Insights
Proofs of fitted skills,tied to the people who need them.
Worked demonstrations, an FAQ for each assessment, and the perspectives behind the method — each tied to a role and the skill direction that answers it.
Demonstrations
Fitted skills, proved on a live problem.
The prove beat leads with a fitted guard on one real app. Each case is one persona’s problem and the skill direction that closes it.
Your guard caught half the attacks, and you didn’t know until it was measured
Baseline a shipped guard on a fixed corpus, fit it (don’t replace it), re-score: 53% → 100% catch, held-out included. The tollgate #4 worked example.
Solves: “Your old gates catch bad code.” AI artifacts fail in behaviour, not syntax — and no one measured the guard.
Read the demonstration →
For: Function headSecurity Operations: when AI outran its controls
Fit triage to your named noise, drop false positives to zero with real attacks still caught, and turn the freed hours into hunting. The gate, demonstrated end to end.
Solves: The board’s red function — autonomy ahead of governance in the SOC, and a queue that’s mostly your own noise.
Read the demonstration →
For: Security newcomerGovernance was present. Comprehension was missing.
Ask a rule in plain language, in your own language; the answer cites the actual clause, or abstains and routes to the owner. The Explain instrument’s evidence page.
Solves: “Am I allowed to do this?” — the policy exists, but nobody can find or parse it at the moment of need.
Read the demonstration →
For: PractitionerWe gave one helper the keys. The locked doors stayed locked.
One assistant, working from Slack and Telegram, drives the scanner, the rulebook and the scoring end to end. It goes everywhere and still cannot delete, cannot see the private material, and cannot make a score up. The integrated run.
Solves: “If we let an AI actually run things, what stops it going where it shouldn’t?”
Read the demonstration →
For: Practitioner1,073 skills entered the pipeline. 35 findings surfaced. One scan.
Build a bill of materials for every skill. Infer capabilities from code. Run static analysis. Construct an attack graph. Here's the complete methodology.
Solves: "We have 1,073 skills. Some are dangerous. Which ones? And which combinations create attack paths?"
Read the demonstration →
For: Function headInitech: ISO 27001, 27701, and 42001 from one AICM run
Same GRA answers rolled through CSA’s 27001, 27701, and 42001 mappings on the AI Controls Matrix (AICM). The delta: gold-standard security, sparse privacy extension, and AI-only controls an ISMS will never clear. Self-assessed sample, not certification.
Solves: “Where does the ISMS end, what does privacy add, and what is AI-only?”
Read the demonstration →
For: Function headInitech: NIST 800-53, CSF 2.0, and AI RMF compared with CSA AICM
Same GRA answers: 800-53 and CSF via the Cloud Controls Matrix (CCM) bridge; AI RMF as the peer frame to the CSA AI Controls Matrix (AICM) (Govern/Map/Measure/Manage). Self-assessed sample, not a NIST attestation.
Solves: “Where does foundational NIST end, and how does AI RMF compare to AICM?”
Read the demonstration →
For: Function headInitech: CSA AI-CAIQ STAR Level 1 readiness pack
Phase-1 GRA domains on the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) v1.1.0: Yes/No/NA answers, domain dashboard, priority findings — Big-4 pack shape, not a CSA STAR listing or audit opinion.
Solves: “What would a STAR for AI Level 1 self-assessment look like for our GRA baseline?”
Read the demonstration →
For: Function headInitech: Quick Mythos Vulnerability Assessment
Same Tier-1 instrument as /assess/quick: indicative headline, five VM areas, gap register. GRA postures where AI Controls Matrix (AICM) ids overlap. Self-assessed sample, not measured.
Solves: “Where is the VM foundation missing before we dig into one function?”
Read the demonstration →
Assessment FAQ
The three assessments, answered.
How to take each one, how to read its report, and the methodology underneath — an aid to the CTA assessments, not a substitute.
A ten-minute on-ramp — where a foundation is missing, before the deep dive.
How long, and how many questions?
Forty questions across five vulnerability-management domains, about ten minutes. Every answer carries forward into the full function diagnostic, so nothing is wasted.
What does it produce?
A fast, indicative Mythos vulnerability read that flags where a foundation is missing — where to dig first. Not the per-function deep dive, and nothing here is measured.
How does it connect to the rest?
The questions map to AI Controls Matrix (AICM) control areas; it’s the tier-1 on-ramp to the function diagnostic, not a standalone score.
The two-axis read of one function: how well it’s governed × how far AI has been let to act.
What do I actually answer?
Pick a function, then answer what’s in place — evidence, not opinion — across two steps: Govern (AI Security Maturity Model (AISMM) maturity) and Adopt (AI Cyber Maturity Model (AI-CMM) autonomy). Around fifteen questions, each tied to a real control.
What’s in the report?
Two radars — governance maturity (AISMM) and AI autonomy (AI-CMM) — the gate reading between them, a per-category ladder, a peer benchmark, a gaps register, and a ranked action plan of the few fitted moves that raise the number. Compatible-standard packs (ISO, NIST, AI Consensus Assessments Initiative Questionnaire (AI-CAIQ)) are lenses on the same AI Controls Matrix (AICM) answers — samples on /maturity#samples, not a second questionnaire.
What is the methodology, exactly?
Every question maps to a real AICM control objective; a maturity level is bounded by coverage evidence, never self-asserted; the gate flags any function whose autonomy outruns its governance. The deep dives below explain each deliverable.
The report, deliverable by deliverable
- The AICM coverage assessment — is each control in place? →
- Placing a function on the AISMM scale — what level, and why →
- The Shared Security Responsibility Model (SSRM) ownership map — who owns each control across the supply chain →
- The prioritised remediation roadmap — what to fix, ranked by effort-to-impact →
- The external-assurance artefact — AI-CAIQ and STAR for AI →
Track 2: four concrete rungs per control for the skills your seat owns.
What is it?
A personal mastery check on the same CSA control spine as the org diagnostic — re-read per seat. Each prompt has four concrete rungs from initial to optimum, then fitted skills from your gaps.
What do I walk away with?
A self-assessed reading: average current vs target, whether your personal gate is open (gate-blocking skills below Leads), and the next skills to climb. Nothing is saved.
How does it connect to the org assess?
Same AICM controls, different job: org maturity grades the function; mastery names what you learn next. Not a second framework and not measured evidence.
Perspectives
The thinking behind the method.
The emerging problems this practice is a response to — each written for one role.
What Claude Mythos Means for Your Security Program
Solves: The home-page threat concern — AI-discovered zero-days and autonomous attack capability — mapped to the vulnerability play and the gate.
Read the perspective →
Why Most AI Security Pilots Don’t Survive Production
Solves: $4–7B spent on pilots, little production capability — the five structural failure modes the methodology is built to avoid.
Read the perspective →
Choosing the Control Spine: CSA, Forrester AEGIS, Gartner AI TRiSM
Solves: “Which framework do we anchor on?” — why this practice runs on CSA, and where the analyst lenses genuinely add.
Read the perspective →
How a Skill Is Built and Fitted to Your Function
Solves: “A thousand skills is inventory, not capability” — the engine that fits a generic skill to a function’s real tools and process.
Read the perspective →
The AI Security & Safety Center of Excellence: A Modular Build Playbook
Solves: “How do I stand up an AI Security CoE — and then operate it?” — the modular build, sequenced from the SOC, and how to run it.
Read the perspective →