Prompt injection
Crafted inputs manipulate the model — unauthorized access, data exfiltration, or corrupted decisions. Still ranked #1 by OWASP.
A live walkthrough of how we move organisations from 'we have an AI policy' to 'we have enforceable, auditable, evidence-backed AI controls.' Click through, evaluate, and see the method work.
of orgs reported a GenAI-related security incident in the past year
have full visibility into AI training data
of agentic AI projects may be cancelled by end of 2027 due to costs, unclear value, or inadequate risk controls
OWASP LLM risks your org faces right now
OWASP's 2025 list reflects what happens when LLMs enter customer interactions, internal operations, and embedded workflows. Every organisation faces all of them.
Crafted inputs manipulate the model — unauthorized access, data exfiltration, or corrupted decisions. Still ranked #1 by OWASP.
LLMs surface PII, credentials, and financial records in outputs — often without anyone noticing until it's too late.
When agents can call APIs, send email, and update records autonomously, one bad decision cascades fast with no human gate.
Models sound confident even when wrong — hallucinated facts and fabricated citations wrapped in polished prose.
Employees using unsanctioned AI tools place data, IP, and compliance obligations outside any audit trail you control.
Third-party models, datasets, and RAG sources introduce vulnerabilities you may not discover until a decision goes wrong.
This is how we train workers to evaluate AI output before acting on it. Pick a scenario, work through the checks, and see the verdict logic resolve.
"Per HIPAA Section 164.312(a)(2)(iv), your organization is required to implement encryption for all ePHI at rest. Based on this requirement, I recommend approving the vendor's data processing agreement immediately."
Click each check to evaluate this output against the STOP–CHECK–DECIDE method.
0 / 4 checks evaluated
Real governance is not a single deliverable. Each example below is a working artefact from live engagements — assessment, treatment, response, readiness, and oversight — tied together by the same control stack.
A 220-person professional services firm engaged us to assess current AI use, identify regulatory exposure, and produce an executive-ready remediation roadmap.
Writing a policy is not governance. We build the controls, evidence, and escalation paths that actually work when something goes wrong.
Discover every AI agent, tool, connector, owner, and risk level across the organisation.
Map each agent to OWASP 2025 risks and assign control depth based on exposure.
Enforceable gates — tool allowlists, human approval flows, prompt-injection testing.
Immutable logs, reviewer records, and regulator-ready audit trails.
Worker training, escalation paths, and ongoing monitoring — governance that lives.
Large or small, regulated or not — your organisation faces the same AI risks. Engagements are sized and priced to match.
Map current AI tools, controls, and gaps against OWASP 2025 and applicable regulatory frameworks.
Inventory, risk tiering, tool allowlisting, data classification, and human-in-the-loop design.
STOP–CHECK–DECIDE modules, role-based risk training, shadow AI awareness.
Acceptable-use policies, decision logs, and audit-ready evidence built for real scrutiny.
Monthly governance reviews, incident response support, and emerging-risk updates.
Sized for the SME and the enterprise alike. Same rigor, different scope.
A complimentary 30-minute governance gap review. No pitch — just clarity on where your organisation stands.