Consensus view
“AI is a productivity story”
What the evidence says
It is also a concentration story: a handful of vendors, models, and data paths now sit underneath workflows nobody has mapped end to end.
Signal & Soil · An independent institute on AI, security, and systemic risk
Signal is what an organization says about itself. Soil is the operating reality underneath. Strategic risk lives in the gap between the two, and a brief from us maps it in writing, with a recommendation you can act on.
One conversation to scope the question. A written brief in two to six weeks.
Track record

Working thesis
The risks that hurt institutions are rarely the ones on the register. They are the ones nobody owned.
We trace claims, dependencies, incentives, and failure modes across systems before recommending anything.
Our lens
Most strategy on AI and security is written from the podium. We write from the operating floor, where ownership is unclear, vendors are brittle, logs are missing, and the second-order effects are the ones that matter.
Consensus view
“AI is a productivity story”
What the evidence says
It is also a concentration story: a handful of vendors, models, and data paths now sit underneath workflows nobody has mapped end to end.
Consensus view
“We have a policy for that”
What the evidence says
A policy is a claim. The question is whether decision rights, escalation paths, and evidence exist to back it when a regulator, a board, or an incident asks.
Consensus view
“The model passed its assessment”
What the evidence says
Models rarely fail alone. Prompts, retrieval, agents, identity, and monitoring form a system, and the system is what gets attacked, audited, and blamed.
Track record
Strategic analysis is only as good as the pattern recognition behind it: knowing which risks are real, which controls are performative, and what survives contact with an incident, an auditor, or a hostile counterparty.
Global platforms
AI governance and security programs for products serving 100M+ users
Telecom + mobile
Security design and implementation for the iPhone launch at AT&T
Microsoft
Trustworthy Computing, open source security assessment, and customer-facing security
Major events
Cybersecurity for the Paris 2024 Olympics & Paralympics
Critical systems
E-voting, anonymization, internet backbone, and cloud infrastructure security
Standards used as tools, not wallpaper
NIST CSF 2.0 · NIST AI RMF · ISO 42001 · ISO 27001 · ISO 31000 · FAIR · SOC 2 · OWASP LLM Top 10 · OWASP Agentic AI · Google SAIF
Practice areas
We publish independently and take commissioned work when a question deserves rigour. Every engagement ends in a decision-grade artifact, not a slide deck of frameworks.
A commissioned, evidence-based read on a specific question: an AI dependency, a vendor concentration, a regulatory shift, a capability the board is being asked to fund.
Structured exploration of how AI, security, and regulatory pressure could play out for your institution over one to five years, and which decisions are robust across futures.
Independent review of prompts, retrieval, agents, identity, monitoring, and data flows, done before attackers, auditors, or the press do it for you.
Turn analysis into decision rights, controls, reporting cadence, and evidence that a board, an auditor, and an operator can each use without translation.
Method
Strategy fails when it starts from a slide. We start from the operating environment and work upward to the decisions it can actually support.
01
Locate the systems, vendors, data paths, owners, and unspoken dependencies that the official picture leaves out.
02
Test the picture against threat paths, failure modes, regulatory duties, and plausible futures until the weak assumptions show.
03
Frame the options with their exposure, cost, and reversibility so leaders can choose, and defend the choice later.
04
Leave behind the artifacts, indicators, and operating rhythm that let your own people keep the analysis current.
Trust signals
AWS
Cloud control design
GCP
Data and platform risk
Azure
Enterprise identity and governance
Identity · Data lineage · Vendor risk · Logging · Incident response. CISSP and ISSMP certified.
Sectors
Strategy on AI and security stops being abstract when the exposure reaches citizens, patients, customers, critical infrastructure, or the board packet due next week.
Citizen-facing AI, public safety workflows, procurement scrutiny, and audit-ready accountability.
Model governance, third-party concentration, fraud systems, operational resilience, and regulator evidence.
Clinical decision support, privacy, safety review, incident response, and patient-impact escalation.
Critical infrastructure, predictive maintenance, OT/IT security boundaries, and continuity planning.
LLM features, agentic workflows, customer trust, platform security, and security review at product speed.
Knowledge automation, client confidentiality, workflow redesign, and defensible AI use policies.
Research
Independent analysis on AI, security, incidents, and systemic risk, written for people who have to decide rather than people who have to be impressed.
governance
How long does an unattended WordPress site last on the modern web? Minutes to be found, months to be noticed — and survival is a property of operations, not software.
governance
The May 2026 Canvas breach exposed 275 million users across 8,800+ institutions. Here's what happened, immediate steps to take, and how to build long-term resilience.
governance
Most organizations rush to deploy AI capabilities without governance frameworks. Here's why that's a costly mistake and how ISO 42001 provides a structured path forward.
Start here
The most useful briefs start with what is already in motion: a vendor you depend on, a capability the board wants funded, an incident that exposed something, a regulator who is about to ask. Tell us the question and we will tell you whether it deserves a brief.
One conversation to scope the question. A written brief in two to six weeks.