AI Risk & Readiness Assessment
A fixed-scope diagnostic that examines what your AI systems actually do rather than what their documentation says they do, scored against the published OSRA model and returned as a prioritized remediation roadmap.
Practice
The work runs on OSRA, an open methodology for finding where AI operational risk actually lives: the infrastructure substrate that governance frameworks assume and never verify. Reading it well takes nearly three decades of having run security and technology functions.
Scoped
Fixed scope, fixed fee, a defined end.
A fixed-scope diagnostic that examines what your AI systems actually do rather than what their documentation says they do, scored against the published OSRA model and returned as a prioritized remediation roadmap.
All four OSRA phases run across the estate rather than a scoped sample, ending in a convergence risk summary and a remediation programme your teams can execute.
Ongoing
A standing relationship rather than a deliverable.
Senior security leadership for organizations that need CISO-level judgment without a full-time hire, and for the ones now working through what an assessment found.
Work with founders and leadership teams on platform architecture, technology strategy, and the structural decisions that determine whether systems scale coherently or accumulate fragility over time.
Direct engagement with leadership teams, boards and audit committees on AI governance, platform risk, cybersecurity obligations and regulatory exposure, including non-executive director and advisory board roles.
Track record
Nearly three decades
Running security and technology organizations as CISO and as CTO.
Four regions
Deployments and accountability across the US, Europe, Japan and APAC.
Patents on AI agent infrastructure
Named inventor on interoperable digital asset execution and on contextual data for AI agent activity, alongside three earlier web platform families.
OSRA, published in full
Methodology, scoring model, practitioner templates and a 22-action catalogue, under CC BY-SA 4.0.
A worked example
All four OSRA phases run against a DORA-regulated bank, published so buyers can read the output first.
Two books
The Split Problem and The Hacker's Letters, both Quill House Press, 2026.
Writing
I have written two books, one on AI and one telling my years in security as fiction, and I have been writing essays long enough that they are worth reading before you book a call.
Next step
A thirty minute call to establish what you are exposed to and whether an engagement is worth running.