Posts

Showing posts with the label NCA

Can You Actually Measure Digital Sovereignty? :The Sovereignty Stack : Part 5 — Series Finale

Image
The Sovereignty Stack // Part 5 — Series Finale Can You Actually Measure Digital Sovereignty? Can you identify the five technology dependencies your organisation would struggle most to replace? Not the five most expensive. Not necessarily the five most critical applications. The five dependencies where your organisation has the least strategic choice — where changing direction would be most costly, most disruptive, or most time-consuming. Most organisations can tell you where their applications run. They can tell you their cloud providers, their identity platform, their AI services. What they often cannot answer is the harder set of questions: Who ultimately controls those dependencies? How replaceable are they? And what would it actually take to leave? That is the difference between knowing your technology estate and understanding your sovereignty posture. And if digital sovereignty is an architectural property — which is the premise this series has...

Interoperability Is Not Enough — The Architecture of Strategic Choice: The Sovereignty Stack, Part 4

Image
The Sovereignty Stack // Part 4 Interoperability Is Not Enough — The Architecture of Strategic Choice Your Kubernetes strategy may be portable. Your service probably is not. A container can move between environments. But the identity model, secrets management, managed database, observability stack, API gateway, and operational knowledge that make that container a functioning service — those do not move automatically. In many cases, they do not move easily at all. You moved the workload. You did not necessarily move the capability. And that distinction sits at the heart of a question Enterprise Architecture rarely asks clearly enough. Does interoperability actually give us strategic choice — or just the appearance of it? After the first three parts of this series, the most common question from readers has been whether interoperability belongs under Platform Sovereignty or Standards Sovereignty. The answer is that it belongs across the entire stack — b...

Who Controls the Intelligence? An Enterprise Architecture Guide to AI Sovereignty — The Sovereignty Stack, Part 3

Image
The Sovereignty Stack // Part 3 AI Sovereignty — When Enterprise Intelligence Becomes a Strategic Dependency Most organisations believe their AI strategy begins with choosing a model. Which one performs best on their benchmarks. Which provider offers the most competitive pricing. Which API integrates most cleanly into existing systems. Those are reasonable questions. They are also the wrong place to start. The more consequential question — the one most architecture governance processes have not yet asked — is a different one entirely. "Can we ever leave?" Because the next generation of vendor lock-in is unlikely to be infrastructure. It will be something harder to see and significantly harder to migrate. It will be enterprise intelligence itself — and understanding what that means is what this article is about. 01 — Why AI Is Different From Every Platform Shift That Preceded It Cloud computing changed where software runs. Virtualisation...

The Essential Cybersecurity Controls — Structure, Scope, and How Everything Else Builds on It

Image
NCA Framework Family // ECC Deep Dive The Essential Cybersecurity Controls — Structure, Scope, and How Everything Else Builds on It Every conversation about NCA compliance eventually comes back to the ECC. It is the document that defines what "baseline" means in Saudi Arabia's cybersecurity regulatory landscape — and understanding it properly is the difference between a compliance programme that holds up under scrutiny and one that has structural gaps its team may not even know about. This piece walks through what the ECC actually is, how its five domains are structured, and — most importantly — how it functions as the shared foundation for every other NCA framework. The short version: The ECC is the mandatory cybersecurity baseline every in-scope organisation must meet. CSCC, CCC, OTCC, DCC, and TCC are all built on top of it. Compliance with any specialised framework presupposes ECC compliance — it does not replace it. 01 — What the ...