How Large Regulated Enterprises Actually Buy AI
The enterprise AI purchasing journey seen from the security gate: the five stages, the three evaluation layers, and the residency traps hiding in vendor documentation.
Read articlels ./writing
Long-form writing on cybersecurity. Threat modeling, AI security, ML security, AppSec, and the spaces where classical methods stop working.
The enterprise AI purchasing journey seen from the security gate: the five stages, the three evaluation layers, and the residency traps hiding in vendor documentation.
Read articleI designed a two-day workshop with AI red-teaming as a full module, not a closing talk. We finished three of eight sessions. The classics ate both days.
Read articleMost real-world harm from generative AI does not come from prompt injection. Analysis of 11,658 incidents shows output handling and misinformation dominate.
Read articleSTRIDE was built for deterministic systems. Agentic AI breaks its core assumptions. Here is a five-zone method that actually finds EchoLeak-class attacks.
Read articlePrompts are payloads. Why classical red-teaming misses LLM-native attacks, and how to design adversarial tests that surface jailbreaks and tool misuse.
Read articleIoT devices fail open by default. A pragmatic checklist for hardening firmware, networks, and lifecycle management against the threats most teams overlook.
Read articleCSA's MAESTRO framework, explained for practitioners. Layer-by-layer attack surface, control mapping, and how to apply it to your ML pipeline this week.
Read articleFive concrete moves security leaders should make this quarter to keep up with AI adoption, without slowing the teams shipping it.
Read articleWhy threat modeling is the highest-leverage activity in a security program, and how to start without buying tooling or hiring consultants.
Read articleA practitioner's comparison of OWASP Threat Dragon, IriusRisk, Microsoft Threat Modeling Tool, and others, with concrete picks by team size and maturity.
Read articleBeyond STRIDE: attack trees, PASTA, kill chains, and how to combine them into a methodology your engineers will actually use.
Read articleWhere pentesting fits inside an ISO 27001 program, what auditors look for, and how to scope tests so they produce defensible evidence, not just findings.
Read articleA foundational guide to threat modeling: what it is, when to do it, who should be in the room, and the seven questions every model must answer.
Read article