Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
Russia's 187-FZ: critical infrastructure security as a separate agenda
What the new critical information infrastructure law means for companies in regulated industries, and why this is not just another compliance exercise.
Software import substitution in Russia: what it actually means for IT leaders
A clear-eyed look at the Russian domestic software registry and what it really changes in procurement and enterprise architecture.
NotPetya: the lesson that a cyberattack can become pure operational loss
What the NotPetya attack reveals about the nature of modern cyber incidents and why this is not just an IT problem but a risk to a company's ability to operate.
The Transformer architecture: a new universal foundation for sequence processing
What the arrival of the Transformer architecture means for companies thinking about applying language models in their processes.
Real-time data: when the business actually needs it, and when it is over-engineered
How to tell which business tasks genuinely need stream processing, and which ones work perfectly well with regular batch updates.
WannaCry: a lesson for any company with an aging estate and weak recovery
What the WannaCry attack reveals about the real state of patch management and recovery readiness in most organisations.
Cobots in manufacturing: economics before automation
How collaborative robots change the calculation for small and mid-sized manufacturers, and why the return-on-investment question matters more than the technology question.
Vendor dependency: calculate the exit cost before you sign
Why the cost of switching an IT vendor needs to be assessed upfront, and how it affects platform choice and contract terms.
The gap between an ML experiment and a production system
Why machine learning in a notebook and machine learning in a running product are different tasks with different requirements.
A data catalog: the discipline of knowing what you have
Why metadata management is not a technical project but an operational necessity for companies that work with data seriously.
Lift-and-shift: when moving to the cloud does not deliver what you expected
Why mechanically moving infrastructure to the cloud without changing architecture preserves old problems and adds new costs.
Forgotten accounts: the quiet debt in access management
Why access audits are not a one-off check but a continuous process, and how former employees and contractors stay as entry points into systems.