Briefing notes on AI, cloud security and architecture assurance.
Occasional, deliberately practical notes from the founding partner on the decisions that sit between cloud platforms, AI adoption, security governance and executive approval. Written when there is something worth saying.
The AI risk most boards miss is the cloud identity boundary
Board papers on AI risk talk about models and prompts. The incidents worth worrying about mostly start with a permission nobody reviewed, and the model is simply the first thing to walk through a hole that was already there.
Why GenAI pilots fail security approval
The pilot worked and the sponsor is delighted, then it reaches the security forum and stalls for a quarter. The sequencing was wrong, not the technology, and the fix costs weeks rather than months.
AI assurance is not a dashboard problem
Posture tools produce telemetry. What an auditor, customer or board asks for is a position someone is prepared to sign, and the two are confused often enough to cost organisations real renewals.