All articles

Practical, long-form writing on IT infrastructure, project delivery and cyber security.

AI & AutomationInfrastructure & Cloud

Microsoft Copilot Lands in IT: What Actually Changes for the People Who Run the Estate

For a year Copilot was something end-users asked me to turn on. In 2026 it quietly became something I have to administer — with an identity, a place in the org chart, and access to everything the person running it can reach. Here's what that means for the people who keep the estate running.

AI & AutomationSecurity & Audit

Security Copilot and the AI-vs-AI Front Line

Attackers got an AI. So did the defenders. Microsoft Security Copilot triages phishing hundreds of times faster than a human analyst — which is genuinely useful and quietly dangerous, in ways worth being precise about. Notes from the AI-vs-AI front line.

AI & AutomationSecurity & Audit

Governing AI Before It Governs You: An IT Auditor's Playbook

On 2 August, the EU AI Act's obligations for high-risk systems become enforceable, with penalties that reach into the tens of millions. Most organisations aren't ready, and most already have more AI in the building than they think. Here's how I'd govern it, from the auditor's chair.

AI & AutomationProject & Delivery

AI in Project Delivery: What the Copilot Hype Gets Right and Wrong

The agentic project-management pitch is seductive: AI spots the slipping dependency, drafts the update, chases the action item. Having actually used it across real delivery, here's my honest split — what it takes off your plate, what it quietly can't do, and the skill that decides whether it helps you or misleads you.

Project & Delivery

Agile After PMP: Making Iterative Delivery Land in a Waterfall-Shaped Organisation

I got the plan-driven certifications first and the agile ones second, which is backwards from how the internet tells you to do it. It turned out to be the right order for the organisations I actually work in — conservative, governed, allergic to the word "sprint". This is how I make iteration land anyway.

Infrastructure & CloudArchitecture

Building an Entertainment Centre's IT on Azure From a Blank Sheet

Most IT jobs are archaeology — you inherit someone else's decisions and spend years excavating them. Occasionally you get a blank sheet: a new venue, no legacy, design it right. This is how I built one on Azure, and the order of operations I'd defend to anyone.

Infrastructure & CloudSecurity & Audit

The Microsoft 365 Security Baseline I Stand Up on Day One

People assume Microsoft 365 arrives secure. It arrives functional, which is not the same thing. Here is the exact baseline I stand up before I let a tenant carry real work — the fundamentals that stop the incidents I actually see.

CertificationsSecurity & Audit

CISA, CISM, CRISC: Mapping the ISACA Triangle

Hold one ISACA certification and you have a specialism. Hold all three and something better happens: you can walk a finding from the server room to the boardroom without it changing shape on the way. Here's how the triangle fits together.

Security & AuditProject & Delivery

The Auditor in the Room: How CISA Changed the Way I Run My Own Estate

I learned to break into systems before I learned to audit them. Reversing that instinct — from "how would I attack this?" to "could I prove this control works to a sceptic?" — did more for how I actually run IT than any tool ever did. Here's the shift, and why it matters more in 2026 than it did when I sat the exam.

Infrastructure & CloudArchitecture

Does CCNP Still Matter When Everything's Moving to SASE?

A younger engineer asked me last month whether CCNP is a waste of time now that networking is "just SASE in the cloud". It's a fair question with a longer answer than he wanted. The fundamentals didn't die. They moved — and knowing where they moved is exactly what separates an operator from a button-pusher.

CertificationsSecurity & Audit

CEH & CHFI: Learning the Attacker's Mindset — Legally

CEH gets dismissed by pentesters and over-sold by training ads — both miss its actual job. Paired with CHFI, it teaches the two halves of a defender's imagination: how systems get broken into, and how the truth gets reconstructed afterwards.

CertificationsArchitecture

Does TOGAF Still Matter? Enterprise Architecture in the AI Era

Every few years someone declares enterprise architecture dead — usually while their organisation buys its third overlapping platform of the quarter. I'm TOGAF-certified, I've seen the framework abused, and I still think its core discipline has never been more necessary than right now.

Security & Audit

Passkeys: Life After Passwords

Passwords are the only technology we all agree is broken yet all keep using. Passkeys are the first replacement with a real chance — because they're easier than what they replace, not just safer. Here's how they work and how to ship them.

CertificationsInfrastructure & Cloud

ITIL in a DevOps World: Service Management That Doesn't Slow You Down

Say 'change advisory board' near a DevOps team and watch the eye-rolls. Say 'who owns this service?' during a sev-1 and watch everyone reach for ITIL vocabulary without knowing it. The framework's ideas outlived its bureaucracy — here's what to keep.

Field NotesSecurity & Audit

A Decade of Ransomware: From WannaCry to Triple Extortion

Ten years of watching ransomware go from a nuisance to an existential business risk — WannaCry, NotPetya, Colonial Pipeline, the leak-site era — and what each turning point taught the people who actually defend estates.

Field NotesSecurity & Audit

The Breaches That Rewrote the Rules: 2017–2026

Equifax, SolarWinds, Log4Shell, MOVEit — the breaches that changed how every IT leader has to think about risk. How the threat moved from your own walls to your suppliers' walls, from an auditor's chair.

Field NotesInfrastructure & Cloud

Ten Years on the Microsoft Stack: From On-Prem Exchange to Copilot

A decade of running the Microsoft stack — on-prem Exchange and Active Directory, the Office 365 migration, the certification earthquake of 2018–2021, identity as the new perimeter, and now Copilot. What churned, and what compounded.

Field NotesInfrastructure & Cloud

The Networking Decade: From MPLS and MCSE to SASE and Zero Trust

Ten years that turned networking inside out — MPLS and on-prem firewalls giving way to SD-WAN, the cloud dissolving the perimeter, and zero trust and SASE becoming the model. What changed, and why the fundamentals only got more valuable.