ai · security · skills

For the function head

Your team adopted AI before you decided anything.

Track 2 · Your skills path is one click away. The story below is depth; the path names what to learn.

Pick your seat

The copilots are already in your workflows.

Accountability arrived after they did — with no floor for what must be true before the AI acts alone.

22%

of AI decision-makers name internal culture and readiness their second-biggest AI concern — the gap between adopting a tool and being ready to govern what it does.

Forrester · State of AI Survey, 2025 · base 1,528 AI decision-makers

That gap has an address: your department. The tools arrived; the floor for “safe to run with less oversight” did not.

Honest answers put a floor under every step, and name the two or three moves that raise it. The hours you free are reinvested in higher-value work.

What has to be in place before I let it run with less oversight?

A 20-minute honest read of your function: where each step sits, whether its floor is met, and the moves that close the gap.

Three parts do the work. Here they are, in the order you’d use them.

The gap map

Graded on evidence, not opinion.

No self-ratings. You answer what’s actually in place — documented, standardised, measured — and the rubric places each workflow step on the maturity ladder for you.

The read is honest about scope: it measures what your function owns, and says so where it doesn’t.

The diagnostic, question by question →

Does your governance keep up?Gate open
No gate at this level — humans do the work end-to-end; AI plays no part in the loop.
Autonomy claimedL1 of 4
Governance in placeillustrative

Manual: Humans do the work end-to-end; AI plays no part in the loop.

The gate, working — watch what each autonomy rung demands before it opens.

The gate floor

What must be true before it runs alone.

Every autonomy rung has a floor: the governance categories, at the levels, that must hold before that rung is safe. Meet the floor, the gate opens. Miss it, the read tells you exactly which category is short — and by how much.

It’s a rubric you can hand to the person being graded. That’s what makes the placement defensible.

The floor table, rung by rung →

The fitted few

Two or three moves, already curated.

The read ends in a prescription, not a catalogue: the few moves matched to your weakest categories, drawn from a curated set — never a thousand-item list to wade through.

Re-run the read after the moves land, and the same instrument shows the climb.

The curated moves, by workflow →

Your reskilling list

26 controls have your name on them.

Your function’s floor, translated into jobs. Each group is work you already run; the AI era raised its bar.

19 to coordinate with a provider · 7 to verify, not build. Nobody reskills for what the provider already owns.

Set your function's floor

17 controls · 3 gate the climb

Gate the climb

1 control

Prove the function with numbers

6 controls · 2 gate the climb

Grow your people

2 controls

This is the same spine the assessment reads. Score your mastery on four concrete rungs per prompt, or run the function diagnostic — every gap lands on this list: the named skill, the group it belongs to, and who learns it.

Browse skills personalities →Run the diagnostic. Your gaps land on this list →

Fresh for you · the practice keeps learning

What just shiftedLOG-15 · 2026-07-20

Mandiant M-Trends 2026: Dwell Time Collapses to 22 Seconds, Forcing Runtime AI Security Shift

Mandiant M-Trends 2026 reports the median time from initial access to threat handoff collapsed from over 8 hours in 2022 to just 22 seconds in 2025. CSA 2026 State of Modern Application and AI Security survey of 900+ cybersecurity leaders finds organizations struggling to distinguish exploitable vulnerabilities from theoretical findings while investment priorities shift toward runtime security, continuous monitoring, and production defense. AI-powered applications increase the need for real-time visibility as the patch gap leaves organizations exposed when AI accelerates both vulnerability discovery and exploit generation.

Sharpens: Security operations function leads must prioritize real-time AI observability and runtime monitoring over purely pre-production controls. Implement continuous AI model I/O logging for forensic readiness. Develop AI-specific incident response playbooks that account for sub-minute dwell times. Invest in automated runtime exploit mitigation capabilities and endpoint instrumentation that monitors AI assistant emissions regardless of sanctioned domain. · source

New way to build itMDS-02 · 2026-07-20

Unit 42 Exposes MCP Sampling Attack Vectors: Resource Theft, Hijacking, Covert Tool Calls

Palo Alto Unit 42 demonstrated that the Model Context Protocol (MCP) sampling feature reverses the client-server interaction pattern, allowing MCP servers to proactively request LLM completions and enabling three critical attack vectors. Resource theft drains AI compute quotas for unauthorized workloads. Conversation hijacking injects persistent instructions to manipulate responses and exfiltrate data. Covert tool invocation performs hidden file system operations without user awareness. The DoD released MCP security design guidance in June 2026. The 2026 MCP Security Top 10 ranks unauthenticated access and confused deputy attacks as highest risks.

Sharpens: Application security function leads must audit all MCP server integrations for sampling capability exposure and enforce explicit user confirmation for server-initiated LLM requests. Implement tool invocation logging with user-visible indicators and scan MCP server manifests and tool definitions during the secure SDLC. Treat MCP servers as untrusted external services requiring least-privilege access and network segmentation. · source

New way to build itDSP-21 · 2026-07-20

Microsoft EchoLeak: Zero-Click RAG Poisoning Exfiltrates Corporate Data via Copilot

Microsoft EchoLeak vulnerability demonstrated that a single malicious email can manipulate Microsoft 365 Copilot into retrieving and exfiltrating sensitive corporate data through rendered image requests without the user ever opening the message. The RAG poisoning attack chain spans five stages: planting hidden instructions in shared documents via invisible text and white-on-white formatting, triggering retrieval through routine employee queries, executing attacker-controlled directives that override system prompts, collecting data within the retrieval scope including emails and CRM records, and exfiltrating over trusted SaaS channels through markdown image rendering that blends into normal application traffic.

Sharpens: Data security function leads must implement content sanitization pipelines that strip invisible Unicode, ANSI escape sequences, and white-on-white text before RAG ingestion. Restrict markdown image rendering to explicitly trusted domains. Apply least-privilege retrieval scoping tied to requesting user access. Schedule regular red-team assessments against RAG knowledge bases treating every connector, document type, and tool integration as an attack surface. · source

New way to build itMDS-07 · 2026-07-20

Reasoning Models Autonomously Jailbreak Other AI at 97% Success Rate

A 2026 Nature Communications study found that large reasoning models can autonomously jailbreak other AI systems with a 97% success rate. Group-IB reports dark web jailbreak commerce surged 371% since 2019, with frameworks like BRUTUS sold as SaaS subscriptions ($50-200 per month). DarkLLMs such as NytheonAI, Xantrox, and EvilGPT offer jailbroken chatbots for malware writing and phishing. State-backed APT groups including APT28 (LameHug AI infostealer) and APT35 (GenAI-generated malicious PDFs) are now integrating jailbreak techniques into attack chains. Static detection rules cannot keep pace with iterating frameworks that release new bypass methods within weeks.

Sharpens: Security function leads must mandate continuous AI red teaming against autonomous jailbreaking, integrate dark web threat intelligence into detection rule pipelines, and implement layered jailbreak detection covering input filtering, output moderation, and behavioral monitoring. Scope testing against OWASP LLM Top 10 and MITRE ATLAS categories per deployment use case. · source

On the frontiernot yet on the CSA spine · 2026-07-19

Dual-Channel Agent Governance Gap Exposed by EchoLeak and ForcedLeak Attacks

The Aurascape 2026 landscape analysis identifies a structural blind spot in AI security: dual-channel agent control. Most security platforms inspect either the model conversation channel (prompts and responses) or the tool-execution channel (API calls and system actions), but not both simultaneously with correlated data lineage. The EchoLeak attack (CVE-2025-32711) exploited this gap against Microsoft 365 Copilot via zero-click indirect prompt injection, while ForcedLeak (CVSS 9.4) used a $5 domain re-registration to exfiltrate data through Salesforce Agentforce. Neither attack would have been caught by single-channel inspection.

Sharpens: Evaluate whether your AI security tooling provides cross-call data lineage that correlates model-level prompts with tool-level actions. When procuring agentic AI security tools, require dual-channel inspection capabilities as a non-negotiable evaluation criterion. For existing agent deployments, implement compensating controls: session-level audit logging that links prompt history to tool-call sequences, and blast-radius containment that limits what any single agent can access regardless of prompt content. · source

What just shiftedMDS-06 · 2026-07-19

Only 26 Percent of Organizations Conduct Proactive AI Security Testing Amid 97 Percent Jailbreak Success Rates

Mindgard's May 2026 benchmarks reveal a stark preparedness gap: only 26 percent of organizations conduct proactive security testing specific to AI systems, while multi-turn jailbreaks achieve a 97 percent success rate within five conversational turns. Single-shot red teaming is insufficient because risks compound across conversational turns. Organizations practicing continuous and structured AI red teaming experience significantly fewer security incidents and vulnerabilities. Budget and workforce skills gaps remain the top inhibitors preventing organizations from operationalizing AI red teaming.

Sharpens: Shift from periodic manual red teaming to continuous automated adversarial testing against all production AI models. Implement multi-turn testing scenarios as standard practice, not just single-shot prompts. Establish a weekly red teaming cadence integrated into your CI/CD pipeline for AI systems. Track and report jailbreak success rates over time as a core AI security KPI for your board and risk committee. · source

Control ids above refer to the CSA AI Controls Matrix (AICM).

~12 real questions per function.

Not a 200-item audit — every question tied to a real AI Controls Matrix (AICM) control, validated at every build.

Get your function’s readSee the whole portfolio
Every number above has a method page behind it: each piece opened up as inputs → mechanism → outputs, with provenance — and the deeper tables named, content owner-gated.The method, piece by piece →

Not your role?

Each role has its own way in. Here is where the others start.