Strategic Insights

Perspectives on governance, risk, and technology leadership.

Modernization as Resilience Investment, Not Cost Reduction

Legacy systems can create structural fragility that cost savings alone will not capture. Boards should evaluate modernization by the risks it reduces, the recoverability it improves, and the resilience it provides.

READ ARTICLE →

Boards Should Ask this First

For years, the cybersecurity question at the board level, and often at the management level, was simply: are we secure? I've come to believe that's the wrong question to lead with. At minimum, it's an incomplete one.

READ ARTICLE →

Tech Risk is Business Risk

Twenty years ago, technology supported the business. Today, technology drives the business. This distinction matters for how boards govern.

READ ARTICLE →

Technology Governance Needs Curiosity

Boards need technology fluency, not technical micromanagement. The stronger governance profile is often curiosity, operating experience, and the ability to ask the questions that reveal risk.

READ ARTICLE →

Vendor AI: The Governance Gap Most Boards Are Missing

Vendor AI can change data exposure before the board sees it. The governance question is whether management has a checkpoint before risk changes at the vendor’s pace.

READ ARTICLE →

The Difference Between a Plan and Readiness

A cyber incident response plan only becomes meaningful when it has been tested under pressure. For boards, the important question is what testing revealed and what changed as a result.

READ ARTICLE →

Culture as a Cybersecurity Variable

Cyber risk often begins with ordinary human behavior. Boards need to ask whether the organization’s culture supports reporting, accountability, and disciplined action before pressure arrives.

READ ARTICLE →

When Technology Risk Should Escalate

Most boards have a clear structure for financial reporting, audit findings, and regulatory matters. Technology risk often moves through a less defined path, leaving management to decide what rises to the board between regular reporting cycles.

READ ARTICLE →

What Good Technology Questions Sound Like

Good technology questions help boards understand which failures matter, what evidence proves readiness, and when risk should escalate.

READ ARTICLE →

What Tabletop Exercises Actually Teach Boards

Tabletop exercises test how governance works under pressure. They show who decides, who communicates, and whether the board knows when to engage or step back.

READ ARTICLE →

The Changing Nominating Committee Conversation

Technology risk governance belongs on the board talent matrix. Nominating committees need to know whether directors can govern cyber, AI, modernization, and third-party exposure as enterprise risk.

READ ARTICLE →

The Financial Risk Double Standard

Boards wouldn’t accept an unreviewed balance sheet. We wouldn’t tolerate undefined ownership of financial risk, or a review cadence that treats it as an annual event, regardless of what is happening in the business. Yet this standard is still common in technology governance.

READ ARTICLE →