15 May 2026 · 9 min read When Risks Collide: A Federated EA's Honest Confusion About Risk Management In a Federated EA model, IT, business, and security architects sit as peers — yet risk keeps dividing them. An open reflection on what happens when "every risk is intolerable" meets defense in depth and Risk Acceptance signatures. Not a tutorial — one provocative question I want pushed back on. Read more
Enterprise Architecture 18 Feb 2026 · 7 min read That Multi-Vendor "Resilience"? It's a Trap. After 15+ years in IT operations, I've seen the same pattern repeat: one solution, two vendors, split workload — sold as resilience but delivered as chaos. Here's why that approach is a trap, and what we should be doing instead. Read more
Cyber Security 7 Oct 2025 · 3 min read Duplicate Approvals Don’t Equal Security (They Just Waste Time) Redundant approvals look safe on paper, but they slow incident recovery without adding real protection. This post breaks down why duplicate sign-offs clog the pipeline, how to design distinct controls that actually reduce risk, and where AI helps streamline low-risk requests—so ops get faster, secur Read more