AI Security

Rolling out Copilot? Staff writing proposals with AI? A chatbot answering your clients?

Every one of those is company information going into a system, under an identity that already sees everything that person can see. Nobody scoped that, and you are the one accountable for it.We inventory what is actually running, scope what each tool can reach, close the paths data leaves by, and catch the drift as configurations move.
Four things are true of most estates on the first pass, and none of them required an attacker. Every one is a default somebody accepted, or a tool somebody installed.

AI inventory and control plan — extract

Sample
AreaFindingPriority
Identity and accessHigh
  • Copilot inherits each user's full SharePoint scope.
  • Forgotten shares included.
P1
Vulnerability managementMedium
  • No review of AI tools added by minor vendor releases.
P3
Data protection — residency, encryptionHigh
  • Prompts and uploads leave the tenant.
  • No answer on training or residency.
P1
Network securityMedium
  • Browser extensions reach model providers directly.
  • No inspection.
P3
Workload protectionHigh
  • 14 AI tools in use, 3 approved.
  • The rest run on personal accounts.
P1
Logging and monitoringMedium
  • Prompt and response audit not enabled.
  • Nothing to reconstruct afterwards.
P2
Incident response and continuityMedium
  • No procedure for revoking an agent mid-incident.
P3
Governance and compliance — Loi 25High
  • No approval path for a new AI tool.
  • No automated-decision inventory.
P2
The first page of what an assessment produces: what is running, what it can reach, and the order to fix it in. The full document runs to every tool found, with the owner and the effort against each line.
Microsoft Purview Data Security Posture Management for AI, showing setup tasks, an oversharing-risk recommendation, and charts of interaction volume across Microsoft Copilot and other AI apps.
The console view this work produces: Copilot and the other AI apps side by side, with oversharing risk quantified rather than assumed.Used with permission from Microsoft
01

Assess

  • Identity and access — what each tool inherits from the person using it
  • Vulnerability management — what a vendor release quietly turned on
  • Data protection — training on your data, and where it sits
  • Network security — N/A, this runs over the vendor's network
  • Workload protection — the AI tools in use, and what each can reach
  • Logging and monitoring — whether prompts and responses are recorded
  • Incident response — how you revoke an agent mid-incident
  • Governance — Loi 25 exposure and automated decisions

How it runs

  • Discovery workshop
  • Technical evaluation against the OWASP LLM and Agentic Top 10s
  • Roadmap, with the risk that stays
02

Protect

  • Identity and access — what the tool may reach, scoped to the work
  • Vulnerability management — new models and releases assessed on arrival
  • Data protection — training opt-out, retention, and the residency answer
  • Network security — N/A, nothing here is yours to segment
  • Workload protection — an approved list of tools, and the settings that enforce it
  • Logging and monitoring — prompt and response logging turned on
  • Incident response — a way to switch a tool or agent off
  • Governance — Loi 25 notice, explanation and human review

How it runs

  • Design, with the controls named up front
  • Build, tested against a real rollout
  • Handover, with an evidence pack
03

Maintain

  • Identity and access — who has the tooling, and what their agents reach
  • Vulnerability management — capabilities added by a vendor release
  • Data protection — where prompts and code are going
  • Network security — N/A, nothing here changes on your side
  • Workload protection — shadow AI, and tools bought by a department
  • Logging and monitoring — whether the logs are still being written
  • Incident response — whether revoking an agent still works
  • Governance — AI risk in the same register as everything else

How it runs

  • Approval criteria agreed in advance
  • New models assessed on arrival, not quarterly
  • A decision your security team can defend

Do you know which AI tools your staff use?

Most organisations cannot answer that. Tell us what you run and we will scope the work with you. Or start with the free evaluation — sixty minutes, and a written read on which domains deserve a real look. We reply within one business day.