Blog

The thinking behind AI security review.

Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.

Newsletter

New posts in your inbox,
when they publish.

Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.

No spam. Unsubscribe anytime.

Technical11 min

Insecure output handling — the LLM risk teams underrate

Teams harden LLM inputs and ignore outputs. Insecure output handling turns prompt injection into code execution, data exfiltration, or stored attacks.

Foundations9 min

When to run an AI security review — the four trigger points

Four trigger points that should initiate an AI security review: initial deployment, model change, scope expansion, incident.

Reference10 min

Assessing the AI feature inside SaaS you already bought

Vendors are adding AI to SaaS you already trust. Those features introduce risks the original assessment missed. The supplemental review defined.

Governance10 min

AI risk acceptance — who actually signs

Risk acceptance attributed to a committee means no one is accountable. Who should sign for AI systems and what that signature requires.

Reference11 min

ISO 42001 vs ISO 27001 — what is new for AI

Already hold ISO 27001? Here's what ISO 42001 adds for AI -- new requirements vs. controls you can extend from your existing ISMS.

Technical11 min

Tool poisoning in MCP servers

MCP tool poisoning uses malicious tool descriptions to manipulate models into unintended invocations or data disclosure. Descriptions are untrusted.

Regulation10 min

Building an EU AI Act system inventory

The EU AI Act requires knowing every AI system you deploy and its tier. Here's how to build that inventory when AI hides in SaaS and vendor products.

Technical11 min

Data poisoning in RAG knowledge bases

RAG knowledge base poisoning inserts malicious content not to corrupt the index, but to influence model outputs when poisoned documents are retrieved.

Technical12 min

Mapping the agentic AI attack surface

Five layers of the agentic AI attack surface — prompt channel, tool surface, memory, orchestration boundary, output channel — mapped with controls.

Technical12 min

Prompt injection, explained for security reviewers

What prompt injection actually is, how its variants work, how it differs from SQL injection, and which controls reduce the risk in practice.

Reference12 min

The AI security review checklist, by lifecycle gate

A lifecycle-gate checklist for AI security reviews: intake through production, with gate-specific questions and evidence needs.

Reference10 min

The AI section your vendor security questionnaire is missing

The AI vendor risk assessment questionnaire your procurement process is missing — model governance, re-assessment triggers, incident notification.