Samuel Rasmussen

The Strange Afterlife of a Regulation

Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.

The Wildfire Doesn't Have to Reach You to Disrupt Your Business

On the morning of July 16, I looked outside in Milwaukee and the city seemed to have misplaced its horizon. The light had that strange, dirty cast that wildfire smoke gives it, and the air smelled faintly burned. This was Wisconsin, not a community evacuating ahead of a fire line. Nothing nearby was burning. The fires were hundreds of miles away, in northern Minnesota near the Boundary Waters and across Canada. Yet by then, the distinction between where the disaster was happening and where its consequences were being felt had become almost meaningless.

Why Ethical Culture Is Becoming Measurable

The Department of Justice's Evaluation of Corporate Compliance Programs contains a question that would have sounded almost eccentric a generation ago. Prosecutors are instructed to ask whether a company has measured its culture. Not whether it published a code of conduct polished to a corporate sheen, nor whether employees dutifully completed another round of ethics training before the deadline, but whether the organization possesses evidence, actual evidence, about the beliefs and behaviors that determine what happens after the policy manual closes and the meeting adjourns.

The End of Point-in-Time Security

The most dangerous assumption in enterprise security is rarely the one anyone remembers making. It settles quietly into the organization, becoming less a decision than a background condition, until eventually everyone begins treating a moment in time as though it were a durable fact. A system was patched, supplier was assessed, and administrator's access was reviewed. The penetration test found nothing significant and the audit closed without material findings. The evidence exists, neatly timestamped and carefully preserved, carrying all the reassuring weight that documentation has always carried. Then the environment changes around it and almost never dramatically.

Sustainability After Net Zero: The Rise of the Resilience Economy

There is a particular kind of language that survives long after the conditions that produced it have changed. It remains in annual reports, in strategy decks, in conference agendas and regulatory consultations, carrying forward assumptions that no longer quite fit the world it describes. Sustainability increasingly feels like one of those words. We still use it. We still build departments around it. We still publish targets beneath its banner.

Book Review: When Governance Outpaces Capability

There is a peculiar imbalance taking shape inside many organizations. Over the past two years, companies have assembled AI governance committees, drafted acceptable-use policies, updated risk registers, and launched internal working groups dedicated to understanding the implications of artificial intelligence. Compliance teams have studied emerging regulations. Privacy officers have debated data-sharing restrictions. Boards have asked increasingly pointed questions about oversight, accountability, and risk.

The Operational Reality Behind Europe’s Simplification Agenda

At one point during the scramble around the EU Deforestation Regulation, people in compliance departments were trying to determine whether a shipment of cattle-derived products could be reliably traced back to land parcels that, in some cases, had changed ownership multiple times across jurisdictions with inconsistent land registries and uneven digital infrastructure. There were meetings about satellite imagery. Meetings about geolocation coordinates. Meetings about whether suppliers in rural regions would even understand the documentation requests they were suddenly receiving from European multinationals. Entire teams found themselves discussing forests they would never see.