Blog

The thinking behind AI security review.

Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.

Newsletter

New posts in your inbox,
when they publish.

Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.

No spam. Unsubscribe anytime.

Technical13 min

Why your existing threat modeling tool doesn't model agents

STRIDE, attack trees, and most commercial threat modeling tools were designed for deterministic software. Agentic AI has five properties those tools cannot represent — and each one is an attack surface.

Reference10 min

Assessing third-party AI vendors — the questions procurement skips

Third-party AI vendor assessments typically cover data processing agreements and SOC 2. They miss model governance, incident notification for model updates, and the evidence required to re-assess when the vendor changes the underlying model.

Worked example12 min

A worked example: AI Risk Disposition for a Copilot Studio procurement agent

Every section of the disposition filled in with real content — decision, rationale, required controls, residual risk acceptance, evidence gaps, re-assessment triggers, and sign-off log. The same system used in the Drel demo dossier.

Technical11 min

Threat modeling an MCP server — the parts AppSec tools miss

MCP servers have four distinct attack surfaces: transport, tool surface, prompt context injection, and auth boundary. Traditional threat modeling tools model the first and miss the other three. Here is the full threat model with controls.

Regulation13 min

EU AI Act Article 9 risk management — what evidence is required

Article 9 of the EU AI Act requires a risk management system for high-risk AI. This piece translates each of its six requirements into specific evidence artefacts — what an auditor will ask for, and the gaps that appear most often when organisations try to produce it.

Reference14 min

OWASP Agentic Top 10 mapped to required controls

The OWASP Agentic Top 10 names the threats. This piece maps each one to the controls that close it, the lifecycle gate where each control must be in place, and the evidence required to verify it — so your AI Committee has a working checklist, not just a threat list.

Foundations11 min

What an AI Risk Disposition actually contains

AI Committees keep approving systems they can't defend later. The Risk Disposition memo is the artifact that fixes this — here is what goes into one, section by section, with examples from a real assessed system.

Governance11 min

What an agentic AI audit trail must capture

Auditing an agentic AI system after an incident requires a different evidence set than auditing a deterministic system. The audit trail must capture not just what happened, but what the model decided and why — and most implementations miss the latter.

Technical13 min

LLM red-teaming for a security review

Red-teaming an LLM application is not the same as penetration testing it. This piece covers the distinct techniques — goal hijacking, jailbreaking, indirect injection, and exfiltration chains — and how to document findings for a security review.

Governance9 min

Presenting AI risk to leadership without the 40-slide deck

Most AI risk presentations to leadership are too long, too technical, and too focused on the threats rather than the decision. This piece defines the structure that gets a governance decision out of a leadership meeting.

Foundations10 min

Five mistakes that make an AI security review undefensible

Most AI security reviews fail not because they miss threats, but because they miss the structure that makes a decision defensible. These five mistakes appear in almost every review we have examined.

Governance10 min

The security terms an AI vendor contract needs

Standard vendor contracts cover SLAs, data processing, and confidentiality. AI vendor contracts need additional terms: model-change notification, training data restrictions, incident notification, and re-assessment rights. This piece defines the clause language.