Blog

Seeing Like a Software Company

Extreme TLDR: Organizations prioritize legibility to facilitate tracking and planning, often at the cost of efficiency. This leads to a reliance on both legible (structured, measurable) and illegible (informal, untrackable) work. While small software companies thrive on illegibility for rapid delivery, large companies persist with legibility for benefits like enterprise deal-making, despite inefficiencies. This creates friction between those exploiting illegibility and those adhering to formal processes, highlighting the dual nature of work in tech companies.

https://www.seangoedecke.com/seeing-like-a-software-company/

Is the CISO Chair Becoming a Revolving Door?

The post highlights CISO tenure issues with average roles lasting three years due to stress, burnout, and liability. Larger organizations retain CISOs longer due to resources, while startups experience high turnover. Communication skills are crucial for success, with some CISOs opting for fractional roles or pivoting careers, indicating diverse motivations behind tenure changes.

https://www.csoonline.com/article/4066101/is-the-ciso-chair-becoming-a-revolving-door.html

Cloud Compliance Requirements: What You Need to Know

Cloud compliance is becoming a strategic necessity for businesses operating in multiple regions and sectors. Major regulations, such as GDPR, HIPAA, and PCI DSS, dictate how data is handled, driving system design and vendor selection. Non-compliance can result in severe fines, delayed launches, reputational damage, or even loss of market access. Certifications such as ISO 27001, SOC 2, and FedRAMP are increasingly prerequisites for customer and partner trust, while frameworks like NIST and CIS help ensure daily operational discipline. To keep pace with evolving laws surrounding privacy, AI risk, digital sovereignty, and industry-specific requirements, organizations must integrate compliance into their core cloud strategy, adopt ongoing monitoring, and ensure leadership remains directly involved. This approach turns compliance from a defensive burden into a competitive advantage and a key proof of enterprise readiness.

https://appinventiv.com/blog/cloud-regulatory-compliances-guide/

Are We Paying Enough Attention to the AI Risks?

KPMG Legal Reimagined outlines the primary legal, regulatory, and ethical risks associated with organizations utilizing AI. Key themes and takeaways:

  • Regulatory Landscape: Laws vary; the EU has the AI Act with strict requirements, while the UK is using decentralized, principle-based oversight.
  • Ethical Considerations: Focus on transparency, explainability, bias, and fairness. Ethics boards are used to oversee these issues.
  • Third-Party Risk: AI risk extends to suppliers; due diligence and contracts are vital.
  • Data Protection: Personal data must always comply with laws like GDPR; clear privacy notices are mandated.
  • AI and Copyright: Tension exists between using AI and creative industries’ rights; guidelines limit how legal data and generative AI can be used.
  • Pace of Change: Rapid AI advancements challenge legal professionals to keep up with new technologies and laws.
  • Opportunities for Legal Teams: AI can improve legal workflows and create new skill needs; leaders should plan for evolving roles and tech adoption.

https://kpmg.com/se/en/insights/newsletters/legal-reimagined/2025/are-we-paying-enough-attention-to-the-ai-risks.html

How AI-Powered Emotional Surveillance Can Threaten Personal Autonomy and Democracy

AI emotional surveillance threatens personal autonomy and democracy, with applications in education, border control, and public safety raising privacy concerns. These technologies analyze emotions through facial expressions and physiological cues, risking manipulation and coercion. Current regulations, like the EU AI Act, inadequately address these issues, leaving legal gaps that could undermine individual freedoms. Without proper oversight, emotional surveillance may lead to a society where self-expression is suppressed, jeopardizing democratic values and autonomy.

https://www.techpolicy.press/how-ai-powered-emotional-surveillance-can-threaten-personal-autonomy-and-democracy/

EU Commission to Unveil Its New Sectoral AI Uptake Strategy

EU Commission unveils AI strategy on Oct 8, 2025, promoting ‘AI-first' approach in various sectors. Aims include enhancing productivity, supporting SMEs, and establishing partnerships. Key initiatives target healthcare, manufacturing, public sector, and more, with a focus on training and compliance under the AI Act. EU seeks to ensure competitiveness and foster growth in AI-driven industries.

https://euobserver.com/eu-and-the-world/ar178848e4

European Approach to Artificial Intelligence

EU's official site emphasizes AI strategies focusing on excellence, trust, and safety. Goals include making Europe a world-leading AI hub, encouraging adoption in key sectors, and safeguarding fundamental rights. The AI Continent Action Plan and Apply AI Strategy aim to enhance competitiveness and innovation in AI, especially for SMEs. Legal frameworks like the AI Act ensure safety while the EU invests in AI development to foster a robust, trustworthy ecosystem. Key initiatives, partnerships, and milestones aim to coordinate efforts and improve AI's societal benefits across Europe.

https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence

Finance Sector Most Affected by GDPR Data Breaches

Between 2023 and Q1 2025, the finance sector reported the highest number of GDPR data breaches in the UK, with 3,820 cases. This includes 2,175 reported specifically by finance, insurance, and credit companies. Other sectors with high breach numbers include education, childcare, retail, and manufacturing. Data breaches range from sending emails to the wrong recipients to cyberattacks, and they are more common in sectors that hold sensitive data. Most incidents are reported in the fourth quarter of each year.

https://www.financialreporter.co.uk/finance-sector-most-affected-by-gdpr-data-breaches.html

Making Cybersecurity Training a Priority for Everyone

TLDR: Cybersecurity relies on skilled users, not just technology; 95% of data breaches in 2024 were due to human error. Investment in user education and reskilling is essential. Training must be relevant and encompass all employees, not only specialists. With AI's rise, ethical understanding and critical thinking in cybersecurity training are critical. Cybersecurity should be a collective responsibility, integrated into daily life, and treated as a public good requiring cooperation and constant adaptation.

https://www.weforum.org/stories/2025/10/cybersecurity-people-not-just-technology/

What an IT Career Will Look Like in 5 Years — and How to Thrive Through the Changes

IT careers by 2030 will require interdisciplinary skills as AI reshapes roles, emphasizing problem-solving, adaptability, and continuous learning. Basic tasks are being automated, increasing demands for higher technical knowledge and soft skills. Networking, certifications, and staying AI-fluent are essential. Future success hinges on blending human and technical capabilities, managing AI, and embracing a continuous learning mindset to navigate an evolving job landscape.

https://www.cio.com/article/4066676/what-an-it-career-will-look-like-in-5-years-and-how-to-thrive-through-the-changes.html

Scroll to Top