01 Sovereignty
Supplier dependence needs an exit plan, not a hope
Most organisations can name their critical suppliers. Far fewer can say which law those suppliers answer to, or what leaving would cost.
I map that dependence, test it against the realistic scenarios, and turn the result into procurement terms and exit plans that would hold up on the day they are needed.
02 AI
AI governance lives or dies on the record it keeps
A board can delegate the building of an AI system. It cannot delegate knowing what that system decides, on whose data, and under whose law.
I set up the controls around AI in use: approved tools, data boundaries, decision logs and the change control that keeps models honest after launch.
03 Certification
Certification should describe how you already work
ISO 27001 and Cyber Essentials Plus are worth having when the controls behind them run every day, not just in audit week.
I run those programmes as working controls, with the evidence captured as the work happens.
04 Data protection
The Data Protection Officer's desk is mostly judgement
Impact assessments, rights requests, processor contracts and international transfers under UK and EU GDPR.
The law sets the frame. The judgement lies in applying it to programmes that collect data from people in very different circumstances, in many jurisdictions at once.
05 High-risk settings
Security has to work where the ground is unstable
Staff travel, devices get seized, connections drop and local law changes quickly.
Designing for that reality, rather than for a head office, is most of the job in international development, and it is the experience I bring to everything else on this page.
06 Advisory
Advisory enquiries go through AltLibre
If one of these problems is yours, AltLibre is where I take on advisory conversations about digital sovereignty.
07 Contact
You can write to me directly
I read everything that arrives, and I reply to anything that is not selling me something. LinkedIn works too, if you would rather start there.
adrian at altlibre dot com