New We now offer ISO/IEC 42001 audit services. Explore →

Humans that know

We help organizations deploy AI that survives attackers, auditors, and regulators.

Book a consultation

Where to start

You know which system you're worried about.

AI Risk Assessment →

You don't yet know the shape of the problem.

AI Enterprise Readiness →

You're already building.

Secure Design Review →

Media

Point of view · Jul 2026

You Made an AI Policy. So Now What?

A policy is not governance. The five ways an AI council fails, mapped to Lencioni's five dysfunctions, and the cheapest fix available before its next meeting.

Point of view · Jun 2026

From Chaos to Control: Managing AI Risk in Healthcare

A control framework tells you what to do. Whether a healthcare organization can actually do it is a question of people, ownership, and maturity, and the workforce now includes AI agents.

Point of view · Jun 2026

You Can't Patch AI!

Policy has started borrowing patch-management language for AI systems. But fine-tuning, retraining, and weight editing are not patches, and the difference matters.

Talk · Mar 2026

Demystifying AI

A three hour workshop with ISACA San Diego, in person and on Zoom, March 5, 2026.

Field notes · Jan 2026

2025: The Year of the Spark

A look back at our first year: research at the NATO IST-210 symposium, CAMLIS, BSides Las Vegas and SPIE DCS, and where we take it next.

Point of view · Nov 2025

Fast Code, Soft Skills?

Fifteen years ago, developers fought over whether IDEs were cheating. Now they're arguing about AI assistants. What automation research says about losing the fundamentals, and how agentic development keeps you the architect.

Talk to the people who'll do the work.

Start a conversation