AI Didn't Break Your Security

August 2026

Most technology functions carry a list of jobs that never quite got finished, and every item on it sits behind a defensible decision, priced when exploiting a gap took an attacker weeks of skilled effort. AI has changed those economics, from outside and from inside. On the repriced risk acceptance, the estate nobody mapped, and the questions a board can ask before approving the next AI spend.

Read the essay

The Operability Gap

July 2026

Some of the smartest product teams in the market hold real certifications and still stall in third-party risk review, because the certificate describes the vendor's own controls while the review asks whether the product can live inside the buyer's control environment. On where those questions came from, the personal accountability that drives them, and why the requirements are knowable before the deal.

Read the essay

The Missing Credential

July 2026

The law is particular about who may sign the accounts that reach an audit committee. The cyber report that reaches the same committee has nothing like that behind it, and the only people any UK regulator has ever insisted on certifying are the testers, not the people defending the firm all year round. The personal accountability for being satisfied lands where the last decade of regulation has aimed it, on named executives and boards, with no profession underneath them.

Read the essay

New pieces appear here as they are published. Ordonis is the advisory practice of Anthony Hines. To talk about anything written here, start a conversation.