Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
Software supply chain attacks: when the vulnerability arrives with an update
An attack delivered through a trusted software vendor is one of the hardest threat vectors to defend against. I look at how it works and what businesses can actually do.
IT modernisation: why big-bang replacement rarely works
Large projects to replace IT systems often fail or exceed their budgets by multiples. I explain why an incremental approach works better and how to apply it.
Data contracts: how teams agree on quality
When multiple teams share data, conflicts of expectation are inevitable. Data contracts are a practical tool for making those expectations explicit.
OpenAI plugins: what the announcement actually means for builders
OpenAI opened plugin access to developers this week. Here is a calm reading of what the architecture implies - and what questions to ask before building on it.
Prompt engineering: the patterns that actually matter in practice
A grounded overview of the prompt techniques that produce reliable results, and the ones that sound sophisticated but do not hold up in production.
GPT-4 and a new conversation about quality, multimodality and the cost of errors
The release of GPT-4 changes not only what language models can do but the conversation about when AI is acceptable in production systems. I look at three key shifts.
RAG: how retrieval-augmented generation actually works
Before building a chatbot over your own documents, it helps to understand what RAG does, what it does not do, and where the failure points are.
LastPass and the lesson in secrets management: what happened and what it means
The 2022 LastPass breach became one of the most discussed incidents in credential management. I look at what happened and what conclusions matter for business.
Dependency map: what you need to know before any migration
System migrations fail not because of technical complexity but because of hidden dependencies. I explain how to build a dependency map and why it is work that must happen before the project starts.
NIST AI RMF 1.0: trustworthy AI gets a practical framework
In January 2023 NIST published the first version of its AI Risk Management Framework. I look at what it means for companies already using or planning to adopt AI.
ChatGPT in the boardroom: the questions founders now ask
The wave of interest in ChatGPT is bringing specific AI questions into boardrooms. I break down what those questions really mean and where to start.
Import substitution, open source, and architectural sovereignty
The departure of Western vendors placed companies in front of a real architectural choice. A breakdown of how to think about it systematically rather than reactively.