Resources.
Field notes and selected engagements: how we think, and what it looks like in practice.
The data question your board should be asking
Not "are we doing something with AI" but "which of our critical decisions run on data we trust, and which only look like they do." One question separates the data-driven enterprise from the data-decorated one.
Fragmented systems are a competitive disadvantage your competitors can see
From the inside, fragmentation feels like history: every system had a reason. From the outside it reads as slow quotes, inconsistent service, and offers that arrive late. Customers feel it. Competitors count on it.
Why your board still can't see its technology risk
Cyber gets agenda time. AI gets a working group. The digital estate underneath them, where operational risk actually accumulates, appears on no agenda at all. That is a visibility problem, and boards can fix it.
The AI governance operating model
Decision rights, policy hierarchy, and operating cadence: the working parts of AI governance that survives scrutiny, mapped to ISO 42001 and the NIST AI RMF.
AI evidence and audit readiness
The evidence architecture to build before the auditor, regulator, or board asks: what to capture at design, deploy, and run, and how to rehearse the questions.
Leading AI-fluent teams
The four adoption failure modes, work design that builds fluency, and policy that enables adoption instead of killing it.
From data-risk findings to action in twelve weeks.
The company knew its data risks in outline but not in the specifics that let anyone act: sensitive information (personal, financial, intellectual property, and regulated data) spread across a large estate, exposure and oversharing unquantified, and retention practices leaving redundant data accumulating risk. Four priorities were clear (classify the sensitive, identify the exposure, realign the access, retire the redundant) and the brief was equally clear: findings that turn into action, not another assessment that ends as a report.
Data governance that leadership could finally see.
One of Australia's largest pension payers faced a widening gap between its data governance and its obligations: a growing set of Australian and US regulatory demands, contractual data and intellectual property that needed stronger protection, and a leadership team yet to be convinced that centralised data governance was worth funding. Governance existed on paper; what was missing was a program the business could see working.
A cyber strategy the whole business could execute.
A globally operating, ASX-listed resources company needed structure and insight in its cyber risk management: stakeholders across the business held different views of the priorities, the roadmap ahead was unclear, and internal capability needed lifting from within rather than replacing from outside. The goal was a cyber program the organisation could align on and execute with confidence.
The work, in your inbox.
Occasional notes on strategy, systems, delivery, and risk, written by the partners, sent when there’s something worth saying. Unsubscribe anytime.
Want to discuss any of this directly?
Whether you are framing a board-level technology decision, scoping a platform build, or recovering a transformation that has stalled, we lead with senior judgement rather than a sales pitch. The first conversation is always free.
Contact us