What's new

Everything that changed here, newest first: research, patents, portfolio works, books, and the site itself.

September 2026

  • NewResearch & IP

    Deletion is the sharpest privacy test

    A verified end-to-end deletion exercises the data map, the vendor list, the backup policy, and the derived-data problem at once. Few organisations pass it on the first attempt.

    Read more

  • NewResearch & IP

    Design out the memory dependency

    For each control that depends on a person recalling guidance under pressure, look for a technical arrangement that makes the safe action the default or the only one.

    Read more

  • NewResearch & IP

    Do not publish a resilience formula yet

    People often ask for one weighted score. Publishing it before the measures are validated would give an untested formula the look of certainty.

    Read more

  • NewResearch & IP

    Escalation paths decay quietly

    Contacts leave, numbers change, portals replace phone trees, and contracts renew with different terms. An untested escalation path is an assumption with a date on it.

    Read more

  • NewResearch & IP

    Fluent output is not evidence

    A generated security assessment reads better than a human one and is harder to doubt. Readability and correctness are unrelated properties.

    Read more

  • NewResearch & IP

    Generate the policy from the enforced rule

    Where a platform enforces a setting, produce the written policy from that configuration. Then the rule and the document cannot drift apart.

    Read more

  • NewResearch & IP

    Governance runs short of time for judgment

    When collecting and formatting evidence takes most GRC hours, little time remains for decisions. Automating the clerical work may give that time back.

    Read more

  • NewResearch & IP

    Keep evidence that can be reproduced

    A screenshot is a claim about a moment. A stored query with provenance can be re-run by the reader, which changes what the evidence is worth.

    Read more

  • NewResearch & IP

    Let machines watch; keep consequential decisions with people

    Machines can watch systems and prepare evidence. People remain responsible for decisions that cannot be reversed.

    Read more

  • NewResearch & IP

    Measure the time between each response step

    Incident counts depend on how hard an organisation looks. Detection, containment, and recovery intervals can be generated on demand and compared over time.

    Read more

  • NewPress

    New book: Bare Metal Software

    Bare Metal Software: AI can write more code, and that changes which layers of software you still need. Software stacks grew tall because human developers needed abstractions, frameworks and managed services to make hard work practical.

    Read more

  • NewPress

    New book: Chasing Native Alpha

    Chasing Native Alpha: AI made building cheap, so what you choose to build now decides your advantage. When every competitor can reach the same models, coding agents and cloud infrastructure, producing more software is no longer a strategy.

    Read more

  • NewPress

    New book: The Code Takes Care of Itself

    The Code Takes Care of Itself: AI gives every competitor the same tools, and the CTO's job is to build a team that wins with them. AI didn't make the job easier; it moved the bottleneck.

    Read more

  • NewPress

    New book: The CTO You Actually Need

    The CTO You Actually Need: The CTO title covers very different jobs. A startup builder, an SME technology leader, a business-unit CTO, an enterprise strategist and a fractional adviser can all be excellent, but not for the same company at the same time.

    Read more

  • NewResearch & IP

    Phishing resistance belongs in the credential

    Origin-bound, hardware-backed authentication removes a whole class of failure regardless of how convincing the message was. This is the clearest available example of design beating vigilance.

    Read more

  • NewResearch & IP

    Put the last demonstrated RTO beside the target

    A recovery objective is a statement of intent written during planning. The useful number is the one produced by the last real restore, with the date attached.

    Read more

  • NewResearch & IP

    Requirements with no evidence source are more common than failed controls

    When requirements are mapped to operational data sources, the largest category is usually requirements that no system can currently answer at all.

    Read more

  • NewResearch & IP

    The audit passed and the network was flat

    Certification scope is negotiated. A clean report describes the environment that was examined against the controls that were selected, at the time of the examination.

    Read more

  • NewResearch & IP

    The restore worked and took four days

    A restore can return all the data and still come too late. Time, sequence, and hidden dependencies often cause the loss.

    Read more

  • NewResearch & IP

    The tool was purchased. Was it tested?

    Procurement produces a deployment date. Nothing in the ordinary purchase process produces evidence that the tool changes an attack outcome in this environment.

    Read more