Blog
Real stories from the compliance, FinOps & operations battlefield
Learnings, frameworks, and lessons from 15+ years implementing ISMS, optimizing cloud costs, and scaling Service Delivery teams in fintech and digital banking across LATAM. No vendor pitch. No fluff.
How much certification costs, how long it takes, and what evidence regulators ask for.
Compliance (ISO 27001 · SOC 2)
How much certification costs, how long it takes, and what evidence regulators ask for.
The day they asked you for the evidence
2015. We were still a small startup, but we'd reached the point where 'everyone does things their own way' stopped being an agile virtue and became a risk. When you define the process yourself, the first audit that asks you to show evidence feels like a threat. It isn't: an audit is about the processes, not the people.
How much does ISO 27001 certification cost and how long does it take in Mexico?
The cost of ISO 27001 certification in Mexico ranges from $80,000 to $450,000 MXN for startups and SaaS/fintech companies, with a typical timeline of 9 to 14 months. I explain what each cost block depends on, why it varies so much between providers, and why an initial diagnosis is the cheapest way to avoid over-quoting or under-estimating the project.
How to choose an ISO 27001 consultant in Mexico?
Before hiring, evaluate five objective criteria: the consultant's real certification (Lead Auditor, not just a 'specialist'), whether you work directly with the person who executes, whether the scope also covers cloud costs and account health, price transparency, and whether support continues after certification.
Should your organization move from the annual pentest to continuous AI monitoring?
The annual pentest model is no longer defensible when the environment changes daily. Continuous validation with agentic AI is already a formal market category (Gartner: Adversarial Exposure Validation, 2026). The real challenge is no longer the technology, but governance: who owns the finding when the one detecting it is an AI agent.
Why scaling compute masks the real problem and how to regain control of spend.
How to reverse a negative NPS, avoid silent churn, and scale the operation.
Customer Success
How to reverse a negative NPS, avoid silent churn, and scale the operation.
From negative NPS to +24: the Customer Success turnaround we did at Formiik
When we started measuring NPS on a new client, the numbers were in the red and the 52 enterprise accounts across 7 countries showed signs of silent churn. We identified friction points in each stage of the customer journey, engaged the client directly, and defined a stabilization and improvement plan. In 12 months, NPS was +24.
Project Fenix: when your client wins an international award and you were behind the operation
Our largest client in Peru —with 2,000+ field users and 300+ offices— won the 2026 Innovation Excellence Award from Global Banking & Finance Review with Project Fenix, a field-agent digitization project. The platforms we operated were the key tool, and I was serving as Director of Operations making sure everything ran at the level a project of this visibility demanded.
First-person stories and reflections on operating SaaS platforms.
Leadership & Operations
First-person stories and reflections on operating SaaS platforms.
The compute that masks problems without solving them
Your platform isn't slow because it lacks compute. And deep down, you already know it. After 15 years running software in production, I learned the most expensive technology fails if there's no team that operates it well. Scaling infrastructure is politically easier than finding the root cause — but the underlying problem stays.
Want each article in your inbox?
No spam. One real story every 2-3 weeks about what works (and what doesn't) in compliance, cloud, and operations for fintech.
