skills
AI SecurityLLM Prompt EngineeringOWASP Top 10 for LLMsGenerative AIModel Context Protocol (MCP)AI Agent SecurityGovernanceThreat ModelingAccess ControlData Protection+5
the problem
No internal baseline for what "secure adoption" means
starting point
An organisation exploring AI capabilities needed visibility and control across models, coding agents, prompts, data flows and external integrations — with no internal baseline for what "secure adoption" even means.
what i did
From vague AI risk to a testable control set
- Defined security requirements for AI adoption: asset discovery, real-time monitoring, input and output controls, policy enforcement, human oversight, access control, model testing, security integrations and operational reporting
- Reviewed AI coding agent deployments end to end — including agent permissions (e.g. pull-request write access to source repositories), API key storage on developer machines, and MCP/tool-integration security
- Produced procurement-grade requirements that both technical and non-technical stakeholders could evaluate
engagement flow
How the engagement flowed
Four phases, four steps — click any step to see what happened and why it mattered.
outcome
Fast adoption on an evidence-based footing
Value created
The organisation could move quickly on AI adoption with a defined, evidence-based control set — requirements that survive vendor conversations and procurement scrutiny rather than generic AI policy statements.
key capabilities
AI securityrequirements engineeringdata protectiongovernanceagent & integration security