Writing

Operational knowledge, codified. Each piece translates direct enterprise experience into frameworks practitioners and executives can act on — from blog posts on emerging threats to published books and research articles.

Why AI-Driven Vulnerability Discovery Breaks Cybersecurity’s Operating Model

Project Glasswing goes beyond faster vulnerability discovery. It eliminates the foundational constraints modern cybersecurity depends on. AI-driven vulnerability discovery collapses the time between exposure and exploitation to near-zero, rendering detection, prioritization, and patch-based models structurally insufficient. The only defensible model is control at runtime, enforced at machine speed.

Read article →

Runtime Governance Is the Only Governance That Counts

Why the Control Plane Is Non-Negotiable

If agentic AI can act without traversing a hardened enforcement boundary, you have policy theater — not risk management. Runtime governance requires a control plane that enforces policy at the moment an agent intends to act, provides auditable evidence, and constrains delegated authority. The gap between governance intent and governance effect is the largest unpriced risk in enterprise AI today.

Read article →

LiteLLM Compromised

What the PyPI Supply Chain Attack Means for Every Organization Running AI

LiteLLM versions 1.82.7 and 1.82.8 on PyPI were compromised with credential-stealing malware as part of a month-long campaign by TeamPCP that included Trivy, KICS, a self-propagating npm worm, and Kubernetes wipers with Iran-targeted destruction. The implications for AI governance are immediate.

Read article →

DNS as a Weapon

What the AWS AgentCore Sandbox Bypass Means for AI Governance

BeyondTrust Phantom Labs demonstrated a full sandbox escape from AWS Bedrock AgentCore using DNS-based C2. The implications for AI governance are significant, and most organizations are not accounting for this class of risk.

Read article →

From Standard to Enforcement

Inside the ACR Control Plane

The ACR Control Plane is now a working reference implementation—open source, deployable, and designed to prove that runtime AI governance is not theoretical. It is operational.

Read article →
The ABCs of Agentic AI

The ABCs of Agentic AI

Featured

Controlling Autonomous Action at Runtime

The definitive guide to governing agentic AI in production. Covers the ACR Standard, runtime enforcement architecture, agentic threat defense, and evidence-first governance for enterprise environments.

Buy Digital Edition — $9.99
The ABC's of Cyber Security

The ABC's of Cyber Security

Total Cyber Security for Small and Medium Sized Businesses

Foundational enterprise security guidance — risk programs, incident response, and the operational controls that protect business infrastructure.

View on Amazon
Weaponization of Social Media

Weaponization of Social Media

Analysis of how social platforms are weaponized for influence operations, disinformation, and threat intelligence — applying the same analytical rigor used in security operations.

View on Amazon

Get governance insights delivered

Runtime AI control strategies, enforcement architecture patterns, and ACR Standard updates — direct from the practitioner who built them.

No spam. Unsubscribe anytime.