Blog

  • What Is a Fractional IT Director and When Do You Need One?

    What Is a Fractional IT Director and When Do You Need One?

    Most growing businesses hit a point where “the IT person” isn’t enough — but a full-time IT Director isn’t quite justified either. That gap is where a Fractional IT Director makes sense.

    This post explains what the role actually is, how it differs from the alternatives, and the four situations where it consistently delivers the most value.

    What a Fractional IT Director Is

    A Fractional IT Director is a senior technology leader who works with your business on a part-time basis — typically one to three days a week, or a fixed monthly retainer. They take accountability for your technology function in the same way a permanent IT Director would, but without the full-time cost or the commitment of a permanent hire.

    The “fractional” model works because the skills you need — strategic technology planning, vendor management, digital transformation leadership, board-level communication — don’t require someone present five days a week. What they require is the right level of seniority and genuine accountability, applied at the right moments.

    A Fractional IT Director is not a consultant who gives you a report and disappears. They’re part of your leadership team, attending management meetings, owning the technology roadmap, and making decisions. The distinction matters because accountability is what you’re actually buying.

    How It Compares to the Alternatives

    Versus a full-time IT Director

    A permanent IT Director in the UK costs £80,000–£140,000 in salary, plus employer NI, pension, benefits, and recruitment fees. All-in, you’re typically looking at £110,000–£180,000 per year before you’ve accounted for notice periods, management time, and the risk of a bad hire.

    A fractional engagement at two days a week costs roughly a third of that. For most businesses under 200 people, the fractional model delivers the same strategic output at a fraction of the cost — because the strategic work doesn’t fill five days a week at that scale.

    Versus an MSP (Managed Service Provider)

    An MSP keeps your systems running. They manage your infrastructure, handle your helpdesk, patch your software, and respond when things break. That’s operations, not leadership.

    An MSP does not set your technology strategy. They don’t challenge your business on whether your current systems are the right ones for where you’re going. They don’t prepare you for an acquisition, challenge a supplier on contract terms, or give your board a view of technology risk. That’s what an IT Director does.

    The two roles are complementary, not interchangeable. Many businesses I work with have a good MSP and no IT leadership — the MSP is doing operational work well, but nobody is asking the strategic questions.

    Versus a project consultant

    A consultant is typically hired to deliver a specific, defined outcome — implement a new system, run a migration, deliver a security audit. The engagement ends when the project ends.

    A Fractional IT Director is an ongoing role with ongoing accountability. They’re not there to deliver a project; they’re there to lead the function. The difference becomes obvious when something unexpected happens. A project consultant is scoped to their deliverable. A Fractional IT Director is responsible for the technology estate in totality.

    Four Situations Where It Consistently Makes Sense

    1. You’ve outgrown your current IT setup but you’re not ready to hire

    Your business has grown. You have 50, 80, 120 people now. The IT that worked when you were 20 people isn’t keeping pace. Systems are patched together. Decisions are being made reactively. The person who “manages IT” is overwhelmed and operating without a strategy.

    You need someone to assess what you have, build a credible roadmap, and start making decisions — but you’re not yet at the scale where a full-time hire makes financial sense. A Fractional IT Director bridges that gap. They give you the leadership now, while the business continues to grow toward the point where a permanent hire becomes justified.

    2. You’re going through a period of significant change

    Acquisition. Merger. Rapid headcount growth. Office consolidation. Major new customer win that requires you to operate differently. These transitions put pressure on technology infrastructure in ways that aren’t always visible until something breaks.

    Technology change during business change requires senior leadership, not just good execution. Someone needs to be asking: what does our IT estate need to look like in 18 months, and are the decisions we’re making today consistent with that? That’s a Fractional IT Director’s job.

    3. You’re a PE-backed business without a technology leader

    Private equity portfolio companies often sit in an uncomfortable position — expected to operate with discipline and demonstrate progress, but not always structured to have senior technology leadership in place. IT gets managed by the CFO, the COO, or whoever happens to be technically literate.

    A Fractional IT Director fits the PE model well. They can operate across multiple portfolio companies, bring consistency to governance and reporting, and provide the oversight a portfolio board expects — without inflating the headcount cost structure of each individual business.

    4. You’re preparing for a transaction or exit

    Technology due diligence is a serious process. Buyers and their advisors will review your infrastructure, your security controls, your vendor contracts, your data management practices, and your ability to continue operating without key-person dependencies.

    Businesses that go into a process without technology leadership in place frequently discover gaps that cost them at the negotiating table — price chips, extended warranties, deferred consideration. A Fractional IT Director with experience of M&A processes prepares you on your own timeline, not the buyer’s.

    What the Engagement Actually Looks Like

    Most fractional engagements start with an assessment. Before we agree a retainer structure, I need to understand your current state — what you have, what the gaps are, and what the priorities should be. That typically takes two to three days and produces a clear picture of where to focus.

    From there, a typical engagement involves a fixed monthly commitment: attending your leadership meetings, owning the technology roadmap, overseeing your IT team or MSP, managing major vendor relationships, and being available when something needs a senior decision.

    The monthly commitment scales with complexity. A simpler business might need two days a month for strategic oversight and governance. A business going through a cloud migration or a major platform change might need two days a week for a defined period.

    The honest version: you’re paying for someone who is accountable for your technology, not just available to advise on it. That accountability is what makes the model work.


    If you’re trying to work out whether a Fractional IT Director is the right move for your business, the Fractional CTO / IT Director service covers how I work in more detail. Or if you’d rather just have a direct conversation, get in touch — I’ll tell you honestly whether I can help.

  • What is a Fractional CISO?

    What is a Fractional CISO?

    What is a Fractional CISO?
    Published: March 17, 2026

    If you’ve started looking at your cyber risk and realised you need someone senior in the room — but a full-time CISO at £120,000–£180,000 a year isn’t on the cards — a Fractional CISO is probably what you’re looking for.

    The term gets used loosely. Let me give you a straight answer about what it actually means, what a Fractional CISO does day-to-day, and how to tell whether you need one.

    The Short Version

    A Fractional CISO is a senior security leader who works with your organisation on a part-time or interim basis — typically one to three days a week, often on a fixed-term engagement. You get the strategic judgement and hands-on experience of someone who has run security at enterprise level, without hiring them full-time.

    The “fractional” model exists because most SMEs and growing businesses don’t need a full-time CISO. What they need is serious security leadership a few days a week — someone who can set the direction, own the risk, talk to the board, and make sure the technical team is pointed the right way.

    What a Fractional CISO Actually Does

    This varies by engagement, but in practice the work falls into a few consistent areas:

    Security strategy and governance — defining your security posture, setting policy, building a roadmap that’s proportionate to your risk and your budget. Not a 200-page document nobody reads. A working plan the business can execute.

    Risk and compliance — owning your risk register, preparing for Cyber Essentials or Cyber Essentials Plus, supporting ISO 27001 if that’s relevant, making sure you’re meeting your contractual and regulatory obligations. For many UK businesses this increasingly means GDPR accountability as well.

    Incident readiness — making sure you have a plan before something goes wrong, not after. Running tabletop exercises, reviewing your backup and recovery position, knowing who calls who at 2am.

    Board and leadership communication — translating technical risk into business language. A board doesn’t need to understand CVE scores. They need to understand what they’re liable for and what it would cost if something went wrong. That’s a skill most technical security people don’t have, and it’s where a good CISO earns their fee.

    Vendor and supplier oversight — reviewing what your MSP is actually doing, checking your cloud configuration, making sure the security tooling you’re paying for is configured correctly. In my experience, most SMEs have the right tools and the wrong settings.

    What a Fractional CISO Is Not

    They’re not a one-off consultant who delivers a report and disappears. That’s a security audit. Useful, but different.

    They’re not a managed security service (MSSP). An MSSP monitors your environment and responds to alerts. A Fractional CISO sets the strategy that determines what you’re monitoring and why.

    They’re not a replacement for a good IT team or MSP. They work alongside your existing technical resource, not instead of it.

    Who Needs a Fractional CISO?

    The businesses I typically work with fit one of a few patterns:

    • Growing SMEs (50–500 people) who have outgrown “IT does security” but aren’t ready to hire a full-time CISO. Often triggered by a new enterprise customer asking about your security posture, or a cyber insurance renewal that suddenly requires evidence.
    • PE-backed portfolio companies where the fund needs consistent security governance across multiple portfolio businesses. One fractional CISO across two or three companies is far more cost-effective than three separate hires.
    • Businesses going through change — acquisition, cloud migration, rapid headcount growth. Security debt accumulates fast in these moments. A fractional engagement through the transition prevents problems that are very expensive to fix later.
    • Businesses post-incident who need someone to come in, stabilise, and build something better. This is the most urgent version of the engagement and usually the most intensive.

    What It Costs

    Engagement structures vary, but a typical fractional CISO arrangement in the UK runs between £3,000 and £8,000 per month depending on days committed and scope. Compare that to the fully-loaded cost of a permanent hire — salary, NI, benefits, pension, recruitment fees — and the economics are usually straightforward.

    For most SMEs, the right entry point is a Discovery Audit: a structured review of your current security posture that produces a prioritised roadmap. It gives you a clear picture of where you stand and what to fix first, and it’s the starting point for any ongoing engagement.

    The Question Worth Asking

    Most businesses don’t call a Fractional CISO until something prompts them — a near-miss, a contract requirement, a board conversation. The ones that get the most value engage before that moment, when there’s time to build something properly rather than fix something broken.

    If you’re not sure whether your business is in a good position, the honest answer is: you probably don’t know, and that’s worth finding out. The way I structure this work is described on the Security & Compliance Strategy service page.

    Book a 30-minute call to talk through your situation — no pitch, just a frank conversation.

  • How Multi-Agent Operations Work in Practice

    e

    Most organisations still treat AI agents like a single chat window with extra buttons. That is fine for a demo. It is not fine when the work touches production systems.

    The difference is operational, not magical. The teams getting value from agents are the ones that add roles, checkpoints, and ownership.

    What works

    A reliable setup usually has four pieces:

    • a coordinator that defines the task and checks the output
    • worker agents that do independent chunks in parallel
    • state that lives somewhere everyone can inspect
    • review points before anything risky moves forward

    That is not glamorous, but it works.

    A simple example

    If three services are acting up at once, a good coordinator breaks the problem apart and sends each service to a separate worker. The workers do not need to talk to each other because the tasks are independent. The coordinator then compares the results and decides whether to approve the fix or escalate.

    That pattern saves time without turning the system into a black box.

    The cost question

    People often assume agent work must be expensive. In practice, the opposite is usually true. The cheap model can do the repetitive work. The better reasoning model is reserved for coordination and review.

    That split matters. It keeps the system affordable and keeps judgment where it belongs.

    What to do first

    1. Decide who owns the outcome.
    2. Identify which tasks can run in parallel.
    3. Make state visible.
    4. Add checkpoints where mistakes would hurt.

    That is enough to get started. The rest is tuning.

  • What 25 Years in IT Changed About How I Build AI Systems

    3 Years Later: From PowerShell to AI Factory
    Published: March 14, 2026

    Three years ago I typed a PowerShell question into ChatGPT with cautious scepticism. Today AI powers 90% of my workflows, governs itself via SentinelForge, ships products through HeliOS-Studio, and writes blog posts like this one. Here’s everything the journey taught me.

    The Stack in 2026

    richardham.co.uk ecosystem
    ├── richardham.co.uk        (Next.js V2 + headless WordPress)
    ├── sentinelforge           (CrewAI production agents)
    ├── control-tower           (GitHub workflow automation)
    ├── helios-studio           (AI startup studio)
    ├── llm-router              (90% cost reduction)
    └── blog-agent              (this post, auto-generated)
    

    The 3-Year Arc

    Year Theme Key Milestone
    2023 Exploration ChatGPT Enterprise → Ollama homelab
    2024 Orchestration Control Tower → 90% cost cut
    2025 Governance SentinelForge → EU AI Act ready
    2026 Commercialisation HeliOS-Studio → products at scale

    What Actually Mattered

    1. Governance first — every time I skipped it, something broke. Every time I built it in, it paid dividends.
    2. Local inference — Proxmox + Ollama removed the ceiling on experimentation. Zero cost = unlimited iteration.
    3. 25 years still matter — AI amplifies expertise. It doesn’t replace the judgement that comes from experience.
    4. Ship early, gate carefully — Control Tower’s human-approval model let me move fast without breaking things.
    5. Document everything — GitHub is the memory. AI is the muscle. You are the judgement.

    The next three years? AI agents running autonomous security operations, HeliOS-Studio shipping SME products monthly, and richardham.co.uk as the hub for all of it.

    Ready to start your AI journey? Book a free Secure AI QuickScan—live now on this site.

  • Does Your Business Actually Need a CISO? An Honest Answer

    Does Your Business Actually Need a CISO? An Honest Answer

    Most of the businesses I talk to ask this question after something has already happened. A contract requirement they didn’t see coming. An insurance renewal that suddenly needs evidence. A near-miss with a phishing attack. A new board member who used to work somewhere with proper security governance.

    The honest answer to “do I need a CISO?” depends on where your business is and what’s about to happen to it. Here’s how to think through it.

    Five Signals You Need One

    1. An enterprise customer is asking about your security posture

    If you’re selling into large organisations — financial services, healthcare, legal, retail, public sector — their procurement and vendor management processes now routinely require you to complete security questionnaires, pass supplier audits, or meet minimum security standards.

    “We take security very seriously” is not an answer to a SOC 2 questionnaire or a CREST assessment. If your current position is that your IT manager handles security alongside everything else, you’re going to start losing contracts to competitors who can demonstrate proper governance.

    A CISO — even fractional — gives you someone who can own this, respond credibly, and make sure your controls match what you’re saying they are.

    2. You’re going through or approaching a transaction

    M&A, PE investment, fundraising, management buyout — any significant transaction will involve a technology and security due diligence process. Buyers and investors are looking for clean estates, documented controls, and evidence of risk awareness.

    Discovering your security gaps during due diligence is expensive. You either fix them under time pressure (costly), accept a price reduction (painful), or watch the deal fall through (devastating). Engaging a CISO before you reach that stage gives you time to find and address the issues on your own terms.

    3. You’re growing faster than your controls

    Headcount doubling. New offices. First international employees. Acquisitions of smaller businesses with their own IT environments. Cloud adoption running ahead of policy.

    Security debt accumulates faster than almost any other kind of technical debt, and it’s less visible until it isn’t. If your organisation has outrun its original IT setup, you almost certainly have gaps that haven’t been properly assessed.

    4. Compliance is becoming unavoidable

    ISO 27001 is now effectively table stakes for mid-market UK businesses selling B2B. Cyber Essentials Plus is increasingly mandated for government supply chain work. GDPR accountability isn’t going away.

    These programmes can be done without a CISO, but they’re more expensive and less effective when they’re treated as a project rather than an embedded practice. A CISO makes compliance a sustainable capability, not a recurring one-off cost.

    5. You’ve had an incident — or you’ve nearly had one

    A ransomware infection that got contained by luck. A staff member who clicked a phishing link and you only found out weeks later. A data breach notification from a supplier. A security researcher who contacted you about an exposed database.

    Near-misses are warnings. They tell you that something in your environment is porous. Responding well to an incident — containing it, understanding the root cause, communicating appropriately, and improving controls — requires someone with the right experience in the room.

    Three Signals You Don’t Need One Yet

    1. You’re genuinely too small

    If you’re under 20 people, cloud-native, with no regulated data and no enterprise customer requirements, a full CISO engagement is probably not the right tool. What you need is a well-configured Microsoft 365 or Google Workspace environment, Cyber Essentials certification, and a sensible backup and recovery position. That’s a project, not an ongoing leadership role.

    2. Your existing IT partner is doing an adequate job

    Some MSPs and IT providers genuinely include good security oversight in their service delivery. If your provider is actively managing patching, monitoring your environment, advising on configuration, and doing periodic risk reviews — and if you have no external compliance pressures — you may not need a separate CISO function yet.

    The test: can you say what your current security posture is? Can you name the three biggest risks to your business and what’s being done about them? If yes, you may be fine. If not, that’s a gap.

    3. You’re not ready for the conversation

    A CISO engagement only works if the business is willing to make decisions and act on the findings. If your leadership team isn’t prepared to invest in the recommendations, change some established habits, or have difficult conversations with suppliers or staff — the engagement won’t deliver value.

    This isn’t a reason to delay indefinitely. It is a reason to make sure the business is aligned before starting.

    What Most UK SMEs Actually Need

    The reality is that most UK businesses between 50 and 300 people sit in a middle ground. They have genuine security risk, real compliance exposure, and meaningful consequences if something goes wrong — but the workload doesn’t justify a full-time hire.

    What they typically need is:

    • Someone accountable for security at a senior level (not just “IT handles it”)
    • A clear picture of their current posture and the gaps
    • A proportionate roadmap — not a 200-page security programme, but the 10 things that matter most
    • Ongoing oversight to make sure progress happens and new risks are caught

    That’s what a Fractional CISO engagement is designed to deliver. Two days a month might sound minimal, but two days a month of focused senior security leadership is more valuable than fifty days of security-adjacent IT management.

    The entry point for most businesses I work with is a Discovery Audit — a structured two-to-three day review that gives you a clear picture of where you stand and what to prioritise. No commitment to an ongoing engagement. Just a straight answer.


    If you’re trying to decide whether your business needs a CISO and aren’t sure where you sit, get in touch. I’ll tell you honestly whether I can help and what the right starting point is. Most conversations are useful even when there’s no engagement at the end. The full scope of how I work is on the Security & Compliance Strategy service page.

  • What Does a Fractional CISO Cost in the UK? (2026 Guide)

    What Does a Fractional CISO Cost in the UK? (2026 Guide)

    If you’ve started looking into fractional CISO arrangements, you’ve probably noticed that nobody publishes rates. You get vague talk about “competitive pricing” and “tailored engagements” but no actual numbers.

    This is my attempt to fix that. I’ll give you the real ranges, explain what moves the price, and give you the comparison you actually need: fractional versus a permanent hire.

    What You’re Actually Buying

    Before we get to numbers, it’s worth being clear about what a Fractional CISO engagement actually covers — because the answer affects the cost.

    A Fractional CISO is not a security consultant who writes reports. That’s a different engagement model. A Fractional CISO is a part-time member of your senior leadership, operating as your de facto Chief Information Security Officer with all the accountability that implies.

    In practice, that means:

    Ownership of your security posture. Not advice about it. Actual ownership — setting strategy, making decisions, reporting to the board or CEO on risk.

    Ongoing availability. Not just fixed project days. A good Fractional CISO is reachable when something happens — a supplier breach, an insurance questionnaire, a board request for a risk briefing.

    Day-to-day security leadership. Reviewing controls, managing incidents, overseeing your IT team or MSP on security matters, making sure the work actually gets done.

    External credibility. Being able to put a named CISO on a client questionnaire, a contract, or an audit scope. For mid-market businesses dealing with enterprise customers, this alone is often worth the fee.

    That distinction matters because it separates fractional from project-based work, and the price reflects it.

    Typical Cost Ranges in the UK Market

    Here are the real numbers as of 2026, based on the UK market specifically:

    Entry-level engagement: £2,500–£4,000/month
    Usually one day a week, or a structured retainer. Covers governance, policy, and light-touch oversight. Right for smaller businesses (20–80 people) who need a documented security posture and someone accountable for it, but don’t have complex infrastructure or active compliance requirements.

    Mid-range engagement: £4,000–£7,000/month
    One to two days a week. This is the most common arrangement for UK SMEs between 80 and 300 people. Covers strategy, compliance (Cyber Essentials Plus, ISO 27001 readiness, GDPR accountability), board reporting, incident management, and oversight of your technical security team or MSP.

    Higher-intensity engagement: £7,000–£12,000/month
    Two to three days per week, or a fixed-scope intensive engagement (post-incident stabilisation, pre-acquisition security readiness, major compliance programme). At this level you’re getting something close to a full-time CISO presence without the full-time cost.

    Some providers price by day rate rather than monthly retainer. In that case, expect senior Fractional CISO day rates in the UK to sit between £900 and £1,800 per day, depending on experience and specialism.

    What Affects the Price

    The same fractional CISO will charge differently for different engagements. Here’s what moves the number:

    Days committed per month. The main variable. More days, more cost — but also more hands-on delivery versus purely strategic oversight.

    Compliance scope. If you’re pursuing ISO 27001, preparing for a major enterprise audit, or navigating sector-specific requirements (financial services, healthcare, defence supply chain), the workload increases substantially. Expect to pay for it.

    Incident history. Starting from scratch is easier than cleaning up after a breach or a failed audit. Post-incident engagements are more intensive and more expensive in the early months.

    Organisation complexity. 50 people in one office with a single cloud environment is a different engagement to 200 people across four countries with a mix of legacy systems, SaaS, and on-premise infrastructure.

    Urgency. A phased 12-month engagement costs less per month than a 90-day sprint to get you through a due diligence process. You pay for speed.

    Fractional vs Full-Time: The Real Comparison

    A permanent CISO in the UK costs, on a fully-loaded basis:

    • Base salary: £90,000–£160,000 (senior hire in London; less outside)
    • Employer NI: ~13.8% on salary
    • Pension contributions: typically 5–8%
    • Benefits package: private health, life assurance, income protection
    • Recruitment fees: typically 20–25% of first-year salary if using an agency

    Add it up and a full-time CISO typically costs £130,000–£220,000 per year all-in before you’ve counted their office space, equipment, management overhead, or the time it takes to find the right person.

    A mid-range fractional engagement at £5,000/month is £60,000 per year. You get senior-level security leadership at roughly half the cost, with no recruitment risk, no notice period to serve, and the ability to scale the days up or down as your needs change.

    For most UK SMEs, the only reason not to go fractional is if your security workload genuinely justifies full-time attention — and that usually means you’re above 500 people with a complex regulatory environment, active threat landscape, or significant security-critical product development.

    The Starting Point: A Discovery Audit

    For most businesses, the right first engagement isn’t a retainer. It’s a Discovery Audit: a structured review of your current security posture that takes two to three days and produces a prioritised action plan.

    It answers the question: where do we actually stand? It removes the uncertainty from any ongoing engagement that follows, and it’s the honest way to scope a fractional arrangement — you don’t know what you’re buying until you know what the problems are.

    If you’re comparing providers, ask whether they’ll do a discovery engagement before committing to a retainer. If the answer is no, that’s a signal.


    If you’d like to talk through what a fractional CISO engagement might look like for your business — scope, cost, timeline — see the Security & Compliance Strategy service or get in touch directly. I’ll give you a straight answer about whether it makes sense.

  • HeliOS-Studio: AI Startup Studio Ignites

    t

    After a few years of building AI tooling, I hit a point where the stack stopped feeling like scaffolding. It started to look like a product in its own right.

    That is a strange moment. You begin by solving a narrow operational problem, then realise the workflow you built to support the work is now valuable enough to stand on its own.

    The shape of it

    The setup was simple in principle:

    • one layer for orchestration
    • one layer for safe execution
    • one layer for inference
    • one layer for content and delivery

    The names changed over time. The pattern did not.

    What the studio produced

    The useful output was not a single breakthrough. It was a steady stream of small, shippable things: business plans, MVP outlines, content drafts, docs, and working repos.

    That changed how I thought about progress. Instead of asking, “Can the system automate this?” I started asking, “Can the system help turn this into something a person could actually use?”

    The takeaway

    Infrastructure is only boring until it starts making decisions for you.

    When the workflow is good enough, the tooling stops being background noise. It becomes part of the offer.

  • EU AI Act Compliance: Governance Frameworks in Practice

    EU AI Act: My Clients Were Ready. Most Weren’t.
    Published: November 10, 2025 (retrospective)

    EU AI Act enforcement began in earnest in late 2025. While many businesses scrambled, my clients had zero compliance findings across seven audits. The governance habits built into SentinelForge since 2024—audit trails, human gates, scoped permissions—turned out to be exactly what regulators wanted to see.

    Framework Coverage

    Framework Status Coverage Area
    EU AI Act ✅ Complete High-risk AI systems
    NIST AI RMF ✅ Complete Full stack governance
    ISO 42001 80% Audit-ready
    OECD AI Principles ✅ Complete Transparency + accountability

    What Auditors Actually Look For

    1. Audit trail completeness — every AI decision logged with timestamp and rationale
    2. Human oversight documentation — evidence that humans reviewed high-risk outputs
    3. Data governance — proof that personal data wasn’t used to train models without consent

    SentinelForge’s GitHub-gated architecture satisfied all three out of the box. The logs were already there.

    The Lesson

    Compliance isn’t a bolt-on. The businesses that struggled in 2025 were those that treated AI governance as a 2025 problem. We started in 2023.

    Need EU AI Act readiness for your AI systems? Book a governance audit.

    Next: HeliOS-Studio—AI startup studio ignites (Feb 2026).

  • AI Arms Race: Predictive Cyber Defence

    AI Arms Race: Predictive Cyber Defence Is Here
    Published: August 20, 2025 (retrospective)

    The AI cybersecurity market is projected to hit $60B by 2028—and for good reason. In August 2025, SentinelForge v2’s predictive threat hunting caught a client ransomware pivot 72 hours before it would have detonated. No SOC. No SIEM subscription. Just CrewAI agents, local LLMs, and disciplined governance.

    SentinelForge v2 Production Stack

    proxmox-ve
    └── sentinelforge (docker)
        ├── crewai crews     (24/7 autonomous monitoring)
        ├── ollama           (local inference)
        ├── grafana          (observability)
        └── uptimekuma       (SLA: 99.9%)
    

    The Catch: Anatomy of a Prevention

    • Day 1: Anomalous LDAP query pattern flagged by Audit Crew
    • Day 2: Lateral movement indicators correlated across 3 systems
    • Day 3 (72h): Human review triggered; client isolated affected segment
    • Result: Zero encryption, zero ransom, zero downtime

    What This Means for SMEs

    Enterprise-grade predictive defence is now accessible without enterprise budgets. The stack cost: £0/month in cloud tokens, running on repurposed hardware.

    1. AI agents don’t get tired—24/7 monitoring without alert fatigue.
    2. Local inference keeps sensitive threat data off third-party servers.
    3. Governance logs every detection decision—invaluable for insurance and compliance.

    Want predictive AI defence for your business? Book a Secure AI QuickScan.

    Next: EU AI Act compliance—governance frameworks in practice (Nov 2025).

  • What AI Session Logs Can Tell You About How You Work

    s

    I had spent a long time using AI tools for code, ideas, and problem-solving. At some point I started wondering whether the logs might be useful for something other than debugging the tools.

    So I exported a pile of sessions and looked for patterns.

    The pipeline

    chat exports -> normalise -> analyse -> notes
    

    The point was not to turn private data into a product. The point was to understand my own habits without relying on memory or vibes.

    What turned up

    1. I over-engineer security more often than I notice in the moment.
    2. I default to doing things myself even when delegation would save time.
    3. I think in systems now, not isolated tasks.

    None of that was shocking, but seeing it written down made it harder to ignore.

    Why it mattered

    The useful part was not the novelty. It was the feedback loop. AI logs can show you where you repeat yourself, where you hesitate, and where you keep solving the same problem in slightly different ways.

    That can be useful. It can also be a privacy trap if you treat the data casually.

    My rule stayed simple: keep the raw data local, keep the analysis honest, and do not mistake pattern recognition for wisdom.