How it works
Build the capability one team at a time.Prove it before you scale.
Pick one security team. Fit a little AI help to the way it already works, and measure what changes. No big-bang, and nothing to rip out.
Assess: One function, honestly measured. The diagnostic sets the baseline everything after is judged against.
The idea
A way of working, not a tool to buy.
Every team is picking up AI on its own. You can’t secure what you can’t see, and you can’t fund what you can’t measure. So instead of one big programme, this builds real capability the safe way: one team, one job, one measured result at a time. One questionnaire runs both tracks: it grades the team, and it names what each person on it learns next.
The method
Three short steps.Each one ends in a go or no-go.
You only fund the next step once the last one has paid off. That’s what keeps it low-risk.
Phase 1 · A few weeks
Assess
Baseline one team on evidence — where it really stands today. Nothing changes in your tools.
You walk away with
A one-page read: the top gaps and the one or two moves worth funding.
Phase 2 · A few weeks
Pilot
Fit one helper to that team’s real work, and capture the number before and after.
You walk away with
A measured before-and-after, and a helper you keep and can reuse.
Phase 3 · Ongoing
Scale
Roll the proven pattern across the team, then on to the next one.
You walk away with
A repeatable pattern — the next team is faster than the first.
Why assess · the loop
You assess to earn the next rung of autonomy.
The diagnostic reads a function on two axes: how well its AI is governed, on the AI Security Maturity Model (AISMM, L1–L5), and how far its work is automated, on the AI Cyber Maturity Model (AI-CMM, L1 Manual→L4 Autonomous; our model · calibrated to SAE J3016, never a CSA or SAE rating). The gate connects them: autonomy must never outrun governance, because autonomy without measured governance is unpriced risk.
The industry frames it the same way. Forrester’s AEGIS (Agentic AI Enterprise Guardrails For Information Security) framework argues for least agency, granting an agent only the autonomy your controls can catch: that is our gate. It argues for continuous assurance, re-verifying as systems change: that is our loop. External framing, cited not copied; the rubric underneath stays CSA (Cloud Security Alliance) AISMM and the AI Controls Matrix (AICM).
Cadence: re-assess when something material changes (a new model, a new data class, a rung-advance attempt), not on a calendar.
For leaders
You can’t fund what you can’t measure.
Every step is graded on evidence, costed, and proven before the next one is funded.
A starting point you can defend
Where the team stands today, graded on evidence — not opinion. That’s the number you’re improving from.
A next step with a price tag
The one or two moves worth funding, each tied to a specific safeguard. You know exactly what you’re buying.
A pattern you can repeat
What works on one team becomes the recipe for the next — so the second team is faster than the first.
The one rule
How independently AI is allowed to act never gets ahead of how well it’s governed. We call it the gate — and it’s the reason the climb from “AI drafts, a human approves” to “AI acts, humans audit” stays safe.
See it work
Two jobs run end to end: a Security Operations team clearing its queue, and an AI app’s guard against jailbreaks. New to all this? Start with the AI threats in plain English →
Anchored to
Recognised standards — the CSA control library and maturity model — mapped to the rules you answer to (the EU AI Act, ISO/IEC 42001, NIST), so satisfying one clears many. See the crosswalk →