top of page
ISO 27001 as a Growth-Stage Startup: Why I'd Do It Again (But Not Earlier)
You're scaling, enterprise clients are asking for security questionnaires, your team doubled, someone's laptop got stolen, and you realize your "security policy" is a Google Doc from 2022 nobody reads. Sound familiar? The Right Time to Do It Don't do it pre-PMF. Do it when: You have paying enterprise customers who actually ask for it Your team is 15-30+ people and processes are breaking You're handling sensitive data (manufacturing defects, customer IP, etc.) You want to forc
Jan 162 min read


My Take on CI/CD Pipelines as a Startup CTO: The Good, the Bad, and the Balancing Act
My Take on CI/CD Pipelines as a Startup CTO: The Good, the Bad, and the Balancing Act
Mar 16, 20254 min read


RTO and RPO: A Startup CTO's Balancing Act
As the CTO of a rapidly growing startup, I'm constantly juggling priorities. We need to move fast, innovate, and keep our customers happy. But we also need to make sure our systems are resilient and our data is safe. That's where RTO and RPO come into play. RTO: How Long Can We Be Down? RTO stands for Recovery Time Objective. It's the maximum amount of time we can afford to have our systems offline before it starts to seriously impact our business. For a startup, downtime can
Aug 11, 20243 min read


The Pursuit of Perfection: Why Even the Best Software Has Bugs 🐞
It's a natural inclination to want our technology to be flawless, especially software that powers critical business processes. However, assuming any software is completely bug-free is unrealistic and can lead to damaging consequences. Understanding Software (and Human) Limitations Even the most meticulously crafted software, developed by highly skilled teams, will inevitably contain some bugs. Why? Because coding is a complex human endeavor, and errors are an unavoidable part
Mar 22, 20241 min read
bottom of page