I've been posting through GPMF 2026 this week — session takeaways, a few photos, the odd disagreement with a panel. A handful of people who don't normally see my technical writing asked me the same question, more or less word for word: what is this series you keep referencing?
Fair question. It's never been explained in one place. Here's the answer — what it actually is, why I'm writing it, how it's built, and an honest account of how far it's actually gotten, gaps included.
What This Actually Is
The Enterprise IT Blueprint is a structured, five-phase series working through everything an enterprise IT leader is actually accountable for: Infrastructure & Operations, Data & Intelligence, Software & Development, Cybersecurity, and Enterprise & Governance. Each phase opens with an overview post, then works through the domains inside it — cloud, networking, DevOps, Zero Trust, ERP, and so on — with periodic "MQ Spotlight" posts that put competing platforms and vendors side by side on the dimensions that actually decide a real procurement, not the ones in the marketing deck.
It isn't a course, and there's no certificate at the end. It's closer to a working notebook, published in public, one domain at a time.
Why I'm Writing It
Most of what gets published about enterprise IT falls into one of two buckets. There's framework material — TOGAF, COBIT, ITIL, ISO 27001 — rigorous, well-structured, and almost entirely disconnected from the actual decision in front of you. And there's vendor content — genuinely useful product detail, wrapped around a conclusion that was decided before the article was written.
Almost nothing sits where the job actually happens: the seat where the framework has to survive contact with a real budget, a real vendor contract, and a real 2 a.m. incident. That's the gap the Blueprint is trying to close. Every post is written from inside the decision, not observing it from outside — grounded in numbers where numbers exist, and honest about the trade-off where they don't.
It's also, plainly, selfish in the useful way. Writing a post forces a level of rigor that just having an opinion doesn't. Half of what's in the Blueprint started as something I thought I already understood, and didn't — not fully — until I had to write it down in a way that would hold up to someone else reading it.
That instinct got reinforced this week, oddly, at a project management conference rather than a technology one. The theme running through most of GPMF wasn't AI, even though AI was the surface topic of half the sessions — it was that governance only means something when it's in service of a real decision, not when it's compliance theater. That's the same bet the Blueprint is making about enterprise IT content generally: the frameworks are worth having, but only once they're forced to answer to something real.
How It Works
Roughly weekly, in sequence — I don't jump ahead to a domain just because it's more interesting that week. Every domain post is built around real data: market share, adoption numbers, cost figures, breach statistics, whatever exists for that topic — not just a structured opinion with headers. MQ Spotlight posts get inserted when there's an actual vendor decision worth comparing, not on a fixed schedule. And increasingly, live research feeds straight back in — conference sessions, briefings, the occasional argument with a vendor at a booth — rather than staying in a notebook nobody else sees.
Where Things Actually Stand
Here's the honest version, not the polished one. The blog has been running since March 2025 — 56 posts published in total. Of those, 21 belong to the Blueprint itself; the other 35 are standalone pieces on whatever was timely that week — a datacenter outage, a framework update, an acquisition worth unpacking.
Four of five planned phases are underway. Infrastructure & Operations, Data & Intelligence, and Software & Development are complete — the last of those alone ran nine posts, from platform engineering through the DevOps toolchain. Cybersecurity opened three weeks ago with Zero Trust Architecture. Enterprise & Governance — ERP, IT governance, portfolio management — is mapped but not yet started.
It hasn't been a straight line. Phases have paused for weeks at a stretch around travel and conferences. One phase opener got skipped entirely and needs to go back and get written. That's the real shape of a side project run alongside an actual job, and I'd rather say that plainly than pretend otherwise.
What's Next
The rest of Cybersecurity — Network Security & SASE, Cloud Security & CNAPP, Security Operations & SIEM, and an MQ Spotlight on endpoint security platforms — then Enterprise & Governance to close the five-phase arc. No fixed end date. It ends when the map is actually covered.
If you want the domain deep dives as they land rather than checking back, the newsletter is the way to do that — no noise, just the piece when it's actually worth reading. Subscribe here.



