The Operating Discipline for AI Library™
Book 05
The AI IT Security Audit™
The exposure your dashboards cannot see.
Available now
A CISO-grade audit framework for proving AI exposure is known, controlled, and governed. Built on The Visibility Triangle and the six domains of the modern security portfolio, it produces an exposure map, a remediation roadmap, a regulatory crosswalk, and a board briefing that survives scrutiny.
The Operating Discipline for AI Library™
Book 06
The AI IT Security Implementation & Strategy™
The question your board will ask. The proof you don’t have yet.
Available now
The operating manual for proving AI risk is governed: ratified policies, an integrated risk register, a regulatory crosswalk, and board reporting that works at a glance. Following the audit’s exposure map, this book builds the governance machinery — a discipline to operate, not a project to complete.
The Operating Discipline for AI Library™
Book 07
Secure by Design in the Age of AI™
Closing the velocity gap before regulators do.
Available now
Engineering velocity is up an order of magnitude. Security review capacity is not. At the same time, AI introduces vulnerabilities that deterministic tooling cannot reliably find. This book introduces The Dual-Impedance Problem and the five working frameworks that produce a defensible Secure by Design operating model for AI-enabled products.
The Operating Discipline for AI Library™
Book 08
Application Security in the Age of AI™
AppSec for applications that no longer behave deterministically.
Forthcoming
Every AppSec tool in production was built on the assumption that an application produces the same output for the same input. AI invalidated that assumption. This book introduces The Runtime Determinism Gap and the AppSec program model executives need when scans pass and applications still fail in production.
The Operating Discipline for AI Library™
Book 09
Cloud and Infrastructure Security in the Age of AI™
Governance for a cloud where most actors are not human.
Forthcoming
Cloud security was built on the premise that every meaningful action could be traced to an accountable human. The identity ratio inverted, infrastructure pace outran governance pace, and the audit chain stopped answering its own question. This book introduces The Sovereignty Problem and the operating model cloud security leaders need to catch up.