Perspectives

Field notes.

Short, practical pieces on AI governance, third-party access, and what security reviews are actually testing — written for the people who have to answer them, not for other consultants.

Field note 01
AI Governance
6 minute read

Most AI risk is an access problem wearing new vocabulary.

The conversation about AI security tends to begin in the wrong place — with model behaviour, hallucination rates, and alignment. Those are real concerns, and they are almost never the thing that harms a mid-market company first.

What harms them first is far more ordinary. An assistant is connected to a shared drive with broader permissions than anyone reviewed. A support copilot is given a tool that can query the customer database, and the ticket text it reads is written by strangers. A team adopts a transcription service that quietly retains recordings of every client call. None of that requires a novel attack. It requires only that nobody drew the data-flow diagram.

This is why our assessments begin with an inventory rather than a threat model. You cannot reason about how a system fails until you know what it can reach. In practice, the majority of what we find in the first week is not exotic AI risk at all — it is conventional access risk that arrived through an AI-shaped door, and would have been caught by a vendor review process that nobody applied because the tool felt like a productivity purchase rather than an integration.

The practical implication for a security leader is encouraging: you are not starting from zero. The disciplines that govern third-party access, data classification, and least privilege transfer directly. What changes is the surface area and the speed of adoption — AI tools enter an organisation through expense reports and browser extensions, not procurement. The governance question is therefore less "how do we secure the model" and more "how did this reach production without anyone reviewing it, and what else took the same path?"

Field note 02
Third-Party Access
5 minute read

The authorisations nobody revoked.

Ask an IT administrator how many third-party applications hold access to the company's email and files, and the answer is usually a number offered with a rising inflection. Ask them to produce the list, and the number is almost always higher than the guess.

This is not negligence. OAuth authorisations are designed to be frictionless — a user clicks "allow," a useful integration begins working, and no further approval is required. Multiply that across several years and a few rounds of hiring, and an organisation accumulates a substantial and entirely undocumented access surface. The applications persist after the person who authorised them has left, after the trial ended, and after the vendor was acquired by someone the company has never evaluated.

Auditors have noticed. Third-party access control is directly testable under SOC 2's common criteria, and the evidence request is uncomfortable precisely because it asks for something most organisations cannot produce on demand: a current, reasoned inventory. "We reviewed it last year" is not a control. Continuous visibility is.

The remediation is rarely dramatic. In most tenants we assess, a small number of authorisations account for nearly all of the meaningful exposure — unverified publishers with broad mailbox or drive scopes, domain-wide delegations granted for a project that concluded, and tokens belonging to people who no longer work there. Identifying those takes an afternoon. Knowing which ones they are is the part that requires judgement.

Field note 03
Enterprise Sales
4 minute read

What a security questionnaire is really asking.

For a growing company, the security questionnaire arrives as an obstacle — a spreadsheet of two hundred questions standing between a signed contract and a delayed quarter. It is treated as an exercise in answering, and answered accordingly: quickly, optimistically, and by whoever has capacity.

That reading misunderstands the document. A security questionnaire is not principally a test of your controls. It is a test of whether your answers are consistent, evidenced, and offered by someone who understands them — because the reviewer on the other side has read several hundred of these and is calibrated for confidence that outruns reality.

The questions that stall deals are rarely the technical ones. They are the governance ones: who owns security, when the last review occurred, how vendors are assessed, what happens during an incident. These are answerable by any competent organisation — but only if someone has decided the answers in advance and can produce the artefact behind them. Improvising is what triggers the follow-up call, and the follow-up call is what costs the quarter.

This is the least glamorous argument for fractional security leadership, and the most commercially direct one. A named, credible owner who can answer a questionnaire in two days rather than three weeks is not a compliance expense. For a company selling upmarket, it is a revenue instrument — and the return is measured in deals that closed on schedule.

Continue the conversation

Recognise any of this?

If one of these describes a problem you are living with, a thirty-minute conversation will tell you whether it is worth engaging anyone at all — including us.