Publications & standards
Publications and standards
The work I'm proudest of is the part other people can check. Named author positions, real papers, a book, and the OWASP standards teams. Here's the record, with links to the primary sources.
AAGATE: A NIST AI RMF-Aligned Governance Platform for Agentic AI
A platform that lines agentic-AI controls up with the NIST AI RMF, so governance has somewhere to live. Second of eleven authors, with Ken Huang and the CSA group.
LAAF: Logic-layer Automated Attack Framework. A Systematic Red-Teaming Methodology for LPCI Vulnerabilities in Agentic Large Language Model Systems
A method for surfacing logic-layer injection flaws in agentic LLM systems. Third of fourteen authors.

The CISO Evolution: Business Knowledge for Cybersecurity Executives
The book Matthew K. Sharp and I wrote to help security leaders carry the business conversation. Wiley, 2022.
LLM and GenAI Data Security Best Practices
Community guidance on protecting the data that trains and runs GenAI systems. A credited author on the OWASP team.
State of Agentic AI Security and Governance 2026
A survey of where agentic-AI security and governance stand in 2026. I co-led it with Ariel Fogel and Evgeniy Kokuykin.
