.

LeadershipBoard ReportingGovernanceCommunication
8/4/2025 7 min

The First 100 Days: A Post-Close Cyber Integration Playbook

The post-close decade is decided in the first 100 days. The eight cyber controls to ship by day 30, and the identity-sprawl audit every exit diligence will run.

SecurityM&ACloud SecurityLeadership
7/14/2025 6 min

Cloud FinOps for the Mid-Market: Where 25–40% of Spend Actually Hides

The press-release version of cloud savings cancels workloads and books compliance debt. The version that lasts is commitment management and SaaS rationalization.

FinOpsAWSAzureCloud Cost