Field notes

Securing the agentic enterprise, one defensible framework at a time.

Opinionated, practitioner-led writing for CISOs, CIOs, AI leaders, board members, and security architects.

Topical authority map

Eight pillars, one point of view.

Each pillar earns search authority while reinforcing the same mental model: AI security is agent perimeter management.

01

The New Perimeter

Framework, attack surface mapping, Zero Trust to Agent Trust, and CISO first 90 days.

02

Enterprise AI Agent Security

MCP, agent actions, multi-agent risk, browser agents, and runtime isolation.

03

Prompt Injection

Direct and indirect injection, RAG security, testing methods, and OWASP LLM translation.

04

Governance, Risk & Compliance

NIST AI RMF, ISO 42001, vendor risk, NYDFS, acceptable use, and incident response.

05

AI Red Teaming

Enterprise methodology, model extraction, continuous testing, internal capability, and reports.

06

Non-Human Identity

Agent identities, OAuth scopes, service accounts, NHI audits, and privilege crisis.

07

Industry Deep Dives

Financial services, healthcare, SaaS, and sector-specific regulatory risk.

08

Transformation × Security

AI-native enterprise adoption, CIO-CISO partnership, maturity models, and safe scale.

Newsletter

Weekly field note

One sharp take, one useful framework, and one practical action for security leaders.

Newsletter

Get the field note security teams forward to leadership.

Weekly writing on agent security, AI governance, prompt injection, red teaming, non-human identity, and enterprise transformation risk.

Join the list