Skip to content

Resources

Resource library

Start with the decision, not the technology.

Choose the problem you are trying to solve. Each path starts with a framing resource, then moves into the evidence, trade-offs, and deeper implementation questions.

Path 01 · Technology decisions

Make better technology decisions.

Start by deciding whether an opportunity deserves investment. Then measure value, inspect the delivery system, and make hidden liabilities explicit.

Start this path
  1. Start hereWhere Does AI Actually Create Value?Use five elimination criteria before an AI initiative becomes a budget commitment.Next → measure the economics
  2. MeasureMeasuring AI ROIReplace speed anecdotes with cost per completed task and real operating economics.Next → inspect delivery flow
  3. DiagnoseThe AI Productivity ParadoxUnderstand why faster coding can move the bottleneck into review, testing, security, and integration.Next → make liabilities explicit
  4. Deep diveTechnical Debt Management: A Practical FrameworkPrice technical debt against future change and choose an explicit treatment instead of maintaining a cleanup list.Use this framework in roadmap decisions

Path 02 · Engineering systems

Build better engineering systems.

Start with the platform as a product. Then measure developer journeys and strengthen cloud foundations only where real signals justify the complexity.

Start this path
  1. Start herePlatform Engineering: What It Is and Why It MattersFrame platform engineering as a product discipline for removing repeated delivery friction.Next → measure the developer journey
  2. MeasureDeveloper Experience: How to Measure and Improve ItFind verified friction in real developer journeys instead of reducing experience to one survey or dashboard.Next → calibrate the foundation
  3. Deep diveYour Cloud Landing Zone Is Burning Months, Not Building FoundationStart with essential guardrails and add foundation complexity when concrete signals demand it.Apply the progressive-foundation test

Path 03 · Security evidence

Turn security evidence into decisions.

Start with the gap between inventory and risk. Build an evidence chain, route critical findings deliberately, document exploitability, and connect the operating model to regulatory expectations.

Start this path
  1. Start hereWhy Your SBOM Does Not Protect YouUnderstand what sits between software inventory and an actual security decision.Next → turn inventory into signal
  2. DecideFrom SBOM to Actionable SignalConnect component inventory, provenance, deployment, exposure, and exploitability before prioritizing remediation.Next → build the evidence chain
  3. BuildBuilding a DevSecOps Evidence ChainMake vulnerability decisions traceable from component inventory to deployment and VEX context.Next → route a critical advisory
  4. OperateResponding to a Critical CVERoute a critical advisory to remediation, investigation, justified deprioritization, or an explicit unknown.Next → document exploitability
  5. EvidenceVEX: Documenting “Not Exploitable”Treat VEX as attributable, bounded evidence before changing a finding's priority or suppression state.Next → connect operations to regulation
  6. GovernWhat the Cyber Resilience Act Changes for Vulnerability ManagementConnect EU product scope, vulnerability operations, ownership, and evidence without turning readiness into a checklist.Then → extend the model to AI systems
  7. Deep diveMLSecOps: Securing Models and Their DataExtend software security thinking to models, datasets, prompts, and inference pipelines.Apply the evidence mindset beyond source code