AI & AutomationInfrastructure & Cloud
For a year Copilot was something end-users asked me to turn on. In 2026 it quietly became something I have to administer — with an identity, a place in the org chart, and access to everything the person running it can reach. Here's what that means for the people who keep the estate running.
Jul 11, 20266 min read
Project & Delivery
I've run IT projects in Kuwait, Malaysia and India — a telecom cell-expansion here, a national metering program there, a holding-company migration somewhere in between. The certifications gave me the vocabulary. The border crossings taught me everything the vocabulary leaves out.
Jul 10, 20266 min read
AI & AutomationSecurity & Audit
Attackers got an AI. So did the defenders. Microsoft Security Copilot triages phishing hundreds of times faster than a human analyst — which is genuinely useful and quietly dangerous, in ways worth being precise about. Notes from the AI-vs-AI front line.
Jul 9, 20265 min read
CertificationsProject & Delivery
People see the alphabet after my name — PMP, CISM, TOGAF, CCNP, CISA, CEH — and assume I collect certificates. The truth is more useful: each one marked the moment a new layer of the technology world stopped being someone else's problem. Here's the map, honestly drawn.
Jul 8, 20265 min read
AI & AutomationSecurity & Audit
On 2 August, the EU AI Act's obligations for high-risk systems become enforceable, with penalties that reach into the tens of millions. Most organisations aren't ready, and most already have more AI in the building than they think. Here's how I'd govern it, from the auditor's chair.
Jul 7, 20265 min read
AI & AutomationProject & Delivery
The agentic project-management pitch is seductive: AI spots the slipping dependency, drafts the update, chases the action item. Having actually used it across real delivery, here's my honest split — what it takes off your plate, what it quietly can't do, and the skill that decides whether it helps you or misleads you.
Jul 5, 20265 min read
Project & Delivery
I got the plan-driven certifications first and the agile ones second, which is backwards from how the internet tells you to do it. It turned out to be the right order for the organisations I actually work in — conservative, governed, allergic to the word "sprint". This is how I make iteration land anyway.
Jul 2, 20266 min read
CertificationsProject & Delivery
I hold PMP, PRINCE2, PMI-ACP and CSM — so I get asked weekly which one to pursue. The honest answer is a decision tree, not a favourite. Here it is, with the trade-offs the training providers won't lead with.
Jun 29, 20263 min read
Infrastructure & CloudArchitecture
Most IT jobs are archaeology — you inherit someone else's decisions and spend years excavating them. Occasionally you get a blank sheet: a new venue, no legacy, design it right. This is how I built one on Azure, and the order of operations I'd defend to anyone.
Jun 24, 20266 min read
Infrastructure & CloudSecurity & Audit
People assume Microsoft 365 arrives secure. It arrives functional, which is not the same thing. Here is the exact baseline I stand up before I let a tenant carry real work — the fundamentals that stop the incidents I actually see.
Jun 18, 20266 min read
CertificationsSecurity & Audit
Hold one ISACA certification and you have a specialism. Hold all three and something better happens: you can walk a finding from the server room to the boardroom without it changing shape on the way. Here's how the triangle fits together.
Jun 15, 20263 min read
Security & AuditProject & Delivery
I learned to break into systems before I learned to audit them. Reversing that instinct — from "how would I attack this?" to "could I prove this control works to a sceptic?" — did more for how I actually run IT than any tool ever did. Here's the shift, and why it matters more in 2026 than it did when I sat the exam.
Jun 10, 20266 min read
Infrastructure & CloudArchitecture
A younger engineer asked me last month whether CCNP is a waste of time now that networking is "just SASE in the cloud". It's a fair question with a longer answer than he wanted. The fundamentals didn't die. They moved — and knowing where they moved is exactly what separates an operator from a button-pusher.
Jun 5, 20266 min read
CertificationsSecurity & Audit
CEH gets dismissed by pentesters and over-sold by training ads — both miss its actual job. Paired with CHFI, it teaches the two halves of a defender's imagination: how systems get broken into, and how the truth gets reconstructed afterwards.
Jun 1, 20263 min read
CertificationsArchitecture
Every few years someone declares enterprise architecture dead — usually while their organisation buys its third overlapping platform of the quarter. I'm TOGAF-certified, I've seen the framework abused, and I still think its core discipline has never been more necessary than right now.
May 18, 20263 min read
Security & Audit
Passwords are the only technology we all agree is broken yet all keep using. Passkeys are the first replacement with a real chance — because they're easier than what they replace, not just safer. Here's how they work and how to ship them.
May 11, 20263 min read
CertificationsInfrastructure & Cloud
Say 'change advisory board' near a DevOps team and watch the eye-rolls. Say 'who owns this service?' during a sev-1 and watch everyone reach for ITIL vocabulary without knowing it. The framework's ideas outlived its bureaucracy — here's what to keep.
May 4, 20263 min read
Field NotesSecurity & Audit
Ten years of watching ransomware go from a nuisance to an existential business risk — WannaCry, NotPetya, Colonial Pipeline, the leak-site era — and what each turning point taught the people who actually defend estates.
Apr 20, 20264 min read
Field NotesSecurity & Audit
Equifax, SolarWinds, Log4Shell, MOVEit — the breaches that changed how every IT leader has to think about risk. How the threat moved from your own walls to your suppliers' walls, from an auditor's chair.
Apr 6, 20264 min read
Field NotesInfrastructure & Cloud
A decade of running the Microsoft stack — on-prem Exchange and Active Directory, the Office 365 migration, the certification earthquake of 2018–2021, identity as the new perimeter, and now Copilot. What churned, and what compounded.
Mar 16, 20263 min read
Field NotesProject & Delivery
Ten years of delivery — the methodology wars, the scaling experiments, the remote-work shock of 2020, PMI's own pivot to agile and hybrid, and ITIL 4. How the industry stopped fighting about method and settled on hybrid.
Feb 24, 20263 min read
Field NotesCertifications
A decade rewrote the certification landscape — Microsoft's role-based pivot and the MCSE retirement, Cisco's 2020 consolidation, the 2021 PMP overhaul, ITIL 4, and the rise of verifiable digital badges. What it means for building a stack now.
Feb 9, 20263 min read
Field NotesInfrastructure & Cloud
Ten years that turned networking inside out — MPLS and on-prem firewalls giving way to SD-WAN, the cloud dissolving the perimeter, and zero trust and SASE becoming the model. What changed, and why the fundamentals only got more valuable.
Jan 26, 20263 min read