Skip to content

Cyber Security

The surfaces that did not exist in the last control review

Security for systems that act autonomously, for plant and physical processes that were never designed to be networked, and for a cryptographic estate with a migration deadline attached to it.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    AI & LLM Application Security Testing

    CloudHybridAdviseBuild

    Adversarial testing of AI features against the failure modes that are specific to them.

    • Prompt injection, jailbreak, tool-abuse and data-exfiltration testing
    • Retrieval pipeline, plugin and function-calling boundary review
    • Model, prompt and output-handling remediation with regression tests
  2. 02

    AI Governance & Assurance

    On-PremCloudHybridAdvise

    A control framework for AI systems that maps to recognised management-system and risk standards.

    • AI system inventory with use-case risk classification
    • Policy, approval gates and human-oversight requirements by risk tier
    • Model documentation, evaluation records and audit evidence pipeline
  3. 03

    Agentic AI Security & Runtime Guardrails

    CloudHybridAdviseBuild

    Let autonomous agents act without granting them unbounded reach.

    • Agent inventory across sanctioned and unsanctioned deployments
    • Tool-use, data-access, spend and rate boundaries per agent
    • Runtime monitoring, anomaly detection, kill-switch and rollback design
  4. 04

    Shadow AI Discovery & GenAI Data Protection

    CloudHybridBuildRun

    Find where corporate data is leaving through personal AI accounts, and close it without banning the category.

    • Discovery of unsanctioned AI tool and model usage
    • Data-egress inspection and policy at browser, endpoint and gateway
    • Sanctioned-alternative rollout with coaching and usage telemetry
  5. 05

    OT / ICS / SCADA Security

    On-PremHybridAdviseBuild

    Protect production on equipment that cannot be patched on your schedule and must not be interrupted.

    • Passive asset discovery and zone-and-conduit modelling
    • Assessment and segmentation aligned to industrial control standards
    • Protocol-aware monitoring and OT-specific response playbooks
  6. 06

    IoT & Connected Device Security

    On-PremCloudHybridAdviseBuild

    Bring the unmanaged, unpatchable device population under policy without breaking what it does.

    • Device discovery, fingerprinting and risk tiering
    • Network isolation, least-function and egress-control policy
    • Firmware, certificate and credential lifecycle governance
  7. 07

    Post-Quantum Cryptography Readiness

    On-PremCloudHybridAdviseBuild

    Begin the migration while long-lived secrets are still worth protecting, and make the estate agile enough to migrate again.

    • Cryptographic inventory and crypto-agility assessment
    • Prioritised migration plan driven by data lifetime and certificate validity
    • Hybrid key-establishment and protocol transition design with test harness
  8. 08

    Forensic Readiness & Cyber Insurance Assurance

    On-PremCloudHybridAdvise

    Be able to evidence an incident to an insurer, a regulator and a court without improvising.

    • Evidence coverage, retention and readiness assessment
    • Insurer control questionnaire and warranty support
    • Claim-grade incident documentation and notification standards

Technical deep dive

Giving autonomous agents real authority without unbounded reach

Applies wherever AI agents have been connected to production systems - which increasingly happens on low-code platforms outside the change process, by teams who are solving a real problem.

What this is

An agent control plane. Every agent has a registered identity with a named human owner, receives short-lived credentials scoped to a declared purpose, and reaches enterprise systems only through a tool broker that authorises each call against policy. Every action is logged to the same place human actions are, and every agent has a stop control that does not depend on the platform it runs on.

The problem being solved

A support team connects an agent to triage tickets. To make it work quickly it is handed a broadly scoped API credential. It now reads mailboxes, writes to the customer system, calls a payments endpoint and can open remote sessions. It does not appear in the identity inventory, because it is not a person. It did not pass change control, because it was built on a platform the technology function does not administer. Nine more exist across the organisation. None has an owner recorded, a permission boundary, a spend limit or an audit trail that survives the platform's own retention. The agent is also a novel attack surface: content it retrieves is instruction-shaped, so a crafted ticket can redirect its behaviour.

Why it is hard

  • The agent is a confused deputy by construction. It holds legitimate authority and acts on untrusted input, so the classic mitigation - validate the input - does not apply cleanly when the input is the task.
  • Static permission models do not fit. The agent's required scope varies per task, and granting the union of all tasks is exactly the over-privilege that caused the problem.
  • Platform-native controls are not enough. If the stop control lives in the vendor's console, an incident depends on that console being reachable and on someone knowing it exists.

Reference architecture - step through it

all
INITIATIONAGENT RUNTIMEMEDIATIONENTERPRISE & OVERSIGHTRequesting humandelegates bounded authorityEvent triggerticket, webhook, scheduleUntrusted contentmay contain injectedinstructionsAgent registryowner, purpose, blast radiusAgent runtimeplans and calls toolsContext assemblyretrieval, provenance taggedInput & output guardsinjection, exfiltration, PIIAgent identity serviceshort-lived, purpose-scopedTool brokerevery call authorisedAuthorisation policytool × scope × object × budgetRate & spend limitsper agent, per taskHuman approval gateirreversible actionsEnterprise systemsCRM, mail, payments, recordsAction ledgersame log as human activityBehavioural monitoringdeviation from declaredpurposeStop controlplatform-independentrevocationdelegatestaintedrevoke credentials
A registered agent, bounded by policy rather than by promptyaml
agent:
  id: agt-support-triage-01
  owner: j.okafor (support-ops)          # a human, always
  purpose: "Classify inbound tickets and draft a first response."
  blast_radius: tier-2                   # customer data, no financial systems
  platform: low-code-automation          # registered even though IT doesn't run it
  review: quarterly | on_purpose_change

credentials:
  type: workload_identity                # no static API key, anywhere
  ttl: 10m
  scope_source: declared_purpose         # not the union of what it might need
  issued_per: task

authorised_tools:
  - tool: tickets.read
    objects: {queue: [support-tier1], age: "<30d"}
  - tool: tickets.comment
    constraints: {visibility: internal_draft}   # cannot publish unreviewed
  - tool: crm.read
    objects: {fields_deny: [payment_instrument, national_id, health_notes]}
  - tool: kb.search
denied_tools: [mail.send_external, payments.*, remote_session.*, crm.write]

budgets:
  model_spend_per_day: 40_usd
  tool_calls_per_task: 25
  objects_touched_per_hour: 200
  on_breach: suspend + notify_owner

content_handling:
  retrieved_content: tainted             # a ticket body is data, never instruction
  taint_rule: >
    Instructions found in tainted content cannot expand scope, call a
    denied tool, or alter budgets. Attempts are logged as INJ-ATTEMPT.
  output_guards: [pii_egress, secret_pattern, external_link_rewrite]

human_gate:
  required_for: [customer_visible_response, refund_suggestion, account_change]
  context_shown: [object_ref, diff, tool_trace]

observability:
  action_log: unified_audit              # same store as human activity
  behavioural_baseline: declared_purpose
  alert_on: [scope_deviation, injection_attempt, budget_breach, off_hours_burst]

stop_control:
  mechanism: revoke_at_identity_service  # not the vendor console
  effect_time: "< 10s"
  authority: [support-ops-lead, security-duty-officer]

Measured change

MeasureBeforeAfter
Agents with a registered owner0 of 1010 of 10, reviewed quarterly
Standing credentials held by agentsadmin-scoped, non-expiringnone - 10-minute, task-scoped
Tool calls authorised individually0%100%, via broker
Injection attempts detected and containedinvisiblelogged, scope-bounded, alerted
Time to stop a misbehaving agentunknown - vendor consoleunder 10 seconds, self-owned

The agents kept working, and the team kept the productivity that made them build one. What changed is that each has an owner, an authority that expires, and an investigation path that answers what it did and on whose behalf.

Talk to an AI, OT & emerging technology security specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours