top of page

JAMES F.
KENEFICK

JAMES' BLOG
Leadership and Technology Insights and News


Minimum Operable Data: The Hidden Requirement Behind Every Successful AI Initiative
Most AI initiatives fail before they ever reach production, and the cause is rarely the model. This article introduces minimum operable data, the scoped, governed data foundation every AI initiative needs to run reliably, and shows executives exactly what to require of their teams before funding moves from pilot to full production scale.
5 days ago


Agentic AI Makes Cybersecurity More Urgent, Not Less
As agentic AI scales across the enterprise, every autonomous agent becomes a new non-human identity with credentials someone must secure and govern. This article explains why agentic AI cybersecurity risk grows more urgent, not less, as agents gain decision authority, and what boards should ask before scaling agent deployments further across the business.
6 days ago


The 2026 AI Governance and Control Checklist for Boards
Most boards can describe their AI ambitions but cannot document their AI controls. This 2026 governance and control checklist walks directors and executives through the eight areas where oversight most often breaks down, from data readiness to human oversight, and shows what a board should be able to produce as evidence, not just discuss as policy, before the next AI decision reaches the table.
Aug 26


From SLA to Business Assurance: Rethinking Managed Services for the AI Era
Service level agreements were built to measure uptime, not business outcomes, and that gap is now a board-level liability in the AI era. This article explains why managed services must shift from SLA compliance to business assurance: a model built on outcomes, resilience, governance, and accountability, and what CIOs and boards should demand from every managed services partner.
Aug 24


AI Readiness Is Not a Technology Problem. It Is a Management Problem.
Most organizations are not struggling with AI because of the technology itself. They are struggling because governance, accountability, and management discipline have not kept pace with deployment. This article explains why AI readiness is fundamentally an operating model and leadership question, not a procurement one, and lays out what boards and executive teams must do now to close the gap.
Aug 20


Governance at Home: Board Oversight of Executive Personal Risk
Governance at home is the sequel to founder exit timing, applying the same readiness discipline to a risk most boards have never put on an agenda, executive personal exposure. This piece breaks down why boards must treat personal risk with the same rigor as cyber and succession risk, and what oversight actually looks like.
Aug 19


The Personal Perimeter: Where Corporate Cybersecurity Stops
Corporate cybersecurity spend keeps climbing, yet the personal perimeter, home networks, personal devices, and family accounts, sits entirely outside it. This piece breaks down why the tools stop at the office door, what boards should ask about executive exposure, and how to close the gap before it becomes a personal accountability requirement.
Aug 18


The Deepfake CEO: A Board Risk Hiding in Plain Sight
A deepfake CEO fraud incident cost one company twenty five million dollars in a single video call. This piece breaks down why convincing fakes work, what boards should ask about verification controls, and how to build a process that holds even when the face and voice on the call look completely real.
Aug 12


The AI Security Playbook Has 20 Threats. 16 Are New.
A widely shared AI security playbook maps twenty enterprise AI threats, from prompt injection to shadow AI. Sixteen of them describe risks that simply did not exist in a pre-AI security program. Here is which threats your existing controls already cover, which ones require new governance entirely, and the four questions every board should ask before approving the next AI deployment.
Aug 10


The AI Tool Settings Executives Need to Govern
A popular checklist of AI tool settings promises better results in minutes: model choice, connectors, memory, custom instructions. Most of it is harmless. One setting, granting an AI assistant OAuth access to email and files, is a governance decision that deserves far more scrutiny than a toggle switch usually gets. Here is how to tell the difference.
Aug 6


Cybersecurity Has 12 Domains. Boards Oversee Two.
Most boards equate cybersecurity with firewalls and a compliance checklist, covering perhaps two of the twelve domains a mature program actually requires. API security, third-party risk, and disaster recovery rarely make the agenda, yet they are where the next material incident is most likely to originate. Here is the full map and the four questions every board should be asking.
Aug 5


How to Explain Agentic AI to Your Board
Most executives conflate agentic AI with chatbots or automation, and the confusion shows up first in governance, not technology. Here is a four-layer model, moving from AI and ML through generative AI and simple agents to full agentic autonomy, that gives boards and leadership teams a shared, accurate vocabulary before they approve the next AI investment.
Jul 30
bottom of page