Security that ships with the product instead of standing in front of it.
Three distinct mechanisms for product security — paved roads (make the right thing easy), guardrails (make the dangerous thing hard), and assurance (prove which one happened).
Reference architectures for LLM, RAG and agentic AI workloads — cloud-neutral paved roads, guardrails, assurance evidence and escape hatches.
Building security into the pipeline rather than gates in front of it.
Modern approaches to security architecture and controls.
Evolution of IT control frameworks and automation.
Security considerations for manufacturing and physical systems.
GRC and regulatory considerations for FDA and digital manufacturing.
Building security into CI/CD pipelines for AI systems.
Interactive tool for AI software bill of materials and supply chain security.
Live reference for AI/BOM frameworks and practices.
Framework and tracking for agentic AI security.
Where AI meets company data, and what to do about it before somebody turns Copilot on.
The system diagram, the five CISA / ASD ACSC risk categories, a tool matrix arranged by the stack you already run, and each of the four layers with 24 risks — every one carrying its preventive and detective controls and the tools that implement them.
Every technique in OWASP LLM Top 10 and agentic systems, mapped to MITRE ATLAS, exploitable in a sandbox, and cross-walked with mitigations from every major framework.
What the modern AI application stack is actually made of — orchestration frameworks, vector stores, tooling layers — and where each piece helps, costs you, or introduces risk.
An SBOM tells you what is in the build. An AI-BOM has to tell you what the model learned, where the weights came from, and what changes when either moves. Scope, fit, and the limits of pretending it is all just another supply chain problem.
How an LLM actually works, what RAG is and why it matters for security, and the vector database layer you need to understand to know what can go wrong.
Eighteen prompt injection techniques laid out, explained, and executable in a sandbox. Every attack you can actually test against, and what a good defense looks like.
The four ways company data meets AI — Copilot inside your own systems, paid Claude or ChatGPT accounts, personal logins nobody told you about, and data you license to other people. For each one, what actually happens to your data and what to configure.
The narrower cut: Microsoft Copilot, enterprise chat deployments, and the accounts nobody registered. What each one does with your data by default, and the settings that change it.
Layer by layer — inputs, training, the agent itself, outputs — each risk mapped to three frameworks, with the preventive control, the detective control and the configuration that makes both work.
Five hands-on red-team labs in one file — the OWASP LLM Top 10, Promptfoo, PyRIT, Garak, and the twelve deeper gaps conventional testing misses. Each with attack classes, live sandboxes and detection guidance.
The secure reference architecture in full: nine zones from user to egress, a 34-step build runbook in dependency order, three threat kill chains (IAM, supply chain, API), and the twelve deeper gaps mapped to controls.
Policy, oversight and accountability for AI — and what survives contact with a delivery team.
Architecture views for systems that have to be explained to somebody who did not build them.
Six domains, seven persistent conditions each. For every one of the forty-two: the paved road that removes it, the guardrail that holds it, and the state it converges on. None is a policy failure — each persists because the compliant option is harder than the alternative.
A single chain of custody for security intent: what we believe, what we are building toward, what engineers actually consume, what the platform refuses to allow, and how we prove it continuously — without asking anyone to file a ticket.
Vendor assessment, and why every generation of it solved the previous generation's problem.
The part everyone skips — why people do what they do when the tooling is not watching.
Reading the people above you, and being read yourself.
Work out what they are really asking, then answer it inside the time you actually have. A drill for interviews, board questions and anywhere the clock is part of the test.
One test, six failure modes, and the sentences that give each of them away — long before the damage shows up in attrition numbers.
Four dimensions of a leader's operating style, four archetypes each. Pick the cell that matches what you have observed — not what the org chart implies — and the brief assembles itself.
Twenty-two moments you have definitely had, one at a time, with a read on each answer as you go — and a picture of your operating style at the end.
Working tools rather than write-ups, grouped by the problem they address. These live on their own domains and open in a new tab; some sit behind access gating.
Product security for regulated medical devices — the premarket evidence, the postmarket obligation, and the threat model underneath both.
Coordinated vulnerability disclosure end to end: a seven-stage workflow with human approval gates, VEX and CSAF export, and deterministic risk scoring tuned for medtech rather than generic CVSS.
The tool index and medtech product security portal. Covers 101 products with FDA recall integration, STRIDE threat models and a per-product risk register, behind Cloudflare Access gating.
Medical device threat modelling as a single-file application — DoDAF views, attack graphs and the FDA premarket architecture views a submission actually asks for.
The other side of the same problem — what the hospital that bought the device now has to defend.
Medical-device security intelligence across 85 hospitals in six states: CVE exposure per site, risk scoring, and inferred network topology diagrams for estates nobody has a current map of.
Medical device risk assessment — working through device risk in the terms a regulated manufacturer and its customers both have to sign off on.
Security questions that only surface when someone is buying, selling or merging the thing.
What actually happened, reconstructed from public evidence — and the field guide for when it happens to you. Each brief is explicit about what is known and what is still unknown.
A ransomware operator used a commercial coding agent as an always-available intrusion assistant. When the agent refused, the operator reframed the work as authorised testing and the safety boundary gave way. Reconstructed from twenty-eight recovered chat sessions.
A cyber incident detected on 25 August 2026 caused a global network outage that disrupted manufacturing, order processing, shipping and some cardiac remote-monitoring activations. The actor, entry path and dwell time have not been made public.
A destructive attack on 11 March 2026 disrupted Stryker's global Microsoft environment, manufacturing, ordering and shipping. No ransomware was found. Public reporting points at abuse of privileged administration and device management.
Threats, detection, escalation and reporting in one place. What to look for, who to tell, how fast, and what the regulator expects to see afterwards.
The controls themselves — libraries, governance, incidents, and where the real failures are.
Data governance is about a noun; AI governance is about a verb. Where the line actually sits and why one depends on the other. Twelve things a good AI policy does, twelve failure patterns to avoid, and a model policy you can adapt.
The control library as a working reference — NIST 800-53, RMF, 800-171 and 172, mapped so you can move between frameworks without re-deriving the same control each time.
Build the control once and satisfy seven assertions from it, rather than running a separate programme per framework. The implementation guide for doing that.
SOX, GxP, FDA product security, ISO 27001, privacy, GLBA and OT are not seven programmes — they are seven things you must prove about the same access reviews, the same change tickets and the same logs. How to build the substrate once and run it on a calendar that survives a global footprint.
Slides and PDFs, if you would rather present it than read it.
Seven slides: the system diagram, what goes wrong and what covers most of it, the four layers one at a time, and references.
The Copilot and enterprise-chat cut as slides: default behaviour, the settings that change it, and what shadow AI does to the picture.
Four slides: the four situations with what to do in each, what to set up and which tools do it, sharing licensed data without it becoming training corpus, and a four-week runbook.
The same four slides as a PDF, for sending to people who will not open a PowerPoint.