Security · AI · Governance · Culture

Insights


1Product security/security

Security that ships with the product instead of standing in front of it.

Long read

Paved roads, guardrails and assurance

Three distinct mechanisms for product security — paved roads (make the right thing easy), guardrails (make the dangerous thing hard), and assurance (prove which one happened).

Three mechanisms · framework
Open it →
Interactive

GenAI: paved roads, guardrails and assurance

Reference architectures for LLM, RAG and agentic AI workloads — cloud-neutral paved roads, guardrails, assurance evidence and escape hatches.

LLM · RAG · agents · assurance evidence
Open it →
Long read

Prodsec without gates

Building security into the pipeline rather than gates in front of it.

Pipeline · operating model
Open it →
Long read

Reimagining security

Modern approaches to security architecture and controls.

Architecture · controls
Open it →
Long read

Future of IT controls

Evolution of IT control frameworks and automation.

Controls · governance
Open it →
Interactive

Manufacturing security

Security considerations for manufacturing and physical systems.

Manufacturing · operational technology
Open it →
Interactive

FDA digital manufacturing

GRC and regulatory considerations for FDA and digital manufacturing.

GRC · FDA · manufacturing
Open it →
Interactive

CI/CD and AI secure pipeline guide

Building security into CI/CD pipelines for AI systems.

CI/CD · pipeline · AI
Open it →
Interactive

AI/BOM workbench

Interactive tool for AI software bill of materials and supply chain security.

AI · SBOM · supply chain
Open it →
Interactive

AI/BOM live

Live reference for AI/BOM frameworks and practices.

AI · SBOM
Open it →
Interactive

Agentic AI boards

Framework and tracking for agentic AI security.

AI · agents · tracking
Open it →

2AI security/aisec

Where AI meets company data, and what to do about it before somebody turns Copilot on.

Interactive

Agentic AI control map

The system diagram, the five CISA / ASD ACSC risk categories, a tool matrix arranged by the stack you already run, and each of the four layers with 24 risks — every one carrying its preventive and detective controls and the tools that implement them.

Seven views · filter by OWASP category · free-text search
Open it →
Interactive

AI Red Team Workbench

Every technique in OWASP LLM Top 10 and agentic systems, mapped to MITRE ATLAS, exploitable in a sandbox, and cross-walked with mitigations from every major framework.

18 techniques · sandbox testing · six frameworks mapped
Open it →
Interactive

AI Stack Lab — LangGraph, LangChain and the ecosystem

What the modern AI application stack is actually made of — orchestration frameworks, vector stores, tooling layers — and where each piece helps, costs you, or introduces risk.

Frameworks · components · trade-offs
Open it →
Interactive

AI-BOM vs SBOM

An SBOM tells you what is in the build. An AI-BOM has to tell you what the model learned, where the weights came from, and what changes when either moves. Scope, fit, and the limits of pretending it is all just another supply chain problem.

About 7 minutes · scope, fit and limits
Open it →
Visual primer

LLM, RAG, and Vector Databases

How an LLM actually works, what RAG is and why it matters for security, and the vector database layer you need to understand to know what can go wrong.

Interactive diagrams · visual explanations
Open it →
Interactive

Prompt Injection Sandbox v2

Eighteen prompt injection techniques laid out, explained, and executable in a sandbox. Every attack you can actually test against, and what a good defense looks like.

18-technique library · automated campaigns · defense patterns
Open it →
Interactive

Protecting Company Data When Using AI

The four ways company data meets AI — Copilot inside your own systems, paid Claude or ChatGPT accounts, personal logins nobody told you about, and data you license to other people. For each one, what actually happens to your data and what to configure.

Six views · a real-life example on every tab · gaps flagged in red
Open it →
Interactive

Protecting Critical Data in Copilot, Enterprise Chat and Shadow AI

The narrower cut: Microsoft Copilot, enterprise chat deployments, and the accounts nobody registered. What each one does with your data by default, and the settings that change it.

Configuration-first · per-platform
Open it →
Long read

Securing Agentic AI Without Slowing It Down

Layer by layer — inputs, training, the agent itself, outputs — each risk mapped to three frameworks, with the preventive control, the detective control and the configuration that makes both work.

About 12 minutes · 24 risks · six control categories by stack
Open it →
Interactive

Security Labs — OWASP, Promptfoo, PyRIT, Garak

Five hands-on red-team labs in one file — the OWASP LLM Top 10, Promptfoo, PyRIT, Garak, and the twelve deeper gaps conventional testing misses. Each with attack classes, live sandboxes and detection guidance.

5 labs · attack classes · sandboxes
Open it →
Interactive

Well-Architected AWS for LLM, RAG and Agentic AI

The secure reference architecture in full: nine zones from user to egress, a 34-step build runbook in dependency order, three threat kill chains (IAM, supply chain, API), and the twelve deeper gaps mapped to controls.

9 zones · 34-step build runbook · kill chains
Open it →

GAI governance/aisec

Policy, oversight and accountability for AI — and what survives contact with a delivery team.

EEnterprise architecture/arch

Architecture views for systems that have to be explained to somebody who did not build them.

3TPRM/tprm

Vendor assessment, and why every generation of it solved the previous generation's problem.

4Culture/culture · /myblog

The part everyone skips — why people do what they do when the tooling is not watching.

5Leadership/leadership · /interview

Reading the people above you, and being read yourself.

PPrototypesregmap.ai · thebitsense.ai

Working tools rather than write-ups, grouped by the problem they address. These live on their own domains and open in a new tab; some sit behind access gating.

IIncidents/incidents

What actually happened, reconstructed from public evidence — and the field guide for when it happens to you. Each brief is explicit about what is known and what is still unknown.

6IT security/security · /controls · /governance · /incidents

The controls themselves — libraries, governance, incidents, and where the real failures are.

7Decks and downloads/aisec

Slides and PDFs, if you would rather present it than read it.