Notes from the practice
Writing on quantitative cyber risk, secure AI, and building security functions that hold up under scrutiny.
- 8 min read
Your risk register is not a model
What Douglas Hubbard's work should change about how we analyse cyber risk, with one register row converted from a colour to a loss exceedance curve.
- 5 min read
When your AI assistant becomes the attack vector
A 2026 red-team exercise turned a compromised AI account into remote code execution by poisoning a synced preference. The assistant is now a social-engineering channel.
- 6 min read
Multi-criteria decision analysis: AHP and value functions
How structured decision methods turn conflicting objectives and subjective judgement into numbers a board can defend, and where AHP and value functions each fit.