Intelligence Briefings for Security Leaders
CISO DEBRIEFS
Practitioner-grade analysis of AI threats, governance failures, and the attack patterns your board needs to understand.
Latest Post
Latest — Incident Response · Accountability Gap
AI IR + Accountability
An autonomous agent acts on authority you delegated. The runbook closes clean — systems restored — and still no one can say who was accountable. IR was built to end with a name. This one ends with a question.
Read the DebriefAll Debriefs
Ransomware & Recovery Integrity
Ransomware + AI
Old ransomware encrypts your data and you restore from backup. This one poisons your agent mesh — and no backup contains a clean version of every decision your agents already made and propagated.
Identity Governance & Machine Credentials
Non-Human Identities
A service account with a long-lived token, scoped to everything and owned by no one, leaks in a forked repo. An attacker assumes the agent’s identity, mints fresh tokens, and reads every customer record.
Agentic Governance & Shadow Infrastructure
Shadow Agents
A regional director connects an AI agent to her work email. It operates for six weeks. Then a phishing email arrives. The agent drafts the wire transfer response. She approves. The wire processes.
Agentic Evasion & Forensic Blindness
Ghost Agent
A malicious AI agent executes its task, exfiltrates data through an authorized channel, and self-terminates — leaving no logs, no trace, no forensic record. Normal termination is the attack.
Model Theft & IP Extraction at Scale
Model Farming
Distillation is the technique. Farming is what happens when it gets industrialized — rotating accounts, distributed infrastructure, automated pipelines running against dozens of targets simultaneously.
Model Theft & IP Extraction
Model Distillation
You spent millions building it. I spent an API key and four months extracting it. Nobody secured what you were saying on the other side of your perimeter.
AI Supply Chain · Third-Party Risk
AI Supply Chain Attacks
The model you deployed was clean. The update wasn’t.
Prompt Injection · Social Engineering
Weaponized Trust
They Didn’t Hack You. They Read Your Job Posting.
Coming Soon
The Unintentional Insider
The Unintentional Insider
No attacker. No breach. Just an employee pasting proprietary data into a chatbot — and a data-loss path your controls were never built to see. The insider threat with no malice and no intrusion.
Coming Soon — Digital Content Series #10
When AI Attacks
Get the next debrief
before your board does.
New AI threat debriefs — prompt injection, agentic attacks, identity failures — the moment they publish.
Subscribe to the SeriesFree · No spam · Unsubscribe anytime