Insights

Current thinking from security leadership and delivery.

Practical analysis on the operating decisions behind cyber resilience, AI governance, identity, cloud and executive assurance.

Native insights

Latest insights

Current themes

The issues I am focused on

AI governance and secure adoption

Ownership, data boundaries, access controls, human approval and auditable decisions.

Resilience and recovery confidence

Testing whether critical services can recover and whether executives can make decisions under pressure.

Identity and cloud control

Pragmatic guardrails that reduce material attack paths without slowing the business.

Modern security operating models

Clear ownership, specialist partners, accountable delivery and capability that scales.

Board-useful cyber reporting

Options, trade-offs, ownership and evidence designed to support executive decisions.

External perspective

Posts and talks elsewhere

Infosecurity Europe: defending the inbox in the age of intelligent threats

What effective defence looks like when attackers automate and organisations still need measurable controls.

AI in cyber: friend or foe?

A practical framing for AI risk, controls, governance and secure adoption.