Blog
Field notes on AI governance, written by a practitioner.
Long-form writing for risk, security, and board readers. Framework-anchored, regulator-literate, and informed by what actually happens in mid-market deployments.
Platform engineering · Risk
Policy-as-code as the control plane your auditors will actually read
Half the controls in a typical APRA submission are statements about what should happen. The other half could be expressed as policy code that runs in the pipeline and produces the evidence automatically. The gap between the two is most of the audit conversation.
ISO/IEC 42001
ISO 42001 readiness for mid-market organisations
What an ISO/IEC 42001 management system actually requires, and what it does not, for organisations under 500 staff. A pragmatic readiness path that does not require a dedicated AI governance team.
Zero trust
Zero trust without vendor capture
Most zero-trust programs we review are vendor roadmaps in disguise: a sequence of product purchases dressed up as architecture. The actual zero-trust shift is a procedural one, and it doesn't need a million-dollar identity overhaul to start.
Microsoft 365
Identity-first security for hybrid Microsoft 365 environments
If you run M365 with on-prem AD synchronised via Entra Connect, your security perimeter is the identity. Most mid-market environments have an Entra tenant configured in 2018 that hasn't been seriously revisited since. Here's the catch-up.
Cryptography
Post-quantum cryptography: a planning timeline for mid-market
NIST published the first post-quantum encryption standards in August 2024. The migration is real, but the urgency depends on what you're protecting and how long it has to stay protected. A pragmatic planning timeline for organisations that aren't a national security agency.
Regulatory horizon
The EU AI Act has reach. Australian firms should map exposure now.
The Act's territorial scope is broader than most Australian general counsel offices have appreciated. Two questions decide whether your AI deployment is in scope, and the documentation burden if it is, is non-trivial.
Stay informed
Get new posts by email.
One email a fortnight. Long-form content only, no promotional sequences. Unsubscribe at any time.
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.