Technology Radar

Where we would put our own money and where we would not, across techniques and platforms. Every placement is labelled as measured, a dated obligation, or a judgement call with no base rate.

Where we would put our own money, and where we would not. Reviewed 2026-08-10.

RingEntriesWhat it means
ADOPT8We use this and would defend it in a review. The evidence is strong enough that not doing it needs a reason.
TRIAL2Worth running for real on something that matters, with a decision date. Not a pilot that lives forever.
ASSESS1Understand it, keep a view, do not build a programme on it yet.
HOLD7Do not start anything new here. Existing use may be fine; new commitment is the thing being advised against.

How to read it

A radar is a set of opinions, and most published ones hide that behind a diagram — a reader cannot tell which placements rest on evidence and which rest on taste. Every entry here is labelled one of three ways, so you can dismiss our judgement without dismissing our data:

  • Measured — 9 entries, each citing a figure we have published, with the page it is on
  • Dated obligation — 1, where the placement is not advice at all but a date already in force
  • Judgement call — 8, where we have no base rate and say so rather than implying one

Placements we could not defend are absent rather than padded. A radar is more useful at twenty defensible entries than sixty confident ones, and the temptation runs entirely the other way.

HOLD does not mean rip it out. It means do not make new commitments here without pricing the alternative first. Several HOLD entries describe things that are perfectly fine to keep running.

ADOPT

We use this and would defend it in a review. The evidence is strong enough that not doing it needs a reason.

Techniques

Query-time permission evaluation

Filtering at index time is faster and wrong. Access lists change and indexes lag, so somebody who left the finance team on Monday keeps getting finance documents until the connector re-crawls on Thursday -- with every component working exactly as designed. Re-evaluating the access list against the live identity at query time closes that window at the cost of a round trip.

Measured. 30 of 30 adversarial permission cases pass, including a group revoked mid-session, which an index-time filter serves until the next crawl /trust/benchmark/

Techniques

Retrieval with citations, no generation in the request path

For factual enterprise questions, returning the passage and its source cannot invent a figure. It also cannot combine two documents into an answer, which is a real limitation and the honest trade. Where a wrong number is expensive -- licensing, regulatory dates, contract terms -- that trade is worth taking.

Measured. Our own engine measured at 100% top-3 retrieval and 75% refusal accuracy, with the failures published /trust/benchmark/

Techniques

Patch SLAs set by exploitation window, not by calendar

Exploitation has overtaken stolen credentials as the top way in. That inverts the usual prioritisation, where identity controls get the budget and patching gets a monthly window. Internet-facing systems need their own SLA, separate from the general estate and reported separately.

Measured. Vulnerability exploitation, 31%, is the top initial access vector -- the first time it has overtaken credentials /research/cybersecurity-readiness/

Techniques

AI interaction disclosure for EU users

Not a recommendation. A person interacting directly with an AI system must be told so, and the duty is already in force. It is usually discovered during a customer's procurement review rather than during a compliance programme.

Dated obligation, set by European Union. 2026-08-02: EU AI Act Article 50 disclosure and marking duties in force /ai-company/ai-product/sop/

Techniques

A named individual accountable per AI system

A committee is not accountable, because accountability that is shared is absent at the moment it is needed. The test is simple: when a model produces a harmful output, who decided it could ship. A role title is an acceptable answer; a committee is not.

Judgement call — no base rate. A governance position, not a measured one.

Techniques

Timed full restore to a clean environment

A DR exercise is not a restore. Restores fail for mundane reasons -- an unmapped dependency, a credential held in the vault that is itself in the failed site, a runbook written for an architecture two migrations ago -- and none of them are visible until it is attempted. Publish the tested time, not the target.

Judgement call — no base rate. A statement about evidence rather than probability: an untested restore has never demonstrated that it works. No figure is needed or offered.

Techniques

Just-in-time third-party access

Standing supplier accounts persist after projects end, get shared inside the supplier, and sit outside your joiners-movers-leavers process because the leaver is not your employee. Expiry by default removes an entire class of access you are not watching.

Judgement call — no base rate. We have not published a figure on third-party breach involvement, so none is quoted.

Techniques

Licensed inventory of non-production environments

Dev, test, UAT and SIT are where entitlement quietly breaks: environments cloned for a project and never decommissioned, developer editions on shared test rigs, UAT running production data. None of it is malicious and all of it is billable at audit.

Judgement call — no base rate. No base rate for how often this is found. Raised because the failure is structural -- non-production is provisioned by people who are not tracking entitlement.

TRIAL

Worth running for real on something that matters, with a decision date. Not a pilot that lives forever.

Techniques

Reviewing workload placement on evidence, including moving back

Repatriation has stopped being an admission of failure and become an ordinary option. Run it as a real evaluation on one workload with a decision date, measuring cost per unit of work rather than total spend -- the metric most organisations do not have, which is why the original business case is never revisited.

Measured. 86% of CIOs now plan to move workloads back from public cloud, the highest recorded /research/cloud-adoption/

Platforms

Technically enforced data residency

Most residency commitments are contractual: a clause saying data stays in a region. Enforced residency means the system cannot write outside it even when misconfigured. Buyers routinely accept the first believing they bought the second. For regulated workloads in the Gulf this is worth establishing properly now rather than during an audit.

Measured. The UAE has three non-overlapping regimes -- federal, DIFC and ADGM -- and which applies is decided by trade licence, not office address /b2b/uae/

ASSESS

Understand it, keep a view, do not build a programme on it yet.

Techniques

Autonomous agents in production

The gap between pilot and production is the whole story, and the reported blockers are data access, ownership and integration -- organisational problems that another pilot does not solve. Understand the technology, keep a view, and do not fund a programme on the assumption that a working demo is most of the way there.

Measured. 88% pilot-to-production failure; 57.3% of surveyed agent engineers run agents in production, from a population self-selected for being further ahead /research/ai-agent-adoption/

HOLD

Do not start anything new here. Existing use may be fine; new commitment is the thing being advised against.

Techniques

Index-time permission filtering

The same point from the other side. It is the default in most enterprise search products because it benchmarks well, and it is the mechanism behind the leak class that matters most: a document served to someone whose access was revoked days ago, with no error anywhere.

Judgement call — no base rate. Stated as a design consequence rather than a statistic. We have published no incident data and will not imply we have.

Techniques

Uncited LLM answers over enterprise content

A generated answer with no traceable source is unauditable, and in a regulated context that is disqualifying on its own. The failure is not that models are wrong often; it is that when they are wrong, nothing in the output distinguishes it from when they are right.

Judgement call — no base rate. We have published no hallucination rate for third-party systems and will not quote one we did not measure.

Techniques

Agents with write access to production systems

An action layer inherits every weakness of the permission model beneath it and multiplies the consequence. Read the wrong document and you have a disclosure; act on it and you have an outage. This is on hold for us too -- we have deliberately not built one, and we would not advise a client to buy one from anybody whose permission model they have not inspected.

Judgement call — no base rate. A consequence argument. No figure offered.

Techniques

MFA with documented exceptions

Partial coverage of an authentication control is defeated by finding the gap, and the gap is discoverable. Break-glass accounts, service accounts with interactive logon, and the one legacy system that could not support it are where exceptions live. The control reads as present in the risk register and is not effective.

Judgement call — no base rate. Structural argument. No base rate published.

Platforms

New commitment to VMware under Broadcom terms

Perpetual licences are gone and the minimum order punishes small estates hardest, which inverts the usual assumption that migration is a large-enterprise problem. Existing use may well be fine; this is advice against new commitment without pricing the alternative first.

Measured. General minimum order of 72 cores, raised from 16 in 2025; reported list roughly $350-$400 per core per year /knowledge/licence-optimisation/

Platforms

Per-employee licence metrics

A metric that scales with hiring rather than usage breaks the normal optimisation instinct entirely: removing the product from most machines saves nothing. It is a tax on a successful year, and it is rarely modelled against the headcount plan before signature.

Measured. Oracle Java rises with hiring whether or not usage does /knowledge/licence-optimisation/

Platforms

Running past a support end date on extended support

Extended support is a purchase, not a plan, and it has an end date of its own. With exploitation now the leading entry vector, the subset of your estate that will never be patched is the subset where exposure accumulates rather than decays.

Measured. Vulnerability exploitation, 31%, top initial access vector in 2026 /research/cybersecurity-readiness/

Cadence

Reviewed quarterly. An entry that has not been reviewed since its stated date is stale, and the page says so rather than presenting an old view as current.

Educational and informational. Not legal, financial or investment advice. Vendor terms change and are specific to your agreement — confirm anything commercial in writing with the vendor before acting on it.