How to Audit a Technology Estate You’ve Never Seen Before

Walking into an organisation on day one and being asked “so, how are we doing” is the single most common moment in fractional CTO work, and it’s also the moment where a wrong first move costs months. There’s no existing context, no institutional memory of past decisions, and a genuine risk of either taking too …

Read more

AI-Accelerated Shadow IT: When Non-Coders Build Ungoverned Agentic Workflows

Shadow IT used to mean a marketing team quietly signing up for an unapproved SaaS tool. It now means a non-technical employee, using a low-code agent builder, quietly wiring together a workflow that reads customer data, calls an external API, and takes automated action — with no code review, no security review, and no one …

Read more

Technology Due Diligence in the Agent Era: New Questions for the Data Room

The technology due-diligence checklist most acquirers still use was written for a world of static software estates. It asks about the codebase, the infrastructure, the technical debt. It does not ask, in most current versions I’ve seen, what AI agents the target company runs, what those agents can actually do, and what happens to that …

Read more

What to Do With the System Nobody Understands Anymore

Every organisation of any age has one: a system, usually critical, that nobody currently on staff fully understands. It works, mostly, and everyone is afraid to touch it — which is a completely rational fear, and also a slowly compounding risk that doesn’t resolve itself by being left alone. I’ve written about knowledge concentration as …

Read more

Hiring Your First Engineer: What to Look For

A founder hiring their first engineer is making a decision they’re structurally unqualified to evaluate on the dimension that matters most — technical judgment — while under real pressure to get it right, because the first engineer disproportionately shapes every engineering decision that follows. Most hiring guidance for this specific moment either assumes technical fluency …

Read more

Starlink at Sea: How Connectivity Ended the Isolation That Protected Ships

A vessel’s isolation used to be its own cyber defence — weeks at sea with no meaningful connectivity meant no meaningful remote attack surface, whatever the ship’s onboard systems actually looked like underneath. Low-earth-orbit satellite connectivity has quietly ended that protection for a huge share of the global fleet, and a great deal of maritime …

Read more

Supply Chain Risk: The Dependencies You Didn’t Choose

Every organisation carefully vets its direct vendors. Almost none of them look one layer further, at the dependencies those direct vendors themselves rely on — the sub-processors, the open-source libraries, the fourth-party infrastructure providers nobody at the organisation ever chose, evaluated, or even knew existed until something went wrong three layers removed from anyone’s actual …

Read more

Book a Pillar 01 - Asset & Estate Visibility scoping call