ai · security · skills

Insights

Proofs of fitted skills,tied to the people who need them.

Worked demonstrations, an FAQ for each assessment, and the perspectives behind the method — each tied to a role and the skill direction that answers it.

DemonstrationsAssessment FAQPerspectives

Demonstrations

Fitted skills, proved on a live problem.

The prove beat leads with a fitted guard on one real app. Each case is one persona’s problem and the skill direction that closes it.

For: DevSecAIOps

Your guard caught half the attacks, and you didn’t know until it was measured

Baseline a shipped guard on a fixed corpus, fit it (don’t replace it), re-score: 53% → 100% catch, held-out included. The tollgate #4 worked example.

Solves: “Your old gates catch bad code.” AI artifacts fail in behaviour, not syntax — and no one measured the guard.

Read the demonstration →

For: Function head

Security Operations: when AI outran its controls

Fit triage to your named noise, drop false positives to zero with real attacks still caught, and turn the freed hours into hunting. The gate, demonstrated end to end.

Solves: The board’s red function — autonomy ahead of governance in the SOC, and a queue that’s mostly your own noise.

Read the demonstration →

For: Security newcomer

Governance was present. Comprehension was missing.

Ask a rule in plain language, in your own language; the answer cites the actual clause, or abstains and routes to the owner. The Explain instrument’s evidence page.

Solves: “Am I allowed to do this?” — the policy exists, but nobody can find or parse it at the moment of need.

Read the demonstration →

For: Practitioner

We gave one helper the keys. The locked doors stayed locked.

One assistant, working from Slack and Telegram, drives the scanner, the rulebook and the scoring end to end. It goes everywhere and still cannot delete, cannot see the private material, and cannot make a score up. The integrated run.

Solves: “If we let an AI actually run things, what stops it going where it shouldn’t?”

Read the demonstration →

For: Practitioner

1,073 skills entered the pipeline. 35 findings surfaced. One scan.

Build a bill of materials for every skill. Infer capabilities from code. Run static analysis. Construct an attack graph. Here's the complete methodology.

Solves: "We have 1,073 skills. Some are dangerous. Which ones? And which combinations create attack paths?"

Read the demonstration →

For: Function head

Initech: ISO 27001, 27701, and 42001 from one AICM run

Same GRA answers rolled through CSA’s 27001, 27701, and 42001 mappings on the AI Controls Matrix (AICM). The delta: gold-standard security, sparse privacy extension, and AI-only controls an ISMS will never clear. Self-assessed sample, not certification.

Solves: “Where does the ISMS end, what does privacy add, and what is AI-only?”

Read the demonstration →

For: Function head

Initech: NIST 800-53, CSF 2.0, and AI RMF compared with CSA AICM

Same GRA answers: 800-53 and CSF via the Cloud Controls Matrix (CCM) bridge; AI RMF as the peer frame to the CSA AI Controls Matrix (AICM) (Govern/Map/Measure/Manage). Self-assessed sample, not a NIST attestation.

Solves: “Where does foundational NIST end, and how does AI RMF compare to AICM?”

Read the demonstration →

For: Function head

Initech: CSA AI-CAIQ STAR Level 1 readiness pack

Phase-1 GRA domains on the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) v1.1.0: Yes/No/NA answers, domain dashboard, priority findings — Big-4 pack shape, not a CSA STAR listing or audit opinion.

Solves: “What would a STAR for AI Level 1 self-assessment look like for our GRA baseline?”

Read the demonstration →

For: Function head

Initech: Quick Mythos Vulnerability Assessment

Same Tier-1 instrument as /assess/quick: indicative headline, five VM areas, gap register. GRA postures where AI Controls Matrix (AICM) ids overlap. Self-assessed sample, not measured.

Solves: “Where is the VM foundation missing before we dig into one function?”

Read the demonstration →

Assessment FAQ

The three assessments, answered.

How to take each one, how to read its report, and the methodology underneath — an aid to the CTA assessments, not a substitute.

For: Function headQuick Mythos Vulnerability Assessment

A ten-minute on-ramp — where a foundation is missing, before the deep dive.

How long, and how many questions?

Forty questions across five vulnerability-management domains, about ten minutes. Every answer carries forward into the full function diagnostic, so nothing is wasted.

What does it produce?

A fast, indicative Mythos vulnerability read that flags where a foundation is missing — where to dig first. Not the per-function deep dive, and nothing here is measured.

How does it connect to the rest?

The questions map to AI Controls Matrix (AICM) control areas; it’s the tier-1 on-ramp to the function diagnostic, not a standalone score.

Take the quick mythos vulnerability assessment
For: Function headFunction diagnostic

The two-axis read of one function: how well it’s governed × how far AI has been let to act.

What do I actually answer?

Pick a function, then answer what’s in place — evidence, not opinion — across two steps: Govern (AI Security Maturity Model (AISMM) maturity) and Adopt (AI Cyber Maturity Model (AI-CMM) autonomy). Around fifteen questions, each tied to a real control.

What’s in the report?

Two radars — governance maturity (AISMM) and AI autonomy (AI-CMM) — the gate reading between them, a per-category ladder, a peer benchmark, a gaps register, and a ranked action plan of the few fitted moves that raise the number. Compatible-standard packs (ISO, NIST, AI Consensus Assessments Initiative Questionnaire (AI-CAIQ)) are lenses on the same AI Controls Matrix (AICM) answers — samples on /maturity#samples, not a second questionnaire.

What is the methodology, exactly?

Every question maps to a real AICM control objective; a maturity level is bounded by coverage evidence, never self-asserted; the gate flags any function whose autonomy outruns its governance. The deep dives below explain each deliverable.

Take the function diagnostic
For: PractitionerSkill mastery

Track 2: four concrete rungs per control for the skills your seat owns.

What is it?

A personal mastery check on the same CSA control spine as the org diagnostic — re-read per seat. Each prompt has four concrete rungs from initial to optimum, then fitted skills from your gaps.

What do I walk away with?

A self-assessed reading: average current vs target, whether your personal gate is open (gate-blocking skills below Leads), and the next skills to climb. Nothing is saved.

How does it connect to the org assess?

Same AICM controls, different job: org maturity grades the function; mastery names what you learn next. Not a second framework and not measured evidence.

Take the skill mastery

Name the skills, then measure the function.

Reskill by function on the maturity tracks, or run the diagnostic when you are ready for a number.