The Blog
Insights
Writing on technology leadership, cybersecurity, AI governance, and the realities of running technology at board level.
Blog
May 1, 2026
Why Technology Governance & Security Sometimes Has to Say “No” And Why Unstructured Code Is Now a Business Risk
Technology Governance & Security teams aren’t the “department of no.” They’re the function protecting organisations from modern supply‑chain attacks, unstructured code, and ungoverned dependencies. Recent Python ecosystem compromises…
Read more →
Blog
April 24, 2026
The EU AI Act Preparation Window Is Open. Here’s Exactly How to Use It.
The EU AI Act's transition period isn't a grace period — it's a preparation window. The organisations that use it well will be ahead of the curve. The…
Read more →
Blog
April 22, 2026
What Good AI Governance Actually Looks Like
Most organisations have one of two AI governance problems: they have no framework at all, or they have a policy document that nobody reads and nothing that embeds…
Read more →
Blog
April 17, 2026
The EU AI Act Is Live. Most Boards Don’t Know What That Means for Them.
The EU AI Act isn't coming — it's here. And while most organisations are still treating it as a future concern, the compliance clock is already running. Here's…
Read more →
Blog
March 27, 2026
CSO ThreatScape 2026: Why Cyber Resilience Is a Leadership Problem, Not a Technology Problem
Reflections from CSO ThreatScape 2026 in Manchester — on why the organisations winning the cyber resilience battle aren't the ones with the best tools, but the ones with…
Read more →
Blog
March 1, 2026
Speaking at CSO ThreatScape Summit UK: What I’ll Be Bringing to the Conversation
I'm joining an exceptional panel of leaders at CSO ThreatScape Summit UK in Manchester on 19 March. Here's what's on my mind ahead of the day — and…
Read more →
Blog
December 1, 2025
The Human Attack Surface: Why AI-Powered Social Engineering Is the Biggest Cyber Threat of the Next Five Years
When AI can mine personal data at scale and craft perfectly personalised influence campaigns, the biggest vulnerability in any organisation isn't its software — it's its people. Here's…
Read more →
Blog
October 31, 2025
Joining the CSO Security Summit London: Cyber Resilience Best Practices
I'm joining fellow security leaders at the CSO Security Summit in London to share cyber resilience best practices. Here's why I think resilience — not just defence —…
Read more →