Blog

Real stories from the compliance, FinOps & operations battlefield

Learnings, frameworks, and lessons from 15+ years implementing ISMS, optimizing cloud costs, and scaling Service Delivery teams in fintech and digital banking across LATAM. No vendor pitch. No fluff.

Compliance (ISO 27001 · SOC 2)

How much certification costs, how long it takes, and what evidence regulators ask for.

View the full topic
Topic guide

Compliance (ISO 27001 · SOC 2)

How much certification costs, how long it takes, and what evidence regulators ask for.

View the full topic
New
Compliance
Aug 18, 20266 min

The day they asked you for the evidence

2015. We were still a small startup, but we'd reached the point where 'everyone does things their own way' stopped being an agile virtue and became a risk. When you define the process yourself, the first audit that asks you to show evidence feels like a threat. It isn't: an audit is about the processes, not the people.

Read full article
New
Compliance
Aug 22, 20266 min

How much does ISO 27001 certification cost and how long does it take in Mexico?

The cost of ISO 27001 certification in Mexico ranges from $80,000 to $450,000 MXN for startups and SaaS/fintech companies, with a typical timeline of 9 to 14 months. I explain what each cost block depends on, why it varies so much between providers, and why an initial diagnosis is the cheapest way to avoid over-quoting or under-estimating the project.

Read full article
New
Compliance
Aug 25, 20267 min

How to choose an ISO 27001 consultant in Mexico?

Before hiring, evaluate five objective criteria: the consultant's real certification (Lead Auditor, not just a 'specialist'), whether you work directly with the person who executes, whether the scope also covers cloud costs and account health, price transparency, and whether support continues after certification.

Read full article
New
Compliance
Aug 27, 20268 min

Should your organization move from the annual pentest to continuous AI monitoring?

The annual pentest model is no longer defensible when the environment changes daily. Continuous validation with agentic AI is already a formal market category (Gartner: Adversarial Exposure Validation, 2026). The real challenge is no longer the technology, but governance: who owns the finding when the one detecting it is an AI agent.

Read full article
New
Compliance
Aug 28, 20266 min

The real cost of not having ISO 27001: lost contracts and how to quantify them

The most common cost of not having ISO 27001 isn't a fine — it's the contract, tender, or funding round that's silently lost. Certification is no longer a differentiator: it's the minimum entry filter in enterprise purchasing. A 3-question method to quantify the loss.

Read full article
New
Compliance
Aug 29, 20266 min

Information security for fintechs in Colombia: what the SFC requires in 2026

Mandatory open finance (Decree 0368/2026), cybersecurity (External Circular 007), SARLAFT 4.0, and sensitive biometric data. Why ISO 27001 is the most direct way to demonstrate compliance with the SFC.

Read full article
New
Compliance
Aug 29, 20266 min

Information security for fintechs in Peru: what the SBS requires in 2026

The Open Finance Department, the Banking as a Service (BaaS) regulation, the sanctions regime, and Legislative Decree 1700. Why the SBS turned security into a requirement, not an option, for fintechs.

Read full article
New
Compliance
Aug 31, 20266 min

Why is compliance shifting from an annual event to a continuous service?

The Compliance as a Service market already exceeds $6 billion and keeps growing because companies are abandoning the "get ready before the audit" model in favor of always being ready. What the shift means, why the annual audit is no longer enough, and how to adopt it.

Read full article
FinOps (Cloud Costs)

Why scaling compute masks the real problem and how to regain control of spend.

View the full topic
Topic guide

FinOps (Cloud Costs)

Why scaling compute masks the real problem and how to regain control of spend.

View the full topic
New
FinOps
Aug 29, 20266 min

The cost nobody sees: users, non-production environments, and the contract gap

Your total cloud bill doesn't tell you whether your architecture scales well — cost per user does. A real story about defining a non-production vs. production benchmark, closing the contract gap around QA SLAs, and what to do when a client saturates your test environments without bad intent.

Read full article
New
FinOps
Aug 29, 20266 min

The end-of-month Pantitlán station: why scaling well is more than scaling cheap

Sizing infrastructure so it never fails, without looking at real usage data, almost always means overpaying the whole month to cover a peak that happens a few days. How to detect silent overprovisioning and why autoscaling needs to know the business calendar, not just the time of day.

Read full article
New
FinOps
Aug 31, 20265 min

FinOps — The PDF that cost $1,500 a month for an unsupervised design

How much does a bad cloud architecture design cost, and how do you fix it at the root? A real case: a Chrome instance that was never closed drove over $1,500 USD/month in avoidable costs. The real fix wasn't more compute — it was fixing the root cause and migrating to Kubernetes.

Read full article
New
FinOps
Aug 31, 20264 min

The client who was taking everyone else down, without meaning to

One tenant saturated the shared compute capacity and caused timeouts that affected other clients on the same platform. The fix was a circuit breaker — isolating and backing off that consumption — the pattern Netflix popularized with Hystrix.

Read full article
New
FinOps
Aug 31, 20265 min

The variable that should never have changed between environments — and did

A banking integration component didn't treat environment variables as immutable between QA and DEV — the first change disabled real operations. Configuration failures are the #1 cause of outages (Uptime Institute 2026).

Read full article
Customer Success

How to reverse a negative NPS, avoid silent churn, and scale the operation.

View the full topic
Topic guide

Customer Success

How to reverse a negative NPS, avoid silent churn, and scale the operation.

View the full topic
New
Customer Success
Aug 12, 20267 min

From negative NPS to +24: the Customer Success turnaround we did at Formiik

When we started measuring NPS on a new client, the numbers were in the red and the 52 enterprise accounts across 7 countries showed signs of silent churn. We identified friction points in each stage of the customer journey, engaged the client directly, and defined a stabilization and improvement plan. In 12 months, NPS was +24.

Read full article
New
Customer Success
Aug 15, 20265 min

Project Fenix: when your client wins an international award and you were behind the operation

Our largest client in Peru —with 2,000+ field users and 300+ offices— won the 2026 Innovation Excellence Award from Global Banking & Finance Review with Project Fenix, a field-agent digitization project. The platforms we operated were the key tool, and I was serving as Director of Operations making sure everything ran at the level a project of this visibility demanded.

Read full article
New
Customer Success
Aug 31, 20266 min

The 30% of tickets that never should have been ours

A client headcount reduction left us absorbing work outside our contractual scope. The fix wasn't just automating — it was automating first and renegotiating scope after: 70-75% less configuration time, 40% fewer tickets.

Read full article
New
Customer Success
Aug 31, 20265 min

When "it's simple" doesn't mean "it's worth it"

A stakeholder insisted on a visual feature described as a "simple quick win", while the real business backlog stayed unfinished. Holding the right priority —not the loudest one— is what allowed the project to scale to every client office.

Read full article
Leadership & Operations

First-person stories and reflections on operating SaaS platforms.

View the full topic
People Leadership

Stories about developing, course-correcting, and caring for the people on a team.

View the full topic

Want each article in your inbox?

No spam. One real story every 2-3 weeks about what works (and what doesn't) in compliance, cloud, and operations for fintech.