INSIGHTS · FIELD NOTES
Short-form observations. Across AI, Cybersecurity, Cloud/Edge, IoT, and Blockchain.
Field Notes are pillar-anchored observations from active NexITC practice — regulatory context, technical patterns, and market signals across the five pillars the practice publicly commits to on the Solutions pages.
15 of 15 Field Notes
What the UAE Agentic AI Mandate actually requires (and what it doesn't)
The Mandate is a services-portfolio sequencing problem, not an enterprise architecture problem. Vendor proposals typically miss this distinction. Here's what the Mandate actually requires — and what it doesn't.
Practice Lead — AI
1 September 2026 · 5 MIN READ
- agentic-ai
- mandate-readiness
- federal-compliance
Five frameworks, one control set: de-duplicating UAE compliance obligations
UAE enterprise cybersecurity typically spans five overlapping frameworks. Control overlap runs 65-80%. Consolidating the overlap into a single control set with framework-specific overlays cuts audit preparation cost and reduces implementation duplication.
Practice Lead — Cybersecurity
1 September 2026 · 6 MIN READ
- compliance
- adhics-v2
- nesa
Provenance without hype: DLT for trade documents that works
Roughly half of blockchain-for-trade-documents feasibility scans conclude that distributed ledger is not the right primitive. The integrity requirements are real; distributed consensus is often not what those requirements need. Here's how to tell the difference.
Practice Lead — Blockchain
1 September 2026 · 6 MIN READ
- dlt
- provenance
- integrity
Governance-first agentic AI: an evaluation harness playbook
Enterprise-grade agentic platforms are largely capability-commoditised. The differentiator is governance — and most enterprises evaluate governance too late in the procurement cadence. Here's the harness that surfaces the gaps before contract signature.
Practice Lead — AI
1 September 2026 · 6 MIN READ
- agentic-ai
- ai-governance
- vendor-evaluation
Vendor-neutral platform selection: the scorecard we actually use
Capability checklists reward feature counts. Demo-driven processes reward sales engineering. Neither reliably produces the right platform for the enterprise's specific requirements. Here's the weighted scorecard NexITC uses instead.
Practice Lead — AI
1 September 2026 · 6 MIN READ
- ai-governance
- vendor-neutrality
- vendor-evaluation
What an ADHICS v2 inspection actually asks for
Beyond the checklist-level control inspection, ADHICS v2 inspectors probe on specific dimensions — access management scrutiny, clinical data protection depth, third-party access controls, incident response readiness. Here's what the inspection actually covers and how to prepare.
Practice Lead — Cybersecurity
1 September 2026 · 7 MIN READ
- compliance
- adhics-v2
- control-mapping
Zero trust without the rip-and-replace: a staged UAE reference path
Zero Trust proposals typically arrive as 18-24 month transformation programmes or vendor-led platform replacements. Most UAE enterprises can achieve inspection-ready Zero Trust posture through a staged path that preserves existing architecture. Here's the reference.
Practice Lead — Cybersecurity
1 September 2026 · 6 MIN READ
- zero-trust
- control-mapping
- practice-approach
Consolidating four observability estates without a big-bang cutover
Four observability estates. Four vendor contracts. Fragmented signal, duplicated instrumentation, no unified incident detection. The staged consolidation approach delivers unified signal within 4-6 months without replacing underlying estates.
Practice Lead — Cloud/Edge
1 September 2026 · 6 MIN READ
- observability
- practice-approach
Sovereign landing zones for CBUAE-supervised entities: a design checklist
Hyperscaler UAE region availability alone is not sovereignty for CBUAE-supervised entities. Sovereignty is a design posture across multiple architectural dimensions. Here's the ten-dimension design checklist that satisfies supervisory expectations.
Practice Lead — Cloud/Edge
1 September 2026 · 7 MIN READ
- sovereign-cloud
- cbuae-guidance
- landing-zones
Why one-off cloud cost optimisation decays in three quarters
Optimisation reports identify 25-35% waste in Quarter 1. By Quarter 4, spend has drifted back to within 5-10% of baseline. The decay is structural, not operational — and the alternative is continuous governance operations, not a better report.
Practice Lead — Cloud/Edge
1 September 2026 · 6 MIN READ
- finops
- retainer-discipline
- practice-approach
Designing edge estates for failure first: heat, dust, and dropped links
Practice Lead — IoT
1 September 2026 · 5 MIN READ
- edge-reliability
- practice-approach
The digital twin question nobody answers: which decision does it improve?
Practice Lead — IoT
1 September 2026 · 6 MIN READ
- digital-twin
- practice-approach
- vendor-evaluation
Purdue levels and the IT/OT conversation that actually works
Practice Lead — IoT
1 September 2026 · 7 MIN READ
- ot-security
- purdue-levels
- practice-approach
What a VARA examiner actually asks about your smart contracts
Practice Lead — Blockchain
1 September 2026 · 7 MIN READ
- vara
- integrity
- compliance
Tokenizing UAE real estate: where the legal claim meets the ledger
Practice Lead — Blockchain
1 September 2026 · 7 MIN READ
- tokenization
- integrity
Have a specific question these Field Notes touch on?
Book a clinic. Practice Lead attends. Field Notes are patterns from active practice; a clinic conversation is where the pattern meets your specific situation.
