Writing
RockCyber Blog
RockCyber Musings is where I think out loud about AI security, governance, and the risk calls executives have to make. It's plain-language and written for the people who own the outcome.
Latest from the blog
- Prompt Injection Defenses: What Reduces Exposure and What Only Looks Like It Does2026-09-17
- Governance Security: The IANS Confidence Signals Are Not a Security Roadmap2026-09-07
- Agent Authorization Boundaries in Incident Response: When the Actor Is a Model2026-09-01
- Two witnesses disagree about prompt injection. Neither one is lying. Venturebeat picked it up.2026-08-26
- The AI Governance Playbook for AI You Adopted but Never Governed2026-08-20
- Third-Party AI Risk Assessment: A Checklist a Mid-Market Team Can Run2026-08-13
- AI Incident and Benchmark Trends: What the Record Shows2026-08-04
- The AI incident recovery readiness audit2026-07-27
- The AI security recovery gap your stack is hiding2026-07-27
- Securing Retrieval Augmented Generation: The Retriever Is Your New Attack Surface2026-07-14
- Measuring AI Control Effectiveness: What a Board Should Demand2026-07-07
- Third-Party AI Assurance Evidence: What a Vendor Can Produce2026-05-05
- AI Red Team Evaluation Methods: Telling a Real Test From a Demo2026-03-26
- AI Incident Response Playbook: When the Actor Is a Model2026-03-19
- LLM Supply Chain Security: What to Inventory Before You Adopt2026-03-12
- AI Model Inventory Requirements: The Fields That Earn Their Place2026-03-05
Latest from RockCyber Musings
- OpenAI Audited Its Bio Safeguards. It Skipped the Cyber Ones2026-09-08
- Weekly Musings Top 10 AI Security Wrapup: Issue 51: August 28 to September 3, 20262026-09-04
- AI Agent Detection Failed at OpenAI. Tuning Won’t Fix It.2026-09-01
- Weekly Musings Top 10 AI Security Wrapup: Issue 50: August 21 to August 27, 20262026-08-28
- Broken Object Level Authorization Is Now an AI Agent Problem2026-08-25
- AI Risk Assessment: Anthropic’s 186-Page Blind Spot2026-08-18
What I write about
- AI and agentic security: the threat models and controls that hold up in production.
- Governance that speeds teams up instead of becoming the thing they route around.
- Risk quantification: putting a number on AI exposure so a board can act on it.
Subscribe to the newsletter
Get RockCyber Musings in your inbox. It is free, and you can leave whenever you want.
