Operational resilience

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

How to Master AI Risk Control Testing for Real-World Assurance

NIST’s August 2026 TEVV-Athlon draft makes real-world AI evaluation a current governance issue. Businesses should connect every test to pre-agreed acceptance thresholds, a named decision owner and clear retest triggers.

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

Why Moving Beyond Vulnerability Management is Central to Building True Operational Resilience

The US GAO’s Equifax findings show how a missed vulnerability becomes a business crisis when identification, detection, segmentation and data governance also fail. ASD, CISA, NIST, NCSC and APRA guidance show why leaders must connect continuous vulnerability assessment to critical services, accountable decisions and tested recovery.

Widespread AI Security Failures in UK Retail Demand Sharper Cyber Risk Ownership

RiverSafe’s Censuswide survey of 200 senior security leaders at large UK retailers reported AI-related incidents, unapproved tools and incomplete security reviews. The UK Government’s Cyber Security Breaches Survey and NCSC secure-AI guidance show how boards can convert that warning into access, supplier, monitoring and incident controls.

Why AI Risk Management Must Treat Privacy as a Dynamic, Context-Specific Challenge

The UK Information Commissioner’s Office expects AI transparency and supply-chain due diligence to evolve as processing purposes become clearer. NIST’s AI Risk Management Framework shows how privacy risk should be documented, measured and monitored throughout the AI lifecycle.

Why AI Risk Management Must Address Vendor Change Controls to Prevent Operational Disruption

Microsoft Azure AI Foundry and Amazon Bedrock show how model retirement can shorten notice periods, stop requests and require code changes. The EU's DORA framework shows why notification, objection and exit rights must connect to a tested operational response.

AI Risk Management Enables Success

The Digital Transformation Agency’s Microsoft 365 Copilot trial shows how a bounded experiment can produce evidence about benefits and limitations. OECD adoption research and UK Government assurance guidance point to an operating model that helps organisations test, scale or stop AI responsibly.

Recent posts