Insights

Field notes on governing and securing AI.

Practical briefs for CISOs, program offices, and boards — on AI governance, machine identity, and the risk most organizations can't yet see.

Machine Identity

Your AI agents have the keys to the kingdom

AI agents are non-human identities operating inside your trust boundary with credentials you issued them. A control model — the AGENT framework — for governing them before they become your next breach.

Read more →
Governance

What NIST's AI RMF actually asks of you

Govern, Map, Measure, Manage — translated from framework language into the concrete steps a security or program leader can start this quarter.

Read more →
Federal

What OMB's AI mandates require of contractors

The federal AI memos raised the bar for agencies — and everyone who sells to them. A plain-language look at what it means for your compliance posture.

Read more →
Identity

Non-human identity is the new perimeter

Machine identities outnumber humans roughly 100 to 1. Why privileged access and Zero Trust have to extend to service accounts, pipelines, and AI agents — now.

Read more →
Cloud Security

Defending the keys to the kingdom in the cloud

AWS, Azure, and GCP handed organizations an explosion of privileged identities. How to implement least privilege and just-in-time access before a breach forces you to.

Read more →
Strategy

Adopt AI fast — without it blowing up

Governance framed as an enabler, not a brake. How to move quickly on AI while keeping the risk, security, and compliance you'll be judged on later.

Read more →

Want this thinking applied to your organization?

Briefings and advisory that turn these ideas into a program you can trust.

Book a Consultation

Get new briefs in your inbox

Practical AI governance and security notes, sent when there's something worth reading. No spam.