Writing
Notes from the architecture side of security.
- AI Security
A Prompt Injection Testing Framework for Enterprise LLM Systems
A repeatable prompt injection testing framework — threat model, attack corpus, harness design, scoring and release gates — for teams shipping LLM and RAG applications in regulated environments.
- AI Security
LLM Security Evaluation: Choosing and Combining Frameworks
A practical comparison of the LLM security frameworks enterprises are actually assessed against — OWASP LLM Top 10, NIST AI RMF, ISO/IEC 42001, MITRE ATLAS — and how to turn them into one evaluation programme.
- Enterprise Cybersecurity
Enterprise Architecture for Secure LLM Deployment
A reference architecture for enterprise LLM and RAG systems — trust boundaries, identity for agents, retrieval-layer authorisation, tool mediation and the evaluation loop that keeps it honest.
- AI Security
The Future of AI Security in Enterprise Environments
How global enterprises are rearchitecting their cyber programs around AI workloads, model integrity, and secure data lifecycles.
- Zero Trust
Zero Trust in the Age of AI
Zero Trust principles applied to autonomous agents, copilots, and machine identities operating at machine speed.
- Microsoft Security
Securing Microsoft 365 for Modern Enterprises
A reference architecture for hardening M365 with Entra ID, Defender XDR, Purview, and Conditional Access in regulated industries.
- Governance
AI Governance and Emerging Cyber Risks
Building an AI governance program that satisfies regulators, accelerates business adoption, and reduces real cyber risk.
- Zero Trust
Identity-Centric Security Architecture
Why identity is the new perimeter — and how to design an identity fabric that scales across humans, devices, workloads, and AI agents.
- Cloud Security
Cloud-Native Security & Operational Resilience
Designing CNAPP, DevSecOps, and resilience patterns that survive real incidents — not just compliance audits.