IT Security

prompt injection risk assessment business ai a hexagonal shield upright

Prompt Injection Risk: Essential Safe Assessment Guide

Prompt injection is the one attack class against business AI that has no structural fix, because instructions and data reach a language model through the same channel. This guide turns that into something you can manage: where injected instructions actually enter a business system, how to scope an assessment so it finishes in days, a ten-question likelihood and impact matrix anchored to observable facts, a control map showing which measures leave a low residual and which depend on the model behaving, how to build an injection corpus and test the boundary rather than the model, how to record findings in a register an auditor can follow, who owns the risk and what UK and EU regulators expect, realistic costs, and a 90-day plan.

Read more
ai agent security tools and system access a padlock shackle shut

AI Agent Security: Essential Guide to Safe Tool Access

The moment you connect a language model to a ticketing API, a finance system, a mailbox or a shell, you stop shipping a chat feature and start shipping a new class of privileged user. This guide covers the engineering work that keeps that user contained: how to classify and scope tools into risk tiers, why an agent needs its own identity and short-lived credentials rather than a shared service account, how to contain the blast radius of a single compromised run with sandboxing and default-deny egress, where to place human approval gates so they are decisive rather than theatre, what actually works against indirect prompt injection arriving through retrieved content, what to log so an incident is investigable, how to test the controls before launch, and a 90-day rollout plan with realistic costs and named owners.

Read more
AI red-teaming - ai red teaming what to test before launch a hexagonal shield upright

AI Red-Teaming: Essential Tests to Run Before a Safe Launch

Most AI systems reach launch having been tested only by people trying to make them work. Adversarial testing asks the other question: what happens when someone actively tries to make the system misbehave. This guide sets out what to test before go-live — how to scope the exercise and define harm in your own domain, the five attack classes that matter for business deployments, whether to run it internally, buy it in or automate it, how to score findings so severity cannot be renegotiated after the fact, which fixes actually hold, what the work costs in person-days and pounds, and the evidence pack that answers an enterprise security questionnaire and maps onto the EU AI Act, ISO 42001 and the NIST AI Risk Management Framework.

Read more
CHAT