top of page

JAMES F.
KENEFICK

JAMES' BLOG
Leadership and Technology Insights and News


Big Enough to Matter, Small Enough to Care: Why Scale Is a Strategy, Not a Size
Growing companies often assume scale is a number to cross. This article reframes scale as a deliberate strategy built on stability paired with speed, decisions kept close to the customer, protected employee experience, and continuous reinvention, not a milestone measured in headcount.
Sep 28


The Future of Work Is Not Fewer People. It Is Better-Orchestrated People.
Every headcount conversation eventually asks how many fewer people AI will require. Wrong question. This article shows why the organizations pulling ahead are the ones orchestrating small teams to direct much larger AI-driven output, and what boards should require to get there.
Sep 22


How Private Equity and Venture Investors Should Evaluate AI-Enabled Operators
Nearly every pitch deck now claims an AI advantage. This article gives private equity and venture investors a four-question diligence framework, proprietary data, operability, governance, and economics, to separate genuine AI-enabled operators from a polished demo before signing.
Sep 21


The Rise of the AI-Native Service Desk
For thirty years the IT service desk ran on the ticket. That model is being replaced by agentic AI that resolves requests end to end instead of routing them. This article explains what makes a service desk genuinely AI-native, why it is rising now, and what executives should require before scaling it.
Sep 9


Agentic AI Makes Cybersecurity More Urgent, Not Less
As agentic AI scales across the enterprise, every autonomous agent becomes a new non-human identity with credentials someone must secure and govern. This article explains why agentic AI cybersecurity risk grows more urgent, not less, as agents gain decision authority, and what boards should ask before scaling agent deployments further across the business.
Aug 31


The 2026 AI Governance and Control Checklist for Boards
Most boards can describe their AI ambitions but cannot document their AI controls. This 2026 governance and control checklist walks directors and executives through the eight areas where oversight most often breaks down, from data readiness to human oversight, and shows what a board should be able to produce as evidence, not just discuss as policy, before the next AI decision reaches the table.
Aug 26


From SLA to Business Assurance: Rethinking Managed Services for the AI Era
Service level agreements were built to measure uptime, not business outcomes, and that gap is now a board-level liability in the AI era. This article explains why managed services must shift from SLA compliance to business assurance: a model built on outcomes, resilience, governance, and accountability, and what CIOs and boards should demand from every managed services partner.
Aug 24


AI Readiness Is Not a Technology Problem. It Is a Management Problem.
Most organizations are not struggling with AI because of the technology itself. They are struggling because governance, accountability, and management discipline have not kept pace with deployment. This article explains why AI readiness is fundamentally an operating model and leadership question, not a procurement one, and lays out what boards and executive teams must do now to close the gap.
Aug 20


Governance at Home: Board Oversight of Executive Personal Risk
Governance at home is the sequel to founder exit timing, applying the same readiness discipline to a risk most boards have never put on an agenda, executive personal exposure. This piece breaks down why boards must treat personal risk with the same rigor as cyber and succession risk, and what oversight actually looks like.
Aug 19


The Personal Perimeter: Where Corporate Cybersecurity Stops
Corporate cybersecurity spend keeps climbing, yet the personal perimeter, home networks, personal devices, and family accounts, sits entirely outside it. This piece breaks down why the tools stop at the office door, what boards should ask about executive exposure, and how to close the gap before it becomes a personal accountability requirement.
Aug 18


The Deepfake CEO: A Board Risk Hiding in Plain Sight
A deepfake CEO fraud incident cost one company twenty five million dollars in a single video call. This piece breaks down why convincing fakes work, what boards should ask about verification controls, and how to build a process that holds even when the face and voice on the call look completely real.
Aug 12


The AI Tool Settings Executives Need to Govern
A popular checklist of AI tool settings promises better results in minutes: model choice, connectors, memory, custom instructions. Most of it is harmless. One setting, granting an AI assistant OAuth access to email and files, is a governance decision that deserves far more scrutiny than a toggle switch usually gets. Here is how to tell the difference.
Aug 6


5 Cybersecurity Frameworks Every Board Should Govern By
Corporate cybersecurity spend keeps climbing, yet the personal perimeter, home networks, personal devices, and family accounts, sits entirely outside it. This piece breaks down why the tools stop at the office door, what boards should ask about executive exposure, and how to close the gap before it becomes a personal accountability requirement.
Jul 28


Healthcare IT Compliance Is a Program, Not a Project
Too many healthcare organizations still treat compliance like a project: finish the assessment, close the gaps, pass the review, move on. That satisfies a plan, not reality. HIPAA is not a once a year checklist; it is a daily operating posture across systems, people, and vendors. This article explains why healthcare IT compliance is a program, and how cadence, ownership, and governance keep the environment defensible as it changes.
Jul 3


From AI to Agentic AI: A Board's Guide to the AI Stack
Artificial intelligence is no longer one capability a company either has or lacks. It is a layered stack that runs from traditional AI through machine learning, deep learning, generative AI, large language models, retrieval augmented generation, and now agentic AI that can act on its own. Each layer carries a different risk profile and a different governance demand, yet many boards still treat all of it as a single line item.
Jun 25
bottom of page