Research &
Publications

What we learn in assessments, investigations and response work, written down and given away. No registration wall, no lead form — read it online or take the PDF.

Security engineer reviewing code and telemetry on multiple displays
Research Report15 min read

Threat Modelling Autonomous AI Agents

An AI agent that can call tools is a new kind of privileged user: it holds credentials, takes actions with side effects, and decides what to do next from text it did not write. This report sets out a threat model for agentic systems and the controls that constrain them — written for teams shipping agents into production rather than evaluating them in a lab.

Whitepapers

Long-form guidance on a single problem, written to be handed to a board or an engineering team.

Research Reports

What we find repeatedly in assessments, generalised into control patterns you can apply.

Threat Advisories

An active pattern, the detections that catch it, and the controls that stop it.

Industry Briefs

Sector-specific notes for environments with constraints the general guidance ignores.

Want This
Presented to Your Board?

We present any of these publications as a briefing for boards, audit committees and technical teams, adapted to your own environment and the decisions actually in front of you. Ask us about a session.