Blog
Insights & Perspectives
August 31, 2026·7 min read
The Product Owner's Hat: Why Technical Strength Matters in AI-Forward Development
Building personal projects with AI agents taught me how much the product owner seat shapes the outcome, and why technical depth in that seat matters more than it ever has.
Read more →June 7, 2026·12 min read
Retiring the 90-Day Password Reset Under PCI DSS 4.0
PCI DSS 4.0 finally gives you two legitimate ways to drop forced password expiry. Here is when MFA alone is enough, and how to build a customized approach that survives your QSA.
Read more →May 10, 2026·14 min read
Single-AZ Isn't Wrong. Accidental Single-AZ Is.
The AWS us-east-1 outage was a reminder that every architecture is a bet on availability. Here's how to make sure yours is a deliberate one.
Read more →May 7, 2026·4 min read
Building an ISMS From Scratch: A Practitioner's Playbook
When there's nothing to inherit — no policies, no risk register, no documentation — here's how to build an information security management system that actually works.
Read more →April 23, 2026·5 min read
PCI DSS 4.0: What I Learned Leading the Migration
After leading our PCI DSS Level 1 migration across multiple entities, here are the lessons that surprised me most — and what I wish I'd known going in.
Read more →