Skip to content

Insights

Perspectives from the frontiers of financial technology.

Practical thinking on the domains we build in — from prototyping and resilience to agentic commerce and the quantum era.

Featured Security

From findings to fixes: security remediation engineering

A security assessment produces findings; someone still has to engineer the fixes. How we set up hands-on remediation engineering capability — application, workflow, release and logging changes, shipped with full evidence and traceability.

14 July 2026 7 min read
Security

Leading Cyber Threat Intelligence in a complex enterprise

How we lead and enhance enterprise Cyber Threat Intelligence — turning feeds and platforms into actionable, intelligence-led decisions across security operations, incident response, threat hunting and risk.

14 July 2026 7 min read
Security

Best practices for third-party risk management

Ten years of client engagements distilled into what an effective third-party risk programme actually contains — from a complete inventory and risk-based due diligence to SBOMs, continuous monitoring and governance aligned to NIST 800-161, ISO 27036, NIS2 and DORA.

14 July 2026 8 min read
Security

Third-party risk: cheap to manage, ruinous to ignore

Many of the largest breaches of the past decade began not inside the victim but inside a trusted supplier. Third-party risk management is inexpensive to do well and catastrophic to neglect — but only if it covers every touchpoint.

13 July 2026 7 min read
AI

The characteristics of successful enterprise RAG

We've written about why ambitious RAG projects fail. Here is the constructive side: the traits the enterprise implementations that actually work reliably share — from curated knowledge and hybrid retrieval to governance, evaluation and citations.

13 July 2026 7 min read
AI

Chunking is harder than people expect

In AI retrieval, how you split documents decides everything. Bad chunking quietly destroys retrieval — good chunking respects the structure of the document. Here is why it is trickier than it looks.

13 July 2026 6 min read
AI

Why ambitious RAG projects fail — and how we turn them around

The RAG builds we are called in to rescue rarely fail because of the model. They fail on foundations: poor data quality, no information architecture, no governance, and the wrong chunking. Here is how we fix them and deliver the value.

13 July 2026 7 min read
AI

Transforming search for the AI world with vector databases

How we built AI-ready shopping recommendations and complementary-product discovery for Shopify merchants on Qdrant — hybrid retrieval, business-aware score boosting, late-interaction precision and MMR diversity.

13 July 2026 8 min read
Security

Saving time and money on PCI DSS — and banking a security win

The cost of PCI DSS is set by the size of your cardholder data environment. Map every touchpoint early, shrink the CDE with tokenisation and segmentation, and the compliance work doubles as a cyber-security and resilience quick win.

13 July 2026 7 min read
Security

Lessons from taking a startup to ISO 27001 for under €10,000

ISO 27001 is sold as slow and expensive. For an early-stage startup we brought it in for under €10,000, returned roughly 5x in value — and left them SOC 2-ready almost for free.

13 July 2026 8 min read
Quantum

Lessons from implementing post-quantum cryptography

Migrating to quantum-safe cryptography is less about picking an algorithm and more about knowing where your cryptography lives. Hard-won lessons from the work.

13 July 2026 7 min read
Prototyping

Proving it first: why working prototypes de-risk innovation in banking

A working prototype turns an argument about the future into evidence you can see. Here is why the largest institutions increasingly start there.

24 June 2026 6 min read
Resilience

Operational resilience is an engineering problem, not a policy document

Regulators increasingly expect firms to prove resilience, not just describe it. That shifts the work from the policy team to the architecture.

15 May 2026 5 min read
Agentic Commerce

Agentic commerce needs payment rails it can trust

As AI agents begin to shop and pay on our behalf, the infrastructure underneath them has to make autonomy safe, bounded and auditable.

2 April 2026 5 min read
Quantum

Getting quantum-ready starts with crypto-agility

The quantum threat to cryptography is years away — but the data it will expose is being captured today. Preparation is a present-day task.

18 February 2026 4 min read

Have a hard problem in financial technology?

Whether you are shaping a strategy, proving a concept or rescuing a programme, we would like to hear about it.