ai · security · skills

Library

The library of fitted skills,tied to the people who need them.

Browse demonstrations, perspectives, and report-method notes in one archive. Below: an FAQ for each assessment, and a LinkedIn door to critique the method.

The archive

Every demonstration, perspective, and report-method note, filterable by what you need.

Browse fitted-skill proofs, the thinking behind the method, and the report-method deep-dives. Each card names a role and the problem it closes.

Demonstration

Your guard caught half the attacks, and you didn’t know until it was measured

Baseline a shipped guard on a fixed corpus, fit it (don’t replace it), re-score: 53% → 100% catch, held-out included. The tollgate #4 worked example.

Solves: “Your old gates catch bad code.” AI artifacts fail in behaviour, not syntax — and no one measured the guard.

For DevSecAIOpsRead →
Demonstration

Security Operations: when AI outran its controls

Fit triage to your named noise, drop false positives to zero with real attacks still caught, and turn the freed hours into hunting. The gate, demonstrated end…

Solves: The board’s red function — autonomy ahead of governance in the SOC, and a queue that’s mostly your own noise.

For Function headRead →
Demonstration

Governance was present. Comprehension was missing.

Ask a rule in plain language, in your own language; the answer cites the actual clause, or abstains and routes to the owner. The Explain instrument’s evidence…

Solves: “Am I allowed to do this?” — the policy exists, but nobody can find or parse it at the moment of need.

For Security newcomerRead →
Demonstration

We gave one helper the keys. The locked doors stayed locked.

One assistant, working from Slack and Telegram, drives the scanner, the rulebook and the scoring end to end. It goes everywhere and still cannot delete, cannot…

Solves: “If we let an AI actually run things, what stops it going where it shouldn’t?”

For PractitionerRead →
Demonstration

1,073 skills entered the pipeline. 35 findings surfaced. One scan.

Build a bill of materials for every skill. Infer capabilities from code. Run static analysis. Construct an attack graph. Here's the complete methodology.

Solves: "We have 1,073 skills. Some are dangerous. Which ones? And which combinations create attack paths?"

For PractitionerRead →
Demonstration

Initech: ISO 27001, 27701, and 42001 from one AICM run

Same GRA answers rolled through CSA’s 27001, 27701, and 42001 mappings on the AI Controls Matrix (AICM). The delta: gold-standard security, sparse privacy…

Solves: “Where does the ISMS end, what does privacy add, and what is AI-only?”

For Function headRead →
Demonstration

Initech: NIST 800-53, CSF 2.0, and AI RMF compared with CSA AICM

Same GRA answers: 800-53 and CSF via the Cloud Controls Matrix (CCM) bridge; AI RMF as the peer frame to the CSA AI Controls Matrix (AICM)…

Solves: “Where does foundational NIST end, and how does AI RMF compare to AICM?”

For Function headRead →
Demonstration

Initech: CSA AI-CAIQ STAR Level 1 readiness pack

Phase-1 GRA domains on the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) v1.1.0: Yes/No/NA answers, domain dashboard, priority findings — Big-4…

Solves: “What would a STAR for AI Level 1 self-assessment look like for our GRA baseline?”

For Function headRead →
Demonstration

Initech: Quick Mythos Vulnerability Assessment

Same Tier-1 instrument as /assess/quick: indicative headline, five VM areas, gap register. GRA postures where AI Controls Matrix (AICM) ids overlap.…

Solves: “Where is the VM foundation missing before we dig into one function?”

For Function headRead →
Perspective

What Claude Mythos Means for Your Security Program

Anthropic’s Mythos found thousands of zero-days and chained them into exploit paths; the UK AI Security Institute (AISI) showed autonomous attack capability…

Solves: The home-page threat concern — AI-discovered zero-days and autonomous attack capability — mapped to the vulnerability play and the gate.

For CISO · 11 June 2026 · 6 min readRead →
Perspective

Why Most AI Security Pilots Don't Survive Production

Between 2023 and 2025, the global enterprise market spent four to seven billion dollars on AI security pilots. Most produced no production capability. The five…

Solves: $4–7B spent on pilots, little production capability — the five structural failure modes the methodology is built to avoid.

For Leadership · 26 May 2026 · 14 min readRead →
Perspective

Choosing the Control Spine: CSA, Forrester AEGIS, and Gartner AI TRiSM

Three kinds of artifact compete for the same decision: open consensus control standards, paywalled analyst operating frameworks, and management-system…

Solves: “Which framework do we anchor on?” — why this practice runs on CSA, and where the analyst lenses genuinely add.

For Compliance · 9 July 2026 · 16 min readRead →
Perspective

How a Skill Is Built and Fitted to Your Function

A thousand unfitted skills are inventory, not capability. How a skill is structured as an executable procedure, the seven steps to author one, and the six…

Solves: “A thousand skills is inventory, not capability” — the engine that fits a generic skill to a function’s real tools and process.

For Practitioner · 9 June 2026 · 7 min readRead →
Perspective

The AI Security & Safety Center of Excellence: A Modular Build Playbook

Build an internal AI Security & Safety Center of Excellence (CoE) as a hub-and-spoke operating model anchored on the CSA AI Controls Matrix (18 domains, 247…

Solves: “How do I stand up an AI Security CoE — and then operate it?” — the modular build, sequenced from the SOC, and how to run it.

For CISO · 31 May 2026 · 35 min readRead →
Method

The AICM Coverage Assessment

A maturity grade without a control inventory is an opinion. The coverage assessment fixes the territory first: one evidence-backed answer per AI Controls…

Solves: The two-axis read of one function: how well it’s governed × how far AI has been let to act.

For Function head · 3 June 2026 · 5 min readRead →
Method

Placing a Function on the AISMM Scale

The scorecard grades the checklist, not the other way round. How a maturity placement is bounded by coverage evidence, justified in writing, and moved one…

Solves: The two-axis read of one function: how well it’s governed × how far AI has been let to act.

For Function head · 3 June 2026 · 5 min readRead →
Method

The Shared Security Responsibility Model (SSRM) Ownership Map

AI controls fail quietly in the gaps between organisations. The shared-responsibility matrix surfaces ownership gaps, chain mismatches, and the justified NAs…

Solves: The two-axis read of one function: how well it’s governed × how far AI has been let to act.

For Function head · 3 June 2026 · 5 min readRead →
Method

The Prioritised Remediation Roadmap

Severity-ordered backlogs stall; effort-to-impact ships defensible wins early and funds the harder lines. The roadmap is the budget conversation pre-written:…

Solves: The two-axis read of one function: how well it’s governed × how far AI has been let to act.

For Function head · 3 June 2026 · 4 min readRead →
Method

The External-Assurance Artefact

The same questionnaire serves two audiences on the same control spine. What the AI-CAIQ attests, what STAR for AI Level 1 is — and emphatically is not — and…

Solves: The two-axis read of one function: how well it’s governed × how far AI has been let to act.

For Function head · 3 June 2026 · 5 min readRead →

Assessment FAQ

The three assessments, answered.

How to take each one, how to read its report, and the methodology underneath — an aid to the CTA assessments, not a substitute.

For: Function headQuick Mythos Vulnerability Assessment

A ten-minute on-ramp — where a foundation is missing, before the deep dive.

How long, and how many questions?

Forty questions across five vulnerability-management domains, about ten minutes. Every answer carries forward into the full function diagnostic, so nothing is wasted.

What does it produce?

A fast, indicative Mythos vulnerability read that flags where a foundation is missing — where to dig first. Not the per-function deep dive, and nothing here is measured.

How does it connect to the rest?

The questions map to AI Controls Matrix (AICM) control areas; it’s the tier-1 on-ramp to the function diagnostic, not a standalone score.

Take the quick mythos vulnerability assessment
For: Function headFunction diagnostic

The two-axis read of one function: how well it’s governed × how far AI has been let to act.

What do I actually answer?

Pick a function, then answer what’s in place — evidence, not opinion — across two steps: Govern (AI Security Maturity Model (AISMM) maturity) and Adopt (AI Cyber Maturity Model (AI-CMM) autonomy). Around fifteen questions, each tied to a real control.

What’s in the report?

Two radars — governance maturity (AISMM) and AI autonomy (AI-CMM) — the gate reading between them, a per-category ladder, a peer benchmark, a gaps register, and a ranked action plan of the few fitted moves that raise the number. Compatible-standard packs (ISO, NIST, AI Consensus Assessments Initiative Questionnaire (AI-CAIQ)) are lenses on the same AI Controls Matrix (AICM) answers — samples on /reports, not a second questionnaire.

What is the methodology, exactly?

Every question maps to a real AICM control objective; a maturity level is bounded by coverage evidence, never self-asserted; the gate flags any function whose autonomy outruns its governance. The deep dives below explain each deliverable.

Take the function diagnostic
For: PractitionerSkill mastery

Track 2: four concrete rungs per control for the skills your seat owns.

What is it?

A personal mastery check on the same CSA control spine as the org diagnostic — re-read per seat. Each prompt has four concrete rungs from initial to optimum, then fitted skills from your gaps.

What do I walk away with?

A self-assessed reading: average current vs target, whether your personal gate is open (gate-blocking skills below Leads), and the next skills to climb. Nothing is saved.

How does it connect to the org assess?

Same AICM controls, different job: org maturity grades the function; mastery names what you learn next. Not a second framework and not measured evidence.

Take the skill mastery

Discuss

Critique the method. Bring a seat story.

This research practice gets sharper when practitioners push back on a sample or share what their role actually needs. LinkedIn is where that conversation lives today.

Curated by Binu Chacko. An independent research practice on AI security, safety, and privacy.

No paywall and no in-site forum — feedback stays on LinkedIn, then comes back into Maturity or Skills.

Pressure-test the function. Build the defender’s skills.

Same underlying answers. One door scores the function. The other names the skills the defender builds next.