Advisory

Technology where confidentiality is part of the service.

Trusts, family offices, law firms and private advisory groups work with information that cannot be treated like ordinary company data. Privacy, continuity and control are part of what their clients are paying for. I think of these as high-discretion environments, and the work I do sits almost entirely inside them.

In such a place a technology decision is also a decision about who can see the information, where it is allowed to travel, how long the organisation could run without a given supplier, and whether recovery is real or merely assumed. Most of these organisations hold decades of confidential records on systems designed before any of those questions were asked of them.

The aim is not to lock everything down. Good control is what lets an organisation move quickly and be confident about it, rather than move carefully and hope.

When people call

Ten situations that usually prompt the call. Most of them are the point at which an organisation decides judgement is the scarce thing, not capacity.

  • A technology decision is approaching that will be expensive to reverse.
  • The organisation has outgrown the technology model it grew up with.
  • There is a gap at the top of the technology function, planned or otherwise.
  • A transformation has stalled and nobody can say precisely why.
  • AI is being adopted faster than anyone has decided what it may see or do.
  • Data is fragmented, sensitive, or both, and reporting has become an act of faith.
  • A principal or board wants an independent read, not a vendor's.
  • A confidential environment needs modernising without increasing exposure.
  • An acquisition or investment carries material technology risk.
  • Dependence on one supplier, or on systems nobody wants to touch, has quietly become a strategic question.
A headland from the air, sea fog rolling in across it
Confidentiality is not a setting somebody switches on. It is the shape of the whole thing.
What the work consists of

Executive work rather than delivery. The distinction matters: the value is in the decision and the structure around it, not in writing the code.

Diagnosis

Establishing what is actually true about the estate, the risk and the dependencies before anyone proposes a solution.

Decision support

Framing consequential choices for principals and boards so the trade-offs are legible without requiring them to become technologists.

How it all fits together

Deciding where systems run, what information each may reach, which suppliers are involved, what happens if one of them becomes unavailable, and who is accountable for each part once the consultants have gone. In the profession that is called the architecture and the operating model. In practice it is the way people, systems, suppliers and decisions fit together day to day.

Governance and technology risk

Security, privacy, identity and AI governance treated as one domain rather than four committees.

Direction and oversight

Setting the path for a programme, choosing vendors, and holding delivery to it without absorbing the delivery itself.

AI and data direction

Where AI belongs, where it does not, what the data layer has to be first, and what authority a system may hold.

How mandates are usually shaped

Four shapes account for most of it. Which one applies is usually obvious once the situation is described.

Ongoing senior advice

Advisory technology leadership

Continuing senior judgement for an organisation that does not need, or cannot justify, a permanent executive in the role.

Leadership for a defined period

Interim leadership and resets

A defined period covering an executive gap, a modernisation, a stalled programme or an operating-model change, with a stated end.

A second opinion before an important decision

Board and principal advice

An independent view of what is being proposed, what it will cost, what could go wrong, and what I would do instead. On an AI decision, a cloud move, an outsourcing arrangement, a supplier, or an investment with technology in it.

One clearly bounded problem

Bounded mandates

One question, one answer, a fixed scope. A technology assessment, a review of whether the organisation is ready for AI, a test of whether recovery actually works, a technology review after an acquisition, or a reset with a deadline on it.

What happens next

Three steps, and you can stop after any of them.

You do not need to decide in advance what kind of help this is. Describe the situation and the shape usually becomes obvious to both of us.

  1. 1

    A private conversation

    A short description of the situation is enough to start. No preparation, no document, no procurement process. If it is not something I am the right person for, I will say so and point you at who is.

  2. 2

    An independent read of the situation

    I look at what is actually true rather than what the last report said: the decision in front of you, what it depends on, what it will cost to reverse, and where the real risk sits. This is deliberately short.

  3. 3

    A written scope, or a straight answer that none is needed

    If there is work worth doing, you get it in writing: what it covers, how long, what you receive and what it costs. Sometimes the honest answer is that the problem does not need an adviser, and that is a perfectly good outcome.

Nothing about the first two steps commits you to the third.

Curved concrete forms meeting in hard light
Three steps, and the shape of the thing becomes obvious from the first one.
What you end up with

Documents a board can act on.

The work is executive rather than delivery, so what it produces is a decision somebody can defend, written down.

A board decision brief

One consequential choice, framed so the trade-offs are legible without anyone having to become a technologist first.

A technology assessment

What the estate, the risk and the dependencies actually are, before anyone proposes a solution.

A ninety-day reset plan

What moves, in what order, with what has to be true before each step.

A supplier recommendation

Which one, why, what it costs to leave, and what happens if they become unavailable.

A technology due-diligence memorandum

For an acquisition or an investment: what is real, what is claimed, and what the buyer inherits.

An AI authority model

What a system may see, what it may suggest, what it may carry out on its own, and who is answerable for each.

A programme recovery plan

For something that has stalled: why it stalled, and the smallest change that restarts it.

What private offices actually worry about

Rarely stated as technology problems. Almost always solved as technology problems.

Getting to trusted information quickly

A question about a file from fifteen years ago should not take three people and a morning.

Not depending on one person's memory

Institutional knowledge that lives in a long-serving employee's head is a continuity risk with a retirement date attached.

Reporting that holds up

Entity and portfolio reporting assembled by hand is slow, and the errors are invisible until they are expensive.

Keeping control of suppliers

Knowing who processes what, where, under what terms, and how quickly any of them could be replaced.

Using AI without leaking anything

The confidentiality obligation does not relax because the tool is useful.

Continuity when people change

Systems, access and knowledge surviving a departure, an illness or a succession.

A hillside seen through heavy fog, its outline barely readable
Discretion is not secrecy. It is knowing exactly what is visible, to whom.

Principal and household exposure

The personal side of the same problem, handled with the same discretion as the institutional side: assessment of where a principal and household are exposed, identity and privacy design, secure remote and travel access, review of home and personal technology, provider selection, and incident-readiness planning. Where specialist protection providers are involved, the work is coordination with them.

It does not include physical protection, monitoring around the clock, managed detection, digital forensics or incident response. Those are different disciplines and are named here so nobody assumes otherwise.

From one engagement in this sector:

90 daysTo retire an ageing estate before a failure forced the decision
Hours to secondsTo find a document in an archive spanning decades
MostOf the intended users working in the new systems inside a month

A substantial share came off the annual licensing bill, and recovery was demonstrated through a ransomware exercise rather than assumed. From one engagement, anonymised.

Start with the problem, not the service.

You do not need to decide in advance whether this is advice, an interim role or a single review. Describe the situation and the shape becomes obvious.