Blog
Field notes on AI governance, written by a practitioner.
Long-form writing for risk, security, and board readers. Framework-anchored, regulator-literate, and informed by what actually happens in mid-market deployments.
Detection
Detection engineering for organisations without a 24/7 SOC
Most mid-market organisations don't have a 24/7 SOC and won't justify the cost of one for years. That's not a reason to give up on detection. It's a reason to be specific about what you actually need to detect, and how.
Incident response
Ransomware response, CPS 230, and the 24-hour decision
The technical incident response is the easier half. The harder half is the decision your executive will be asked to make at the 6-hour mark and again at the 24-hour mark, and whether your organisation has actually decided how to make it.
Email security
AI-assisted phishing: what's actually new
The volume of AI-assisted phishing has gone up; the success rate per attempt has not changed as much as the headlines suggest. The substantive change is the resource asymmetry, and what that means for your defensive program.
Privileged access
Just-in-time privileged access for mid-market
Standing administrative privilege is the largest avoidable risk in most mid-market environments. The fix is a procedural change supported by tooling you probably already own. The work is mostly the policy, not the technology.
Information security
Secrets sprawl is the boring breach pattern that keeps working
The interesting attack chains get the conference talks. The pattern that actually wrecks regulated firms is unrotated credentials in code, in CI variables, in vendor portals, and in places nobody owns. The cleanup is unglamorous, and the savings are large.
Third-party risk
Third-party risk after the supply-chain attack era
Most third-party risk programs in mid-market financial services are questionnaire factories. They produce paperwork; they do not produce risk reduction. After several years of supply-chain incidents, the realistic position has changed. Here's what actually works.
Stay informed
Get new posts by email.
One email a fortnight. Long-form content only, no promotional sequences. Unsubscribe at any time.
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.