mksim.pro
Blog

Notes on data, AI, IT and security

No marketing fog. The way I think about real problems with founders and managers.

Security

Software supply chain attacks: when the vulnerability arrives with an update

An attack delivered through a trusted software vendor is one of the hardest threat vectors to defend against. I look at how it works and what businesses can actually do.

Read
IT

IT modernisation: why big-bang replacement rarely works

Large projects to replace IT systems often fail or exceed their budgets by multiples. I explain why an incremental approach works better and how to apply it.

Read
Data

Data contracts: how teams agree on quality

When multiple teams share data, conflicts of expectation are inevitable. Data contracts are a practical tool for making those expectations explicit.

Read
AI

OpenAI plugins: what the announcement actually means for builders

OpenAI opened plugin access to developers this week. Here is a calm reading of what the architecture implies - and what questions to ask before building on it.

Read
AI

Prompt engineering: the patterns that actually matter in practice

A grounded overview of the prompt techniques that produce reliable results, and the ones that sound sophisticated but do not hold up in production.

Read
AI

GPT-4 and a new conversation about quality, multimodality and the cost of errors

The release of GPT-4 changes not only what language models can do but the conversation about when AI is acceptable in production systems. I look at three key shifts.

Read
AI

RAG: how retrieval-augmented generation actually works

Before building a chatbot over your own documents, it helps to understand what RAG does, what it does not do, and where the failure points are.

Read
Security

LastPass and the lesson in secrets management: what happened and what it means

The 2022 LastPass breach became one of the most discussed incidents in credential management. I look at what happened and what conclusions matter for business.

Read
IT

Dependency map: what you need to know before any migration

System migrations fail not because of technical complexity but because of hidden dependencies. I explain how to build a dependency map and why it is work that must happen before the project starts.

Read
AI

NIST AI RMF 1.0: trustworthy AI gets a practical framework

In January 2023 NIST published the first version of its AI Risk Management Framework. I look at what it means for companies already using or planning to adopt AI.

Read
Data

ChatGPT in the boardroom: the questions founders now ask

The wave of interest in ChatGPT is bringing specific AI questions into boardrooms. I break down what those questions really mean and where to start.

Read
IT

Import substitution, open source, and architectural sovereignty

The departure of Western vendors placed companies in front of a real architectural choice. A breakdown of how to think about it systematically rather than reactively.

Read