Why Technology Governance & Security Sometimes Has to Say “No” And Why Unstructured Code Is Now a Business Risk
Technology Governance & Security teams aren’t the “department of no.” They’re the function protecting organisations from modern supply‑chain attacks, unstructured code, and ungoverned dependencies. Recent Python ecosystem compromises show why governance isn’t about slowing innovation — it’s about preventing exposure.
The EU AI Act Preparation Window Is Open. Here’s Exactly How to Use It.
The EU AI Act’s transition period isn’t a grace period — it’s a preparation window. The organisations that use it well will be ahead of the curve. The ones that don’t will be scrambling when enforcement arrives. Here’s what to do right now.
What Good AI Governance Actually Looks Like
Most organisations have one of two AI governance problems: they have no framework at all, or they have a policy document that nobody reads and nothing that embeds it in practice. Here’s what good actually looks like.
The EU AI Act Is Live. Most Boards Don’t Know What That Means for Them.
The EU AI Act isn’t coming — it’s here. And while most organisations are still treating it as a future concern, the compliance clock is already running. Here’s what boards need to understand right now.
CSO ThreatScape 2026: Why Cyber Resilience Is a Leadership Problem, Not a Technology Problem
Reflections from CSO ThreatScape 2026 in Manchester — on why the organisations winning the cyber resilience battle aren’t the ones with the best tools, but the ones with the clearest leadership.
Speaking at CSO ThreatScape Summit UK: What I’ll Be Bringing to the Conversation
I’m joining an exceptional panel of leaders at CSO ThreatScape Summit UK in Manchester on 19 March. Here’s what’s on my mind ahead of the day — and why the conversation around cyber resilience and secure culture has never mattered more.
The Human Attack Surface: Why AI-Powered Social Engineering Is the Biggest Cyber Threat of the Next Five Years
When AI can mine personal data at scale and craft perfectly personalised influence campaigns, the biggest vulnerability in any organisation isn’t its software — it’s its people. Here’s what cybersecurity leaders need to be thinking about.
Joining the CSO Security Summit London: Cyber Resilience Best Practices
I’m joining fellow security leaders at the CSO Security Summit in London to share cyber resilience best practices. Here’s why I think resilience — not just defence — is the right frame for where we are right now.