● UK · EU — Regulated fintech & energy Certifications delivered: ISO 27001 · PCI DSS v4 · DORA

Insights

Board-level security writing

Pillar articles + cluster posts. Specific moments, not generic problems. Written for CISOs, CTOs, COOs, and board directors at regulated fintech operators.

Pillar · 12 June 2026

Agentic AI and MCP Security for Fintech

Secure agentic AI and the Model Context Protocol in regulated finance: the autonomy spectrum, connector supply chain, scoped identity, and a kill switch.

Read
Article · 12 June 2026

AI assurance evidence for auditors

AI assurance evidence is the gap most programmes ignore. Here is how to build a control-to-evidence map your internal auditor can test independently.

Read
Article · 12 June 2026

AI governance and board accountability

AI governance in a regulated firm needs four targeted additions to your existing risk machinery, with named accountability attached before an incident.

Read
Article · 12 June 2026

AI incident response and resilience

AI incident response needs its own playbook: extend your IR process, build a kill-switch decision tree, and design resilience for non-deterministic AI.

Read
Article · 12 June 2026

Data poisoning defences for fintech AI

Data poisoning is the quiet threat in fintech AI: planted in grounding data, it fires long after you stop looking. How to defend what you control.

Read
Article · 12 June 2026

NIS2 and UK NIS for AI systems

NIS2 does not vanish for FS firms because DORA applies. Where NIS2 and UK NIS still bite on AI estates, supply chains, and group structures.

Read
Article · 12 June 2026

Quantifying AI risk for the board

How to move from heat maps to money-denominated loss distributions when quantifying AI risk for boards and CROs, with autonomy as the key magnitude multiplier.

Read
Article · 12 June 2026

Runtime monitoring for AI agents

Runtime monitoring for AI agents means more than application logs. What to instrument, how to detect abuse in production, and how to bound damage early.

Read
Article · 12 June 2026

Secure by design AI agents and MCP

Secure by design for AI agents is not a post-launch phase. Identity, least privilege, MCP hardening, and the gateway control plane, in plain terms.

Read
Article · 12 June 2026

Securing decisioning copilots in finance

Decisioning copilots in credit, fraud, and disputes need per-domain autonomy ceilings, not just output filters. Here is the framework I use.

Read
Article · 12 June 2026

Third-party AI risk management

A practical guide to third-party AI risk: how to vet providers, what to contract for, and how to manage concentration before a regulator asks.

Read
Pillar · 20 April 2026

AI Security Guardrails for Fintech

Ship production AI agents in regulated fintech: the three guardrail layers, the model-risk register, and board-ready evidence that survives audit.

Read
Pillar · 20 April 2026

DORA and the AI Rulebook for Fintech

DORA, the EU AI Act, SM&CR and PCI DSS mapped into one control layer, with evidence a board and an auditor both accept.

Read
Pillar · 20 April 2026

vCISO vs Fractional CISO vs BISO

How a regulated fintech buys security leadership: vCISO, fractional CISO, or BISO, with engagement models, pricing, and a board-ready ROI case.

Read
Article · 4 November 2024

Implementing ISO 27001 for regulated fintech

An end-to-end ISO 27001:2022 implementation for fintech operators on a 26-week timeline, covering scope, controls, audit, and an operating model.

Read
Article · 12 September 2024

Secure CI/CD pipelines for regulated fintech

Seven baseline controls that turn a fintech CI/CD pipeline from supply-chain liability into an audit-ready asset, with practical auditor-focused patterns.

Read
Article · 10 August 2024

Mitigating insider threats in regulated fintech

Most insider-threat programmes default to surveillance. The ones that work default to design. A framework for fintech CISOs.

Read
Article · 22 May 2024

Cybersecurity risk frameworks for financial institutions

How fintech operators reconcile NIST, ISO 27005, FAIR, and DORA's risk requirements without running four parallel programmes.

Read
Article · 15 March 2024

Agile risk management: integrating risk into agile boards

How to weave ICT risk management into agile delivery cadence without halting the team. Practical patterns for fintech CTOs and CISOs.

Read

Next step

Read what boards should be asking right now

One short email a month: a board-level question, a specific moment, and a next step. No spam, no drip sequences.