Writing
RockCyber Blog
RockCyber Musings is where I think out loud about AI security, governance, and the risk calls executives have to make. It's plain-language and written for the people who own the outcome.
Latest from the blog
- Prompt Injection Defenses: What Reduces Exposure and What Only Looks Like It Does2026-09-17
- Governance Security: The IANS Confidence Signals Are Not a Security Roadmap2026-09-07
- Agent Authorization Boundaries in Incident Response: When the Actor Is a Model2026-09-01
- Two witnesses disagree about prompt injection. Neither one is lying. Venturebeat picked it up.2026-08-26
- The AI Governance Playbook for AI You Adopted but Never Governed2026-08-20
- Third-Party AI Risk Assessment: A Checklist a Mid-Market Team Can Run2026-08-13
- AI Incident and Benchmark Trends: What the Record Shows2026-08-04
- The AI incident recovery readiness audit2026-07-27
- The AI security recovery gap your stack is hiding2026-07-27
- Securing Retrieval Augmented Generation: The Retriever Is Your New Attack Surface2026-07-14
- Measuring AI Control Effectiveness: What a Board Should Demand2026-07-07
- Third-Party AI Assurance Evidence: What a Vendor Can Produce2026-05-05
- AI Red Team Evaluation Methods: Telling a Real Test From a Demo2026-03-26
- AI Incident Response Playbook: When the Actor Is a Model2026-03-19
- LLM Supply Chain Security: What to Inventory Before You Adopt2026-03-12
- AI Model Inventory Requirements: The Fields That Earn Their Place2026-03-05
Latest from RockCyber Musings
- Weekly Musings Top 10 AI Security Wrapup: Issue 54: September 25 to October 1, 20262026-10-02
- Human in the Loop Is a Rubber Stamp. Its Replacements Are Too.2026-09-29
- Weekly Musings Top 10 AI Security Wrapup: Issue 53: September 18 to September 24, 20262026-09-25
- The Math Behind the AI Agent Restart Gate: OpenAI Hit Restart on July 7. The Hugging Face Breach Began July 8.2026-09-22
- Weekly Musings Top 10 AI Security Wrapup: Issue 52: September 11 to September 17, 20262026-09-18
- All AI Extinction Risk Panic Does Is Ban the Safer Model and Keep the Worse One.2026-09-15
What I write about
- AI and agentic security: the threat models and controls that hold up in production.
- Governance that speeds teams up instead of becoming the thing they route around.
- Risk quantification: putting a number on AI exposure so a board can act on it.
Subscribe to the newsletter
Get RockCyber Musings in your inbox. It is free, and you can leave whenever you want.
