Blog
Real stories from the compliance, FinOps & operations battlefield
Learnings, frameworks, and lessons from 15+ years implementing ISMS, optimizing cloud costs, and scaling Service Delivery teams in fintech and digital banking across LATAM. No vendor pitch. No fluff.
How much certification costs, how long it takes, and what evidence regulators ask for.
Compliance (ISO 27001 · SOC 2)
How much certification costs, how long it takes, and what evidence regulators ask for.
The day they asked you for the evidence
2015. We were still a small startup, but we'd reached the point where 'everyone does things their own way' stopped being an agile virtue and became a risk. When you define the process yourself, the first audit that asks you to show evidence feels like a threat. It isn't: an audit is about the processes, not the people.
How much does ISO 27001 certification cost and how long does it take in Mexico?
The cost of ISO 27001 certification in Mexico ranges from $80,000 to $450,000 MXN for startups and SaaS/fintech companies, with a typical timeline of 9 to 14 months. I explain what each cost block depends on, why it varies so much between providers, and why an initial diagnosis is the cheapest way to avoid over-quoting or under-estimating the project.
How to choose an ISO 27001 consultant in Mexico?
Before hiring, evaluate five objective criteria: the consultant's real certification (Lead Auditor, not just a 'specialist'), whether you work directly with the person who executes, whether the scope also covers cloud costs and account health, price transparency, and whether support continues after certification.
Should your organization move from the annual pentest to continuous AI monitoring?
The annual pentest model is no longer defensible when the environment changes daily. Continuous validation with agentic AI is already a formal market category (Gartner: Adversarial Exposure Validation, 2026). The real challenge is no longer the technology, but governance: who owns the finding when the one detecting it is an AI agent.
The real cost of not having ISO 27001: lost contracts and how to quantify them
The most common cost of not having ISO 27001 isn't a fine — it's the contract, tender, or funding round that's silently lost. Certification is no longer a differentiator: it's the minimum entry filter in enterprise purchasing. A 3-question method to quantify the loss.
Information security for fintechs in Colombia: what the SFC requires in 2026
Mandatory open finance (Decree 0368/2026), cybersecurity (External Circular 007), SARLAFT 4.0, and sensitive biometric data. Why ISO 27001 is the most direct way to demonstrate compliance with the SFC.
Information security for fintechs in Peru: what the SBS requires in 2026
The Open Finance Department, the Banking as a Service (BaaS) regulation, the sanctions regime, and Legislative Decree 1700. Why the SBS turned security into a requirement, not an option, for fintechs.
Why is compliance shifting from an annual event to a continuous service?
The Compliance as a Service market already exceeds $6 billion and keeps growing because companies are abandoning the "get ready before the audit" model in favor of always being ready. What the shift means, why the annual audit is no longer enough, and how to adopt it.
Why scaling compute masks the real problem and how to regain control of spend.
FinOps (Cloud Costs)
Why scaling compute masks the real problem and how to regain control of spend.
The cost nobody sees: users, non-production environments, and the contract gap
Your total cloud bill doesn't tell you whether your architecture scales well — cost per user does. A real story about defining a non-production vs. production benchmark, closing the contract gap around QA SLAs, and what to do when a client saturates your test environments without bad intent.
The end-of-month Pantitlán station: why scaling well is more than scaling cheap
Sizing infrastructure so it never fails, without looking at real usage data, almost always means overpaying the whole month to cover a peak that happens a few days. How to detect silent overprovisioning and why autoscaling needs to know the business calendar, not just the time of day.
FinOps — The PDF that cost $1,500 a month for an unsupervised design
How much does a bad cloud architecture design cost, and how do you fix it at the root? A real case: a Chrome instance that was never closed drove over $1,500 USD/month in avoidable costs. The real fix wasn't more compute — it was fixing the root cause and migrating to Kubernetes.
The client who was taking everyone else down, without meaning to
One tenant saturated the shared compute capacity and caused timeouts that affected other clients on the same platform. The fix was a circuit breaker — isolating and backing off that consumption — the pattern Netflix popularized with Hystrix.
The variable that should never have changed between environments — and did
A banking integration component didn't treat environment variables as immutable between QA and DEV — the first change disabled real operations. Configuration failures are the #1 cause of outages (Uptime Institute 2026).
How to reverse a negative NPS, avoid silent churn, and scale the operation.
Customer Success
How to reverse a negative NPS, avoid silent churn, and scale the operation.
From negative NPS to +24: the Customer Success turnaround we did at Formiik
When we started measuring NPS on a new client, the numbers were in the red and the 52 enterprise accounts across 7 countries showed signs of silent churn. We identified friction points in each stage of the customer journey, engaged the client directly, and defined a stabilization and improvement plan. In 12 months, NPS was +24.
Project Fenix: when your client wins an international award and you were behind the operation
Our largest client in Peru —with 2,000+ field users and 300+ offices— won the 2026 Innovation Excellence Award from Global Banking & Finance Review with Project Fenix, a field-agent digitization project. The platforms we operated were the key tool, and I was serving as Director of Operations making sure everything ran at the level a project of this visibility demanded.
The 30% of tickets that never should have been ours
A client headcount reduction left us absorbing work outside our contractual scope. The fix wasn't just automating — it was automating first and renegotiating scope after: 70-75% less configuration time, 40% fewer tickets.
When "it's simple" doesn't mean "it's worth it"
A stakeholder insisted on a visual feature described as a "simple quick win", while the real business backlog stayed unfinished. Holding the right priority —not the loudest one— is what allowed the project to scale to every client office.
First-person stories and reflections on operating SaaS platforms.
Leadership & Operations
First-person stories and reflections on operating SaaS platforms.
The compute that masks problems without solving them
Your platform isn't slow because it lacks compute. And deep down, you already know it. After 15 years running software in production, I learned the most expensive technology fails if there's no team that operates it well. Scaling infrastructure is politically easier than finding the root cause — but the underlying problem stays.
When one person's departure almost cost us the account
A key contributor left unplanned from a fully in-person banking account served remotely — metrics sank. An on-site intervention and a structural shift from remote to local reversed the trend and rebuilt trust.
The evidence that built trust where there was no hierarchy
An integration error caused false positives between our platform and a client's banking core. Without formal authority over the external vendor, irrefutable evidence —not hierarchy— got the collaboration and the fix.
Stories about developing, course-correcting, and caring for the people on a team.
People Leadership
Stories about developing, course-correcting, and caring for the people on a team.
The 6-hour feature that should never have been built
A new manager was about to request a 6-8 hour feature the platform already handled. Showing the reports live avoided the build and built their mental model. Context: engineers spend 17.3 h/week on technical debt (Stripe).
What the numbers didn't explain — until I asked
A team member's performance dropped for no apparent reason. Instead of watching them, I asked: it was a health issue, not a commitment issue. Adjusting their schedule restored their numbers. Context: 86% of employees value empathetic leadership (EY).
Want each article in your inbox?
No spam. One real story every 2-3 weeks about what works (and what doesn't) in compliance, cloud, and operations for fintech.
