Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
Managing internal APIs as teams scale
When a five-person team grows to fifty, informal API agreements stop working. What to put in place before it starts to hurt.
How to evaluate the return on AI investments: questions before the decision
ROI of AI projects is measured differently than ROI of traditional automation. I break down the right questions to ask before money is spent.
The CrowdStrike outage lesson: when protection becomes a single point of failure
The CrowdStrike update incident in July 2024 halted operations at thousands of companies worldwide. What it reveals about resilience architecture.
dbt: why this is a question of team discipline, not tool selection
dbt has become a standard for data transformation. But it only creates value when a team changes how it works with data logic - not just by installing it.
Long context in LLMs: what changes for architects and decision-makers
Models with hundred-thousand-token context windows look like a solution to many problems. I break down what this actually changes in practice - and where the traps are.
Physical automation: the gap between pilot and production
Why robotic pilots look convincing but scaling hits a wall - and how to think about this before making an investment decision.
Zero trust: what it means in practice for a mid-size company
Zero trust has become a buzzword. Behind it is a genuinely useful access model - but getting there requires specific decisions, not just a policy statement.
AI assistants and identity: the new attack surface
When corporate AI assistants gain access to email, documents, and systems, a new class of threats emerges that managers need to understand.
The coding agent and the new assembly point of development
GitHub Copilot is becoming an agent that can execute development tasks autonomously. What this changes for companies that commission or run software development.
Context windows and knowledge management in a company
How growing language model capabilities affect how companies can organise access to corporate knowledge.
IT budget without transparency: why the numbers diverge from reality
How companies lose control of IT spending, and what it takes for the budget to reflect what is actually happening.
SaaS supply chain attacks: lessons for managers
Incidents from early 2025 show that a company's security perimeter now runs through its SaaS providers. What this means in practice.