Cybersecurity

How ISO 24970 and prEN 18229-1 Turn Post-Deployment Chaos Into Auditable Evidence

When AI Systems Fail, Logs Tell the Story Your AI system just flagged 300 legitimate transactions as fraud. A biometric authentication tool locked out half your workforce. A …

The prEN 18228 Problem: Why Your AI Risk Assessment Will Fail the First Real Test

Most AI risk assessments look solid on paper and collapse the moment a regulator, client, or auditor asks a simple question. What exactly can go wrong, how likely is it, and what …

The 45 AI Threat Vectors That Your Security Team Probably Isn't Tracking

A Practitioner’s Field Guide Most AI threat models are incomplete. Not slightly incomplete. Fundamentally incomplete. Last year I reviewed the threat model for a financial services …

Practical ISO 42001 Certification Guidance

Implementation Tips for GRC and AI Professionals Make the AI Policy Operational, Not Decorative Most AI policies fail before they get printed. A paragraph about “responsible AI” …

Practical AI Red Team Implementation Tips for Safer, More Resilient AI Systems

Playbook for Building an AI Red Team Three months after deploying a customer-facing language model, a financial services firm I advise discovered that a determined user could …