Insight

Articles on security as a leadership responsibility, written for the people who make the decisions, not the ones who run the systems.

These are lasting professional articles, written to stay relevant. Dated news is under News.

Security is decided in the boardroom, not the server room

In most organisations, information security is still something handled by somebody else, somewhere further down the structure. Responsibility, meanwhile, has moved upwards: regulation and owners now expect the board and the executive team to account for risk, priorities and control. Here is what owning security actually involves as a leader, and why it does not require you to become a technologist.

Operational security in the energy sector is national preparedness

In energy and other critical infrastructure, the cost of an outage is rarely measured in lost revenue alone. It is measured in what else stops working: water supply, payments, cold chains, care homes. This article looks at the IT/OT boundary, at plant designed to run for decades, at the supply chain, at what NIS2 actually asks of the board, and at what separates genuine preparedness from a preparedness document.

Under NIS2, the board's accountability is personal and documented

NIS2 places accountability for security where the decisions are made. The directive requires the management body to approve risk management, oversee it, undergo training itself, and be able to evidence what it has decided. This article sets out what that means in practice, and where the line runs between having documentation and having control.

AI in the business: how to make a safe start

Most organisations have already started using AI: rarely through a decision, more often through employees who found a tool that made the day easier. This article explains, calmly, what a language model is and is not, why that matters when you are trusted with confidential information, and how to begin in a way you can stand behind. It is written for leaders, not for developers.

AI governance: auditing what is not deterministic

For organisations already using AI in something that matters. On ISO/IEC 42001 as a management system, its relationship to ISO 27001, roles and duties under the EU AI Act, data governance and model risk. And on how to audit a system that does not give the same answer twice.