<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Governance Meridian ]]></title><description><![CDATA[Decision-grade governance briefings on cyber, AI, and the African frontier. Transitioning practice from the United States to the continent — for the operators who carry the consequences.]]></description><link>https://www.governancemeridian.com</link><image><url>https://www.governancemeridian.com/img/substack.png</url><title>The Governance Meridian </title><link>https://www.governancemeridian.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 26 Aug 2026 02:22:59 GMT</lastBuildDate><atom:link href="https://www.governancemeridian.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Baliyat Johnson]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[governancemeridian@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[governancemeridian@substack.com]]></itunes:email><itunes:name><![CDATA[Baliyat Johnson]]></itunes:name></itunes:owner><itunes:author><![CDATA[Baliyat Johnson]]></itunes:author><googleplay:owner><![CDATA[governancemeridian@substack.com]]></googleplay:owner><googleplay:email><![CDATA[governancemeridian@substack.com]]></googleplay:email><googleplay:author><![CDATA[Baliyat Johnson]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Name Your Operating Assumptions Before You Name Your Controls]]></title><description><![CDATA[Every control you run is a bet on a condition you have not written down. Write it down first.]]></description><link>https://www.governancemeridian.com/p/name-your-operating-assumptions-before</link><guid isPermaLink="false">https://www.governancemeridian.com/p/name-your-operating-assumptions-before</guid><dc:creator><![CDATA[Baliyat Johnson]]></dc:creator><pubDate>Wed, 03 Jun 2026 07:22:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IHgq!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01f37c67-15e0-4015-a151-6f0c04609aae_1500x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Cyber, AI, and the African Frontier</em></p><p>Issue 02 &#183; ASMM #1: Foundations &#183; <strong>Name Your Operating Assumptions Before You Name Your Controls</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.governancemeridian.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Governance Meridian ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><em>Every control you run is a bet on a condition you have not written down. Write it down first.</em></p><p>A bank in Lagos buys a second internet line. Two carriers, two contracts, two invoices, redundancy on paper. Eighteen months later both lines go dark for nine hours on the same afternoon, because both carriers route through the same submarine cable, and that cable was cut by an anchor off the coast of the Ivory Coast. The bank did not buy redundancy. It bought the appearance of redundancy, twice. The control was real. The assumption underneath it was wrong, and nobody had written the assumption down where it could be checked.</p><p>This is the failure that the second issue of this publication is about. Not a missing control. A missing assumption. The security programme that fails on contact with operators almost never fails because someone forgot to deploy a tool. It fails because the tool was deployed against a condition that does not hold, and the gap between the assumed condition and the real one was never made visible enough to argue about.</p><h1>The refusal</h1><p>Here is the piece of received framework wisdom this issue refuses: that you start with controls. Almost every imported maturity model opens with a control catalogue or a function list. Identify, Protect, Detect, Respond, Recover. Pick your tier, map your controls, close your gaps. The assumptions that make those controls coherent are left implicit, which is precisely how organisations adopt models that do not match their reality. The catalogue looks complete, so the question of whether it fits never gets asked out loud.</p><p>The African Security Maturity Model inverts this. Edition 1 buried its operating assumptions at the back, where they could not shape the reading. Edition 2 pulled them to the front, ahead of the Postures, ahead of the ten Domains, ahead of every control. The reordering was not cosmetic. It was the single most important structural change between the two editions, because it changes what the reader does first. You do not begin by asking which controls to run. You begin by asking which conditions you are betting on.</p><h1>Six bets you are already making</h1><p>The ASMM names its assumptions across five groups: infrastructure, regulatory, organisational capability, threat environment, and economic and social conditions. You do not need the full instrument to feel the force of the idea. Six bets carry most of the weight, and each one, stated plainly, is the kind of sentence a board has never seen in a security paper.</p><p><strong>Power and connectivity are unreliable but not absent. </strong>Your continuity controls assume intermittent grid power and multiple sources to fall back on. In a sustained conflict zone where every source is gone for weeks, that bet is off, and your Power and Pipe Resilience controls need a different design than the model prescribes.</p><p><strong>Your two carriers may be one carrier. </strong>Redundancy is a bet on divergent upstream paths, not on two logos on two invoices. The Lagos bank lost that bet. Validate the cable, not the contract.</p><p><strong>A meaningful share of your customers cannot read. </strong>Every SMS warning, every text-driven authentication challenge, every phishing-recognition assumption is a bet that the user can read it. For a non-trivial fraction of the continent that bet fails silently, and the customer who cannot read your warning is the customer the fraud economy reaches first.</p><p><strong>The state has legal demand authority over your security function. </strong>Imported frameworks treat lawful demand as a privacy footnote. On most of the continent it is a working condition: call detail records, customer data, intercept assistance, server-room access. Compliance with the law is not the failure. Operating without a documented practice for handling the demand is.</p><p><strong>Your people are physically exposed. </strong>A response runbook that requires a senior engineer to drive to the data centre at three in the morning has quietly assumed they will arrive. In parts of the operating geography that assumption is a real bet with a real failure rate, and it belongs in the runbook, not in the silence around it.</p><p><strong>Fraud is the first threat, not the second. </strong>If your threat model is inherited from a stable jurisdiction, it ranks the nation-state intrusion first and the fraud economy somewhere below. Across most African regulated organisations that ranking is inverted, and the adversary frequently has community ties to the people inside your own building.</p><h1>The Monday-morning exercise</h1><p>Here is the decision you can act on at the start of the week. Before your next control review, before the next tooling renewal, before the next board paper, take one page and write down the six conditions your current programme assumes. Then mark each one against your environment: true, partial, or false. True means the assumption holds and your controls are coherent. Partial means it holds in part and the control needs local adaptation. False means the condition does not exist and the control is running against air.</p><p>This is the ASMM Field Test, compressed to a single sitting. The model&#8217;s own threshold is blunt: if three or more of your core assumptions come back false, you do not adopt the framework as written. You adapt it first, or you find a better reference. The same threshold applies to your existing programme. Three false assumptions is not a tuning problem. It is a programme built for a place you do not operate in.</p><p>The exercise costs an hour. It will not produce a new control. It will produce something more useful: a written record of where your defensible-looking programme is betting on conditions that are not true, which is the one document an external assessor, a regulator, or a sceptical board chair can actually argue with. An assumption you have written down is a gap you can work. An assumption you have left implicit is a gap that works you.</p><p>Next issue moves from the assumptions to the Postures themselves: why they are operating states rather than capability tiers, why an organisation can lose one as well as earn one, and why the weakest critical Domain, not the average, sets the headline. For now, the work is the page.</p><p><em>List the controls and you describe what you have bought. List the assumptions and you find out what you have actually been defending.</em></p><p><strong>&#8212; Baliyat Johnson</strong></p><p><em>CISM, PMP</em></p><p><em>Written from Denver, Colorado &#183; June 03, 2026</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.governancemeridian.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Governance Meridian ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why Africa Will Set Standards, Not Only Adopt Them]]></title><description><![CDATA[A publication for the operators who carry the consequences. Written, for now, from a long way away.]]></description><link>https://www.governancemeridian.com/p/why-africa-will-set-standards-not</link><guid isPermaLink="false">https://www.governancemeridian.com/p/why-africa-will-set-standards-not</guid><dc:creator><![CDATA[Baliyat Johnson]]></dc:creator><pubDate>Thu, 28 May 2026 08:36:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bdbe5de6-26b1-45c2-94a4-87f730090283_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Why Africa Will Set Standards, Not Only Adopt Them</strong></p><p><em>A publication for the operators who carry the consequences. Written, for now, from a long way away.</em></p><p>This is the first issue of The Governance Meridian. It exists because of a specific dissatisfaction, and the dissatisfaction is worth naming before the work begins.</p><p><strong>Why this publication exists</strong></p><p>For most of the past two decades, the dominant cyber and AI governance frameworks have been written by people who do not work where they are read. The lineage is recognizable. A Western federal agency, an international standards body, or a large consultancy synthesizes practice from regulated industries in stable jurisdictions, packages it into a control catalogue or a maturity model, and ships it to the rest of the world as the default reference.</p><p>The frameworks are not wrong. They are not designed for the conditions under which most of the world&#8217;s enterprises actually operate.</p><p>The conditions are these. Power is unreliable. Two redundant ISPs route through the same submarine cable and fail together. Talent that joins does not stay, and a meaningful share of senior security capability operates from outside the country it serves. The principal adversary is not a nation-state APT; it is a fraud economy with community connections to insiders. The principal customer interface is a feature phone, a USSD session, or an agent at a kiosk. The state security services have legal demand authority over the security function. Some staff face physical risk going to work. Several controls in the imported framework assume preconditions that do not exist on the ground.</p><p>The result, repeatedly, is a security program that looks defensible on paper and fails on contact with operators. Boards approve roadmaps that are unimplementable. Regulators inherit framework language that does not anchor to local law. AI deployments outpace governance because the governance was written for a different deployment context. The gap is real and it is widening.</p><p>This publication is one attempt to close part of it, and it begins by being honest about how far that attempt has actually got.</p><p><strong>What this publication is</strong></p><p>The Governance Meridian publishes decision-grade analysis for executives building cyber and AI governance programs at the seam between Western compliance frameworks and African operational reality. The audience is specific: CEOs and boards who approve security expenditure, regional CISOs and Security and Trust Leads, pan-African institutional executives, regulators with cyber and AI portfolios, and investors deploying into emerging markets who need to know what defensible actually looks like.</p><p>The work rests on three pillars.</p><p><strong>Posture and Frameworks.</strong> Serialized treatment of the African Security Maturity Model, a continental reference for cyber and AI security under constraint, structured around ten Domains and five Postures. The model exists because the imported alternatives left two Domains unwritten and several controls beyond reach. The serialization is the long arc of this publication.</p><p><strong>Executive Controls and Procurement Discipline.</strong> Translation of US federal-grade gating practice (FedRAMP, CMMC, demo readiness, vendor governance) into governance controls usable in African regulated environments. The capital is imported; the application is local.</p><p><strong>AI Sovereignty in Practice.</strong> A real-time field log of the ISACA Advanced in AI Security Management certification and its application to African enterprise AI adoption. Built in public. Where AAISM holds up under local deployment reality, it will be written up. Where it does not, that will be written up too.</p><p><strong>What this publication is not</strong></p><p>It is not a curation feed. It will not aggregate other people&#8217;s analysis with light commentary.</p><p>It is not a vendor scorecard or a procurement marketplace. There will be no sponsored placements in the first year, and probably not after.</p><p>It is not a certification cram resource. The AAISM diary will not contain exam tips or study schedules; it will contain the points at which the curriculum holds and the points at which it does not, judged against deployments on the continent.</p><p>It is not a hot-takes channel. Incidents will be analyzed where there is something useful to add, and silence will be the better contribution where there is not.</p><p>And it is not an authority claim from a finished position. I am not writing to you from a server room in Lagos. I am writing from Denver, with the move to the continent underway and the framework I will serialize still ahead of its first real test. The next section says exactly what that means.</p><p><strong>A note on voice, and on what I have not yet earned</strong></p><p>I write from twenty years of project and program leadership across telecommunications, financial services, and enterprise managed security, including SOC and MDR work for clients in regulated industries. I hold the Certified Information Security Manager and Project Management Professional designations, and I am sitting the Advanced in AI Security Management certification this year.</p><p>None of that is the qualification for this publication, and I want to be precise about what is.</p><p>The framework I will serialize here has been put through one deliberate adversarial critique, conducted from the standpoint of a skeptical CISO operating under real constraint. That critique returned findings that were harder to read than they were to write, and the current edition exists because of them. But here is what the edition says about itself, and what I will say to you directly: it has not yet been deployed in a live environment. It has not been reviewed across a range of practitioners. It has not met a real operating floor in Lagos, in Nairobi, or anywhere else. The field has not yet been heard from. I am not going to pretend otherwise, not here, and not in any issue that follows.</p><p>That is the editorial commitment of this publication, and it is the whole of it: describe what is true today, foreshadow what is coming, and never collapse the two. A framework that has survived a stress test of its ideas is not a framework that has survived deployment, and the difference between those two things is exactly the difference this publication exists to respect.</p><p>So the voice will be direct. It will refuse to describe controls that cannot be implemented. It will name the gap when there is one, including the gap between what I have written and what I have proven. It will use the cost-reality numbers a board approves rather than the qualitative language that lets the gap hide. It will treat regression as a managed condition rather than a failure to conceal. Where I am wrong, the correction will be published in the next issue and not buried.</p><p><strong>On the dateline</strong></p><p>You will have noticed it. This issue is written from Denver, Colorado, a publication about a continent I do not yet live on, by someone in the middle of moving there.</p><p>I could have waited until I had landed and opened with an African dateline as though I had always been there. That would have been the first lie, and a publication built on operational honesty cannot afford its first lie to sit on the masthead. So: I am in Denver. The move is underway. When the dateline changes, and it will, you will have watched it happen in real time rather than being asked to take it on faith. That change, when it comes, will be the most honest thing I publish all year, precisely because none of it will have been backdated.</p><p>The same logic governs the framework. You are not being asked to trust a finished, field-proven model. You are being invited to watch one get tested in public, against real environments, and rewritten where the environment wins. If that is not the kind of thing you want to read, this is the right moment to know it.</p><p><strong>What I am asking of you</strong></p><p>Three things, none of them subscription metrics.</p><p>Read with an operator&#8217;s lens. If what I publish would not survive your environment, write back and say so. The framework improves where it is criticized by practitioners outside the author&#8217;s direct line of sight, and the field test it most needs has not yet happened. I am inviting that test explicitly.</p><p>Refer the work to the people in your network who carry the consequences. The audience this publication exists to serve is the working CISO at a Tier-2 bank in Accra, the head of trust at a mid-market fintech in Nairobi, the regulator&#8217;s deputy in Abuja, the board chair in Kigali approving an AI deployment whose risk surface nobody in the room fully understands. If you know that person, the work is for them, and their critique is what turns it from theory into something defensible.</p><p>Hold me to the cadence and to the claims. Weekly anchor essay, monthly AAISM field note, quarterly cost-reality and regulator-watch updates, quarterly field report once I am in-country. If the cadence slips without explanation, that is a regression and I owe you the protocol for it. If a claim outruns the evidence, the same obligation applies.</p><div><hr></div><p>This chapter is a map with the cliffs marked. The territory begins where the dateline changes, and you will be there when it does.</p><p>Subscribe to follow the work, and to watch it get tested.</p><p>&#8212; Baliyat Johnson<br>CISM, PMP<br>Written from Denver, Colorado &#183; May 28, 2026</p><div><hr></div><p></p>]]></content:encoded></item></channel></rss>