Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
GitHub Copilot: what changes for development teams and what a manager should think about
GitHub Copilot launched publicly. A look at what this changes for engineering teams and what questions managers should be asking.
Cloud costs in 2022: why the bill grew without new projects
How currency swings and provider pricing changes shifted the economics of cloud for companies in 2022.
RPA: where process automation works and where it does not
A clear-eyed look at RPA - which tasks are genuinely suited to robotic automation, and where expectations diverge from reality.
The Okta breach: what it means when an identity provider is compromised
In March 2022 Okta confirmed a breach. A look at the lesson a director should take from this, not just a security specialist.
Data contracts: how teams agree on integration
Why most data integration problems between teams are problems of agreements, not technology.
DALL-E 2 and the new visual productivity
OpenAI unveiled DALL-E 2. A look at what changes for business - not for artists, but for companies that work with visual content every day.
Vendor exit strategy: how to think about software dependencies
Why companies need an exit plan for vendor dependencies, and how to start building one before it becomes urgent.
IT system resilience when conditions shift fast
How a manager should think about IT infrastructure resilience when the external environment changes quickly and unpredictably.
Data mesh is about ownership, not about the platform
Breaking down the data mesh concept without the hype - why it is an organisational model first and a technical stack second.
Log4Shell: the management lessons from the incident
Breaking down the Log4Shell vulnerability as a management lesson - about hidden dependencies, response speed, and invisible risk.
GPT-3 in the API: what a founder should do with it
OpenAI opened GPT-3 access through its API. A clear-headed look at what changes for business and where to slow down.
Log4Shell: if you do not know your dependencies, you do not know your attack surface
The Log4Shell vulnerability showed that most companies have no idea which libraries are running inside their systems.