Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
GPT-4 and a new conversation about quality, multimodality and the cost of errors
The release of GPT-4 changes not only what language models can do but the conversation about when AI is acceptable in production systems. I look at three key shifts.
RAG: how retrieval-augmented generation actually works
Before building a chatbot over your own documents, it helps to understand what RAG does, what it does not do, and where the failure points are.
LastPass and the lesson in secrets management: what happened and what it means
The 2022 LastPass breach became one of the most discussed incidents in credential management. I look at what happened and what conclusions matter for business.
Dependency map: what you need to know before any migration
System migrations fail not because of technical complexity but because of hidden dependencies. I explain how to build a dependency map and why it is work that must happen before the project starts.
NIST AI RMF 1.0: trustworthy AI gets a practical framework
In January 2023 NIST published the first version of its AI Risk Management Framework. I look at what it means for companies already using or planning to adopt AI.
ChatGPT in the boardroom: the questions founders now ask
The wave of interest in ChatGPT is bringing specific AI questions into boardrooms. I break down what those questions really mean and where to start.
Import substitution, open source, and architectural sovereignty
The departure of Western vendors placed companies in front of a real architectural choice. A breakdown of how to think about it systematically rather than reactively.
Year-end IT architecture review: questions for planning 2023
A set of concrete questions that help assess the current state of a company's IT architecture and set the right priorities for the coming year.
ChatGPT: the consumer interface to AI goes mass market
What the launch of ChatGPT means for companies and managers - not technologically, but in terms of how expectations around automation will change.
Analytic database versus operational database: when to separate them
Why one database cannot serve both transactions and analytics well - and how to recognise when the time to separate them has arrived.
Identity after the perimeter: what zero trust is and why founders need to understand it
The corporate perimeter has ceased to exist. A breakdown of what this means for security and what practical steps follow from this logic.
SSO and SaaS sprawl: why identity architecture matters before the breach
How the accumulation of SaaS tools creates an identity problem that security tools alone cannot fix - and what to do about it before something goes wrong.