AI advisory
Strategic and architectural advisory on AI in security, for the CISO, the leadership team, and the board.
At FM CyberSecurity we use AI for everything from building presentations and developing AI-based security monitoring (Agentic SOC) to writing software. We have learned a lot about using AI, not least in the context of secure development.
- How do you secure AI agents and assistants?
- How can you safely let the business build its own applications and services?
- How do we secure the supply chain?
- How do we prevent business-critical data from being leaked by AI?
What we deliver
- AI risk register and governance framework
A dedicated register for AI risk, wired into existing risk management, with named owners and a decision cadence.
- Shadow AI policy and discovery strategy
The decision work before any operational discovery, what is allowed, what is logged, what is blocked.
- Agentic SOC adoption read
When an agent-driven SOC architecture fits your context, and when it does not.
- AI-assisted code policy
Governance for vibe coding inside engineering teams, from approved tools to SDLC requirements.
- EU AI Act readiness for in-scope systems
Classification of AI use against the AI Act categories, and what has to be documented per system.
- Board-level AI risk briefing
A half-day briefing scoped to the board meeting, in the language the board uses to make decisions.
How we deliver this service
- In a project
A bounded advisory engagement, typically two to six weeks, with written recommendations.
- As part of a service
The strategy layer above an operational AI-security engagement, or included in Secured by FM CyberSecurity.
- In a role at the customer
An ongoing AI governance advisor with a fixed cadence, for organisations that want to keep the topic live.
The platform we offer
Recent insights on AI advisory
- CrowdStrike links PhantomRaven malware to likely AI-written code
CrowdStrike's new PhantomRaven report connects likely AI-written malware, npm packages and bug bounty activity. Here is what the findings establish.
- CrowdStrike uses AI on the PC to recognise sensitive information
Falcon Data Security aims to recognise confidential information in ordinary text. Here is how classification on the PC works.
- What is CrowdStrike Agentic Identity Provider?
Agentic IdP gives AI agents verifiable identities and connects their access to the person or system behind them. Here is how it relates to Guardian and Continuous Identity.