Insights
Observations from the field and perspectives on where technology is going.
My take on leadership, strategy, and the people side of technology, alongside perspectives on industry trends, emerging technology, risk, and governance. Different topics, grounded in the same belief: understand the people, the organization, and the outcome before deciding what technology should do.
Subscribe via RSS. One feed covers everything below.
When IT Becomes the Team That Always Says “No”
A technology function that reflexively says no gets routed around. What “yes, and” looks like in practice; and why knowing when to say no still matters.
An AI acceptable use policy is a trust document, not a ban list
A ban-list AI policy doesn't stop shadow AI, it hides it. What a usable acceptable use policy needs, and why access should expand, not just restrict.
Outcomes, not deliverables: why individual contributors stop caring
Teams that manage only to deliverables can hit every deadline and still fail. How to write outcomes into the work so contributors know what it was for.
Your vendor questionnaire is not a control
Most third-party risk programs collect evidence that a vendor can answer questions, not evidence that the vendor is safe. Here is what to measure instead.