Skip to content
New: AI Red Teaming for LLM apps and agents, with an attestation letter you can share with customersLearn more ↗
Home/Resources/Blog
Resources

Research and field notes

Practical writing on AI threats, AI governance and running a security programme with a small team. New articles every two weeks.

AI Security

Indirect prompt injection: why your AI agent reads attacker instructions

How instructions hidden in emails, web pages and documents reach an agent, and the controls that stop them acting on it.

8 min read · Coming soon
AI Governance

ISO/IEC 42001 for a 50-person company: what it takes

A practical scope, the documents you actually need, and how long readiness takes for a small team.

10 min read · Coming soon
Virtual CISO

The first 90 days with a virtual CISO

What a good vCISO delivers in week 1, month 1 and month 3, and how to measure it.

6 min read · Coming soon
Data Security

PDPA and generative AI: using customer data in AI tools

When consent is needed, what to put in your notices, and how to set up AI tools safely.

7 min read · Coming soon
AI Security

Securing MCP servers: a checklist for engineering teams

Authentication, tool scoping, logging and supply-chain checks for Model Context Protocol servers.

9 min read · Coming soon
Virtual CISO

A one-page cyber risk report your board will read

A template and the five numbers directors should see every quarter.

5 min read · Coming soon
Get started

Want these in your inbox?

Get a short email when we publish new research. No marketing, and you can unsubscribe any time.