Skip to main content

25 posts tagged with "Security"

Privacy, threat modelling, and secure AI delivery

View All Tags

End-to-End AI Solution Engineering Playbook: Responsible AI, Governance, Security and Privacy for Banking Customer Service

· 15 min read
AI Playbook author

Before production, MonGo must show the hybrid customer-service AI is lawful, fair, secure, accountable, controllable and fit for purpose. The goal is not zero risk—it is proportionate controls, measured residual risk and evidence for every decision to continue, restrict or stop.

This article is Part VI of the Banking Customer-Service AI playbook. It follows Part I through Part V.

The Practical Core Framework Set for End-to-End AI Solution Engineering

· 22 min read
AI Playbook author

Most AI engagements fail not because the organisation lacks frameworks, but because it has too many of the wrong kind. Teams accumulate strategy canvases, maturity models, scoring formulas and governance checklists until the methodology itself becomes the delivery risk. The practical response is not a larger catalogue. It is a core set: enough structure to run end-to-end AI solution engineering, and little enough that practitioners can actually use it.

Leadership: Protect Quality, Independence and Trust

· 30 min read
AI Playbook author

A Big Four firm does not compete only through its technical expertise, global network, technology platforms or client relationships. Its most valuable asset is trust.

Clients trust the firm with commercially sensitive information, strategic decisions, financial records, personal data and complex regulatory matters. Regulators trust the firm to exercise professional judgement and uphold required standards. Investors, employees, governments and the wider public expect the firm to behave responsibly, independently and ethically.

AI Governance and Information Security: Implementing ISO/IEC 27001 as the ISMS Backbone for Enterprise AI

· 33 min read
AI Playbook author

Information security for AI should not exist as a pile of threat models, vendor questionnaires and one-off pen tests. ISO/IEC 27001 establishes an organisation-wide Information Security Management System—scope, policy, risk assessment, control selection, operation, audit, management review and continual improvement—so confidentiality, integrity and availability remain enforceable when models, retrieval systems, agents and suppliers change.

AI Red Teaming Roadmap: A Practical Guide from Fundamentals to Enterprise Security Testing

· 32 min read
AI Playbook author

Artificial intelligence systems introduce a new class of security problems. A conventional application may fail because of insecure code, weak authentication or an exposed API. An AI application can suffer from all of those problems plus prompt injection, poisoned retrieval data, unsafe tool execution, model extraction, sensitive-data leakage, misleading outputs and autonomous agent behaviour.

AI red teaming is the structured practice of testing these systems from an adversarial perspective. The objective is not simply to make a model produce an inappropriate answer. It is to discover how an attacker, careless user, compromised data source or unexpected interaction could cause the complete AI system to violate its security, safety, privacy or business requirements.

API Security Engineering: A Practical End-to-End Roadmap

· 36 min read
AI Playbook author

APIs connect web applications, mobile apps, cloud services, partners, customers, internal systems and increasingly AI agents. They also expose valuable business capabilities directly: creating payments, changing account details, retrieving customer records, submitting claims, placing orders and triggering operational workflows.

That makes API security much broader than adding authentication to an endpoint.

A secure API must verify:

  • Who or what is making the request.
  • Whether that identity is allowed to perform the requested action.
  • Whether it may access the specific object and properties involved.
  • Whether the request is structurally and semantically valid.
  • Whether the operation is being abused at scale.
  • Whether sensitive information is exposed in the response.
  • Whether the service and its dependencies remain secure throughout deployment and operation.

The Complete Microsoft Azure Roadmap: Cloud Architecture, AI Engineering, Security and Governance

· 60 min read
AI Playbook author

The AWS Learning Roadmap follows a sensible progression: learn cloud fundamentals, identity, networking and compute first; then add storage, databases, containers, serverless and operational services. This Azure roadmap follows the same learning philosophy but expands it into an enterprise-grade programme covering cloud architecture, application delivery, AI engineering, cybersecurity, Responsible AI, regulatory compliance and operating-model design.

Terminology note: Microsoft’s current documentation refers to its unified enterprise AI development platform as Microsoft Foundry. You may still encounter the previous “Azure AI Foundry” name in existing projects, articles and interfaces. Microsoft Foundry brings together models, agents, development tooling and production AI operations as an Azure platform service. (Microsoft Learn)