Articles
Private equity due diligence has sharpened considerably on security in recent years. It is no longer a box-ticking appendix to commercial and financial due diligence, it is frequently its own workstre...
For most businesses, security is a supporting function protecting the thing they sell. For a SaaS business, security protects the thing that often is the sale. Customers are trusting a SaaS provider w...
Selling into larger, more regulated or more risk-conscious customers usually means clearing a gate most smaller sales don't require: a security review. A questionnaire, sometimes running to hundreds o...
Almost every mid-market business has a disaster recovery plan of some description. Almost none of them have tested it in the way that matters: by actually trying to recover a system under realistic co...
Every mid-market leadership team is being asked, by a board member, an investor or a customer, some version of the same question: what is the business doing about AI? Most of the pressure to answer la...
Opening a second country office feels, at first, like a scaling problem: more people, more customers, more revenue. It is also, quietly, an IT architecture problem, and it's usually the part of the ex...
There is a comforting story being sold to a lot of scaling businesses right now: adopt AI and your productivity problem, your cost problem, your growth problem gets easier. It is a story about a tool,...
Nothing about crossing from SME into mid-market happens on a single day. There's no threshold that rings a bell. But somewhere between roughly £2m and £20m in revenue, the risk you carry changes shape...
"It still works" is one of the most expensive sentences in a scaling business's technology strategy, precisely because it sounds like a reason for confidence rather than a warning sign. A system that ...
Most businesses don't decide to go without security leadership. They simply keep deferring the decision until a customer, an insurer, or an incident forces their hand. By the time that happens, the hi...
For a regulated business, financial services, insurance, healthcare-adjacent, anything already answering to a sector regulator, AI adoption was never purely an efficiency question. It's a compliance q...
No single dramatic moment causes this. It's a slow accumulation, invisible from inside any one team, and only visible once someone looks at the whole business at once, usually well after the point whe...
Get actionable advice every Saturday
The CTO’s Playbook
Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.
Join The FREE Challenge
Enter your details below to join the challenge.