Publications & standards
Publications and standards
The work I'm proudest of is the part other people can check. Named author positions, real papers, a book, and the OWASP standards teams. Here's the record, with links to the primary sources.
OWASP Top 10 for Large Language Model Applications 2026
The 2026 edition of the community standard for LLM application security. Updated rankings, wider threat coverage, and mitigations mapped to NIST, MITRE ATLAS and CWE. Second of twenty authors. DOI 10.5281/zenodo.22109015.
Incident-Data Robustness Analysis of the OWASP Top 10 for LLM Applications (2026): How a Community-Expert Ranking Holds Up Against a Large-Scale LLM Incident Corpus
Does the expert ranking agree with the incident record? We labeled 6,639 incidents drawn from CVE, GHSA, OSV and AIAAIC against the taxonomy and built a data-derived ranking to compare. Agreement is weak, at a Cohen's kappa near 0.20 with a 90% interval that crosses zero, and the expert ranking holds up anyway under a pre-registered bake-off of four frontier classifiers. First of two authors with Steve Wilson. An exploratory analysis by two working-group members, not an official OWASP release.
AAGATE: A NIST AI RMF-Aligned Governance Platform for Agentic AI
A platform that lines agentic-AI controls up with the NIST AI RMF, so governance has somewhere to live. Second of eleven authors, with Ken Huang and the CSA group.
LAAF: Logic-layer Automated Attack Framework. A Systematic Red-Teaming Methodology for LPCI Vulnerabilities in Agentic Large Language Model Systems
A method for surfacing logic-layer injection flaws in agentic LLM systems. Third of fourteen authors.

The CISO Evolution: Business Knowledge for Cybersecurity Executives
The book Matthew K. Sharp and I wrote to help security leaders carry the business conversation. Wiley, 2022.
LLM and GenAI Data Security Best Practices
Community guidance on protecting the data that trains and runs GenAI systems. A credited author on the OWASP team.
State of Agentic AI Security and Governance 2026
A survey of where agentic-AI security and governance stand in 2026. I co-led it with Ariel Fogel and Evgeniy Kokuykin.
