Nine questions across the three fronts that matter — Defend, Govern, Apply, from our Post-Quantum & Agentic AI Transformation practice. Three minutes, no email required to see your score.
Front 01 · Defend
Do you have visibility into AI-accelerated attack patterns — automated reconnaissance, AI-assisted phishing — targeting your organisation specifically, rather than generic threat feeds?
Has your vulnerability management and patching cadence been stress-tested against attack tooling that now operates at machine speed rather than human speed?
Do you have a tested incident response path for an AI-accelerated attack — e.g. an automated credential-stuffing campaign — distinct from your standard playbook?
Front 02 · Govern
Do you have a named owner accountable for governing the organisation's adoption of AI, including any autonomous agents, distinct from general IT governance?
For any AI agents with system or data access today, can you name the specific tollgates — identity, authorisation, execution, observation, containment — that constrain what they're allowed to do?
If an AI agent took an unauthorised or harmful action tomorrow, do you have a tested process to detect it, contain it, and explain it to your board within 24 hours?
Front 03 · Apply
Is your security team currently using AI or LLM tools to accelerate detection, triage, or delivery work — and if so, is that usage itself governed and logged?
Have you assessed where AI could measurably reduce your security team's operational burden — alert triage, evidence collection — but haven't yet resourced it?
Does your board understand the difference between AI as a threat, AI as something to govern, and AI as a capability you use internally — or is "AI security" still one undifferentiated topic?
0 of 9 answered
Defend0 / 6
Govern0 / 6
Apply0 / 6
Want to walk through what this means for your organisation, specifically?