Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
NIST Cybersecurity Framework 2.0: the framework gets broader and closer to business
What changed in the new version of NIST CSF and why the update matters not only to security teams but to executives who are responsible for risk management.
API-first architecture: the business case for owners who do not write code
Why API-first is not a technical preference but a business decision about how the company will integrate, scale, and switch vendors.
Data mesh or central warehouse: choosing without an ideology fight
A practical framework for choosing between a centralised data warehouse and a decentralised data mesh approach - without evangelism in either direction.
LLM context windows: what the limit means for business applications
Why the context window constraint in language models is not a technical footnote but an architectural decision that determines what can actually be built.
Humanoid robots in 2023: where the industry actually stands
A sober look at the state of humanoid robotics by the end of 2023: what is genuinely ready, what remains demonstration, and what to track.
Platform engineering after the DevOps wave: what changes for IT leadership
How the internal developer platform idea transforms the role of IT in a company and why this is a strategic question, not just an operational one.
Data contracts: the discipline that separates order from chaos
What data contracts are, why they matter for any team passing data between systems, and how to start without complex infrastructure.
AI in 2023: what actually changed and what is still open
A mid-November account of what the year delivered in practical terms - not a hype recap but an honest read of where things moved and where the gaps remain.
DevDay, long context, and the tooling shift toward LLM production systems
What OpenAI's DevDay announcements mean for companies thinking about moving from LLM pilots to working production systems.
The Okta breach: what happens when your identity provider is compromised
A look at the Okta incident in October 2023 and practical conclusions for companies that rely on centralised authentication.
Zero trust networking: a practical starting point for non-security teams
Zero trust is talked about constantly but implemented rarely. Here is a grounded explanation of what it means in practice and where a company with limited security resources should actually start.
LLM operational economics: how to model costs before you scale
Why token costs for language models need to be modelled in advance, and how to avoid an unexpected invoice when load grows.