Why Africa Will Set Standards, Not Only Adopt Them
A publication for the operators who carry the consequences. Written, for now, from a long way away.
This is the first issue of The Governance Meridian. It exists because of a specific dissatisfaction, and the dissatisfaction is worth naming before the work begins.
Why this publication exists
For most of the past two decades, the dominant cyber and AI governance frameworks have been written by people who do not work where they are read. The lineage is recognizable. A Western federal agency, an international standards body, or a large consultancy synthesizes practice from regulated industries in stable jurisdictions, packages it into a control catalogue or a maturity model, and ships it to the rest of the world as the default reference.
The frameworks are not wrong. They are not designed for the conditions under which most of the world’s enterprises actually operate.
The conditions are these. Power is unreliable. Two redundant ISPs route through the same submarine cable and fail together. Talent that joins does not stay, and a meaningful share of senior security capability operates from outside the country it serves. The principal adversary is not a nation-state APT; it is a fraud economy with community connections to insiders. The principal customer interface is a feature phone, a USSD session, or an agent at a kiosk. The state security services have legal demand authority over the security function. Some staff face physical risk going to work. Several controls in the imported framework assume preconditions that do not exist on the ground.
The result, repeatedly, is a security program that looks defensible on paper and fails on contact with operators. Boards approve roadmaps that are unimplementable. Regulators inherit framework language that does not anchor to local law. AI deployments outpace governance because the governance was written for a different deployment context. The gap is real and it is widening.
This publication is one attempt to close part of it, and it begins by being honest about how far that attempt has actually got.
What this publication is
The Governance Meridian publishes decision-grade analysis for executives building cyber and AI governance programs at the seam between Western compliance frameworks and African operational reality. The audience is specific: CEOs and boards who approve security expenditure, regional CISOs and Security and Trust Leads, pan-African institutional executives, regulators with cyber and AI portfolios, and investors deploying into emerging markets who need to know what defensible actually looks like.
The work rests on three pillars.
Posture and Frameworks. Serialized treatment of the African Security Maturity Model, a continental reference for cyber and AI security under constraint, structured around ten Domains and five Postures. The model exists because the imported alternatives left two Domains unwritten and several controls beyond reach. The serialization is the long arc of this publication.
Executive Controls and Procurement Discipline. Translation of US federal-grade gating practice (FedRAMP, CMMC, demo readiness, vendor governance) into governance controls usable in African regulated environments. The capital is imported; the application is local.
AI Sovereignty in Practice. A real-time field log of the ISACA Advanced in AI Security Management certification and its application to African enterprise AI adoption. Built in public. Where AAISM holds up under local deployment reality, it will be written up. Where it does not, that will be written up too.
What this publication is not
It is not a curation feed. It will not aggregate other people’s analysis with light commentary.
It is not a vendor scorecard or a procurement marketplace. There will be no sponsored placements in the first year, and probably not after.
It is not a certification cram resource. The AAISM diary will not contain exam tips or study schedules; it will contain the points at which the curriculum holds and the points at which it does not, judged against deployments on the continent.
It is not a hot-takes channel. Incidents will be analyzed where there is something useful to add, and silence will be the better contribution where there is not.
And it is not an authority claim from a finished position. I am not writing to you from a server room in Lagos. I am writing from Denver, with the move to the continent underway and the framework I will serialize still ahead of its first real test. The next section says exactly what that means.
A note on voice, and on what I have not yet earned
I write from twenty years of project and program leadership across telecommunications, financial services, and enterprise managed security, including SOC and MDR work for clients in regulated industries. I hold the Certified Information Security Manager and Project Management Professional designations, and I am sitting the Advanced in AI Security Management certification this year.
None of that is the qualification for this publication, and I want to be precise about what is.
The framework I will serialize here has been put through one deliberate adversarial critique, conducted from the standpoint of a skeptical CISO operating under real constraint. That critique returned findings that were harder to read than they were to write, and the current edition exists because of them. But here is what the edition says about itself, and what I will say to you directly: it has not yet been deployed in a live environment. It has not been reviewed across a range of practitioners. It has not met a real operating floor in Lagos, in Nairobi, or anywhere else. The field has not yet been heard from. I am not going to pretend otherwise, not here, and not in any issue that follows.
That is the editorial commitment of this publication, and it is the whole of it: describe what is true today, foreshadow what is coming, and never collapse the two. A framework that has survived a stress test of its ideas is not a framework that has survived deployment, and the difference between those two things is exactly the difference this publication exists to respect.
So the voice will be direct. It will refuse to describe controls that cannot be implemented. It will name the gap when there is one, including the gap between what I have written and what I have proven. It will use the cost-reality numbers a board approves rather than the qualitative language that lets the gap hide. It will treat regression as a managed condition rather than a failure to conceal. Where I am wrong, the correction will be published in the next issue and not buried.
On the dateline
You will have noticed it. This issue is written from Denver, Colorado, a publication about a continent I do not yet live on, by someone in the middle of moving there.
I could have waited until I had landed and opened with an African dateline as though I had always been there. That would have been the first lie, and a publication built on operational honesty cannot afford its first lie to sit on the masthead. So: I am in Denver. The move is underway. When the dateline changes, and it will, you will have watched it happen in real time rather than being asked to take it on faith. That change, when it comes, will be the most honest thing I publish all year, precisely because none of it will have been backdated.
The same logic governs the framework. You are not being asked to trust a finished, field-proven model. You are being invited to watch one get tested in public, against real environments, and rewritten where the environment wins. If that is not the kind of thing you want to read, this is the right moment to know it.
What I am asking of you
Three things, none of them subscription metrics.
Read with an operator’s lens. If what I publish would not survive your environment, write back and say so. The framework improves where it is criticized by practitioners outside the author’s direct line of sight, and the field test it most needs has not yet happened. I am inviting that test explicitly.
Refer the work to the people in your network who carry the consequences. The audience this publication exists to serve is the working CISO at a Tier-2 bank in Accra, the head of trust at a mid-market fintech in Nairobi, the regulator’s deputy in Abuja, the board chair in Kigali approving an AI deployment whose risk surface nobody in the room fully understands. If you know that person, the work is for them, and their critique is what turns it from theory into something defensible.
Hold me to the cadence and to the claims. Weekly anchor essay, monthly AAISM field note, quarterly cost-reality and regulator-watch updates, quarterly field report once I am in-country. If the cadence slips without explanation, that is a regression and I owe you the protocol for it. If a claim outruns the evidence, the same obligation applies.
This chapter is a map with the cliffs marked. The territory begins where the dateline changes, and you will be there when it does.
Subscribe to follow the work, and to watch it get tested.
— Baliyat Johnson
CISM, PMP
Written from Denver, Colorado · May 28, 2026

