Practical defence library

Clear action for moments that feel uncertain.

Short, printable guidance for AI-enabled attacks, secure AI, agents, MCP, RAG, data handling, supply-chain assurance, incident response and defensive AI operations.

Guide library

Find the next safe step.

Search by situation or filter by control area. Every guide opens as a clean reading page with a quick-action panel, checklist, references and print support.

15 guides shown

01 / VERIFICATION 5 min

Verification • Everyone

Verify the person, not the performance

A calm, trusted-channel response to cloned voices, synthetic video and urgent impersonation requests.

Read guide Reviewed 11 August 2026
02 / DATA 6 min

Data protection • People & organisations

Classify before you paste

A practical decision path for prompts, uploads, chat history, AI workspaces and connected information sources.

Read guide Reviewed 11 August 2026
03 / AGENTS 7 min

Agentic AI • Leaders & technical teams

Permission before automation

Reduce agentic AI risk with bounded actions, minimum access, approval points, audit trails and safe failure.

Read guide Reviewed 11 August 2026
04 / APPLICATIONS 8 min

AI application security • Developers & technical teams

Prompt injection: treat content as untrusted

Protect AI applications that read webpages, files, email, retrieved records or user-controlled instructions.

Read guide Reviewed 11 August 2026
05 / OPERATIONS 6 min

Incident readiness • Executives, finance & assistants

Executive impersonation response

A repeatable response when a senior leader appears to request payment, access, secrecy or urgent disclosure.

Read guide Reviewed 11 August 2026
06 / GOVERNANCE 7 min

AI governance • Organisations

Shadow AI discovery without a witch-hunt

Find unsanctioned AI use, understand why it exists and replace risky workarounds with approved pathways.

Read guide Reviewed 11 August 2026
07 / GOVERNANCE 8 min

Supplier assurance • Procurement, risk & security

AI supplier security questions

Questions that turn an AI demonstration into a reviewable security, privacy, resilience and accountability decision.

Read guide Reviewed 11 August 2026
08 / OPERATIONS 6 min

Incident response • Everyone

The first hour after suspected account compromise

Calm containment steps for a suspicious login, stolen session, malicious mailbox rule or account-recovery scam.

Read guide Reviewed 11 August 2026
09 / AGENTS 8 min

Agentic AI • Technical teams & leaders

Secure an AI agent before giving it tools

A deployment checklist for agent identities, tools, memory, approvals, logging, limits and safe shutdown.

Read guide Reviewed 11 August 2026
10 / APPLICATIONS 8 min

Applications • Developers & security teams

MCP security before you connect

A practical MCP review covering authorization, token audience, servers, tools, consent, logs and revocation.

Read guide Reviewed 11 August 2026
11 / APPLICATIONS 8 min

Applications • Developers & security teams

RAG security: treat retrieval as untrusted

Protect retrieval-augmented generation from poisoned documents, indirect prompt injection and excessive data access.

Read guide Reviewed 11 August 2026
12 / DATA 8 min

Data protection • Developers

Protect secrets with AI coding assistants

Keep credentials, private code and sensitive configuration out of unapproved AI workflows.

Read guide Reviewed 11 August 2026
13 / OPERATIONS 8 min

Incident response • Security & IT teams

AI incident response: the first 60 minutes

Contain an unsafe or compromised AI workflow while preserving prompts, tools, identities, data and downstream evidence.

Read guide Reviewed 11 August 2026
14 / GOVERNANCE 8 min

Governance • Leaders, risk & technical teams

Secure the AI supply chain

Track model, dataset, provider, library and connector provenance so material changes do not silently change risk.

Read guide Reviewed 11 August 2026
15 / OPERATIONS 8 min

AI for defence • Security teams

Using AI safely in security operations

A controlled pattern for AI-assisted vulnerability, threat, phishing, detection and incident work.

Read guide Reviewed 11 August 2026

EVIDENCE BEFORE ACTION

Read. Adapt. Rehearse.

HUMAN AUTHORITY ACTIVE
01

Read before pressure arrives

Choose the guide that matches a likely scenario and identify trusted contacts.

Decision recorded

Need an organisation-specific version?

Turn general guidance into your operating playbook.

Align verification, escalation, evidence and decision ownership with your real systems and teams.