Skip to main content

Signal & Soil · An independent institute on AI, security, and systemic risk

We find the gap before your board, your regulator, or an attacker does.

Signal is what an organization says about itself. Soil is the operating reality underneath. Strategic risk lives in the gap between the two, and a brief from us maps it in writing, with a recommendation you can act on.

One conversation to scope the question. A written brief in two to six weeks.

Track record

  • Paris 2024 Olympics & Paralympics security
  • iPhone launch security architecture
  • Microsoft Trustworthy Computing
An empty boardroom table facing a glass wall, with rows of server racks in the data hall beyond

Working thesis

The risks that hurt institutions are rarely the ones on the register. They are the ones nobody owned.

We trace claims, dependencies, incentives, and failure modes across systems before recommending anything.

Our lens

The consensus view is usually incomplete.

Most strategy on AI and security is written from the podium. We write from the operating floor, where ownership is unclear, vendors are brittle, logs are missing, and the second-order effects are the ones that matter.

Consensus view

“AI is a productivity story”

What the evidence says

It is also a concentration story: a handful of vendors, models, and data paths now sit underneath workflows nobody has mapped end to end.

Consensus view

“We have a policy for that”

What the evidence says

A policy is a claim. The question is whether decision rights, escalation paths, and evidence exist to back it when a regulator, a board, or an incident asks.

Consensus view

“The model passed its assessment”

What the evidence says

Models rarely fail alone. Prompts, retrieval, agents, identity, and monitoring form a system, and the system is what gets attacked, audited, and blamed.

Track record

Practitioners, not pundits.

Strategic analysis is only as good as the pattern recognition behind it: knowing which risks are real, which controls are performative, and what survives contact with an incident, an auditor, or a hostile counterparty.

Global platforms

AI governance and security programs for products serving 100M+ users

Telecom + mobile

Security design and implementation for the iPhone launch at AT&T

Microsoft

Trustworthy Computing, open source security assessment, and customer-facing security

Major events

Cybersecurity for the Paris 2024 Olympics & Paralympics

Critical systems

E-voting, anonymization, internet backbone, and cloud infrastructure security

Standards used as tools, not wallpaper

NIST CSF 2.0 · NIST AI RMF · ISO 42001 · ISO 27001 · ISO 31000 · FAIR · SOC 2 · OWASP LLM Top 10 · OWASP Agentic AI · Google SAIF

Practice areas

Analysis you can act on.

We publish independently and take commissioned work when a question deserves rigour. Every engagement ends in a decision-grade artifact, not a slide deck of frameworks.

Method

Ground truth first. Then strategy.

Strategy fails when it starts from a slide. We start from the operating environment and work upward to the decisions it can actually support.

01

Map

Locate the systems, vendors, data paths, owners, and unspoken dependencies that the official picture leaves out.

02

Stress

Test the picture against threat paths, failure modes, regulatory duties, and plausible futures until the weak assumptions show.

03

Decide

Frame the options with their exposure, cost, and reversibility so leaders can choose, and defend the choice later.

04

Transfer

Leave behind the artifacts, indicators, and operating rhythm that let your own people keep the analysis current.

Trust signals

Grounded in the systems you actually run.

AWS

Cloud control design

GCP

Data and platform risk

Azure

Enterprise identity and governance

Identity · Data lineage · Vendor risk · Logging · Incident response. CISSP and ISSMP certified.

Sectors

Where a missed risk has consequences.

Strategy on AI and security stops being abstract when the exposure reaches citizens, patients, customers, critical infrastructure, or the board packet due next week.

Public Sector

Citizen-facing AI, public safety workflows, procurement scrutiny, and audit-ready accountability.

Financial Services

Model governance, third-party concentration, fraud systems, operational resilience, and regulator evidence.

Healthcare

Clinical decision support, privacy, safety review, incident response, and patient-impact escalation.

Energy & Utilities

Critical infrastructure, predictive maintenance, OT/IT security boundaries, and continuity planning.

Tech & SaaS

LLM features, agentic workflows, customer trust, platform security, and security review at product speed.

Professional Services

Knowledge automation, client confidentiality, workflow redesign, and defensible AI use policies.

Research

Briefs and analysis.

Independent analysis on AI, security, incidents, and systemic risk, written for people who have to decide rather than people who have to be impressed.

Start here

Bring the question that does not fit on a slide.

The most useful briefs start with what is already in motion: a vendor you depend on, a capability the board wants funded, an incident that exposed something, a regulator who is about to ask. Tell us the question and we will tell you whether it deserves a brief.

One conversation to scope the question. A written brief in two to six weeks.