AI advisory
Strategic and architectural advisory on AI in security, for the CISO, the leadership team, and the board.
At FM CyberSecurity we use AI for everything from building presentations and developing AI-based security monitoring (Agentic SOC) to writing software. We have learned a lot about using AI, not least in the context of secure development.
- How do you secure AI agents and assistants?
- How can you safely let the business build its own applications and services?
- How do we secure the supply chain?
- How do we prevent business-critical data from being leaked by AI?
What we deliver
- AI risk register and governance framework
A dedicated register for AI risk, wired into existing risk management, with named owners and a decision cadence.
- Shadow AI policy and discovery strategy
The decision work before any operational discovery, what is allowed, what is logged, what is blocked.
- Agentic SOC adoption read
When an agent-driven SOC architecture fits your context, and when it does not.
- AI-assisted code policy
Governance for vibe coding inside engineering teams, from approved tools to SDLC requirements.
- EU AI Act readiness for in-scope systems
Classification of AI use against the AI Act categories, and what has to be documented per system.
- Board-level AI risk briefing
A half-day briefing scoped to the board meeting, in the language the board uses to make decisions.
How we deliver this service
- In a project
A bounded advisory engagement, typically two to six weeks, with written recommendations.
- As part of a service
The strategy layer above an operational AI-security engagement, or included in Secured by FM CyberSecurity.
- In a role at the customer
An ongoing AI governance advisor with a fixed cadence, for organisations that want to keep the topic live.
The platform we offer
Recent insights on AI advisory
- News from Fal.Con: CrowdStrike's September AI security announcements
Falcon Guardian, agent identities, package protection and Charlotte AI: what CrowdStrike announced in September and what businesses should check before adopting it.
- Falcon Guardian: putting limits on what AI agents can do
CrowdStrike is extending AI security into agent activity. Here is what Guardian adds and what we would check before a rollout.
- Researchers link May's RubyGems abuse to OpenAI agents
RubyGems removed more than 500 malicious packages in May. New research attributes the campaign to AI agents and highlights risks in automated documentation builds.