Insights · page 1
Board-level security writing
Agentic AI and MCP Security for Fintech
12 June 2026
Secure agentic AI and the Model Context Protocol in regulated finance: the autonomy spectrum, connector supply chain, scoped identity, and a kill switch.
AI assurance evidence for auditors
12 June 2026
AI assurance evidence is the gap most programmes ignore. Here is how to build a control-to-evidence map your internal auditor can test independently.
AI governance and board accountability
12 June 2026
AI governance in a regulated firm needs four targeted additions to your existing risk machinery, with named accountability attached before an incident.
AI incident response and resilience
12 June 2026
AI incident response needs its own playbook: extend your IR process, build a kill-switch decision tree, and design resilience for non-deterministic AI.
Data poisoning defences for fintech AI
12 June 2026
Data poisoning is the quiet threat in fintech AI: planted in grounding data, it fires long after you stop looking. How to defend what you control.
NIS2 and UK NIS for AI systems
12 June 2026
NIS2 does not vanish for FS firms because DORA applies. Where NIS2 and UK NIS still bite on AI estates, supply chains, and group structures.
Quantifying AI risk for the board
12 June 2026
How to move from heat maps to money-denominated loss distributions when quantifying AI risk for boards and CROs, with autonomy as the key magnitude multiplier.
Runtime monitoring for AI agents
12 June 2026
Runtime monitoring for AI agents means more than application logs. What to instrument, how to detect abuse in production, and how to bound damage early.
Secure by design AI agents and MCP
12 June 2026
Secure by design for AI agents is not a post-launch phase. Identity, least privilege, MCP hardening, and the gateway control plane, in plain terms.
Securing decisioning copilots in finance
12 June 2026
Decisioning copilots in credit, fraud, and disputes need per-domain autonomy ceilings, not just output filters. Here is the framework I use.