What's new
Everything that changed here, newest first: research, patents, portfolio works, books, and the site itself.
September 2026
NewResearch & IP
Do not publish a resilience formula yet
People often ask for one weighted score. Publishing it before the measures are validated would give an untested formula the look of certainty.
NewResearch & IP
Escalation paths decay quietly
Contacts leave, numbers change, portals replace phone trees, and contracts renew with different terms. An untested escalation path is an assumption with a date on it.
NewResearch & IP
Fluent output is not evidence
A generated security assessment reads better than a human one and is harder to doubt. Readability and correctness are unrelated properties.
NewResearch & IP
Generate the policy from the enforced rule
Where a platform enforces a setting, produce the written policy from that configuration. Then the rule and the document cannot drift apart.
NewResearch & IP
Governance runs short of time for judgment
When collecting and formatting evidence takes most GRC hours, little time remains for decisions. Automating the clerical work may give that time back.
NewResearch & IP
Keep evidence that can be reproduced
A screenshot is a claim about a moment. A stored query with provenance can be re-run by the reader, which changes what the evidence is worth.
NewResearch & IP
Let machines watch; keep consequential decisions with people
Machines can watch systems and prepare evidence. People remain responsible for decisions that cannot be reversed.
NewResearch & IP
Measure the time between each response step
Incident counts depend on how hard an organisation looks. Detection, containment, and recovery intervals can be generated on demand and compared over time.
NewPress
New book: Bare Metal Software
Bare Metal Software: AI can write more code, and that changes which layers of software you still need. Software stacks grew tall because human developers needed abstractions, frameworks and managed services to make hard work practical.
NewPress
New book: Chasing Native Alpha
Chasing Native Alpha: AI made building cheap, so what you choose to build now decides your advantage. When every competitor can reach the same models, coding agents and cloud infrastructure, producing more software is no longer a strategy.
NewPress
New book: The Code Takes Care of Itself
The Code Takes Care of Itself: AI gives every competitor the same tools, and the CTO's job is to build a team that wins with them. AI didn't make the job easier; it moved the bottleneck.
NewPress
New book: The CTO You Actually Need
The CTO You Actually Need: The CTO title covers very different jobs. A startup builder, an SME technology leader, a business-unit CTO, an enterprise strategist and a fractional adviser can all be excellent, but not for the same company at the same time.
NewResearch & IP
Phishing resistance belongs in the credential
Origin-bound, hardware-backed authentication removes a whole class of failure regardless of how convincing the message was. This is the clearest available example of design beating vigilance.
NewResearch & IP
Put the last demonstrated RTO beside the target
A recovery objective is a statement of intent written during planning. The useful number is the one produced by the last real restore, with the date attached.
NewResearch & IP
Requirements with no evidence source are more common than failed controls
When requirements are mapped to operational data sources, the largest category is usually requirements that no system can currently answer at all.
NewResearch & IP
The audit passed and the network was flat
Certification scope is negotiated. A clean report describes the environment that was examined against the controls that were selected, at the time of the examination.
NewResearch & IP
The restore worked and took four days
A restore can return all the data and still come too late. Time, sequence, and hidden dependencies often cause the loss.
NewResearch & IP
The tool was purchased. Was it tested?
Procurement produces a deployment date. Nothing in the ordinary purchase process produces evidence that the tool changes an attack outcome in this environment.
NewResearch & IP
Unknown is red
If nobody can show that a control works, score it as failing. Amber and blank let an untested control sit quietly beside a tested one.
NewResearch & IP
What a findings dashboard leaves out
Counting open findings measures the discovery process. It says nothing about detection speed, containment, or recovery, and it falls when scanning stops.
