Defend

You deployed AI. Who's securing it?

A fixed-scope project that answers three questions: which AI tools your company actually uses, what data flows into them, and which of those flows put you at risk. In two to four weeks you get a full inventory, risk-ranked findings, an acceptable use policy, and a 90-day remediation plan.

Shadow AI discovery

The AI you approved is not the AI in use.

Every company has two AI footprints: the one IT approved, and the bigger one employees built themselves.

~55%of employees admit to using AI tools their company never approved.UHY middle-market research, 2026
~35%of the data employees paste into AI tools is sensitive: client records, financials, source code, credentials.Cyberhaven data flow analysis

Discovery pairs log analysis with staff interviews: personal ChatGPT accounts doing client work, free tools with training rights over your data, AI features switched on inside software you already own. For a preview, read our guide to shadow AI and what to do about it.

What we assess

Five areas, tested against how attackers and auditors think.

LLM and vendor risk

Who owns each vendor, where data is processed, whether your inputs train their models, and what their security posture actually is.

Data flows

We map what leaves your boundary and where it lands: prompts, uploads, connected drives, and integrations, ranked by sensitivity.

Prompt injection exposure

If chatbots or copilots touch your data, we test how they handle hostile input designed to hijack them.

Acceptable use policy

We review or write your policy: approved tools, prohibited data, and consequences, in language staff will read.

NIST AI RMF alignment

Your governance mapped against NIST AI RMF, the standard insurers, auditors, and enterprise customers increasingly ask about.

Identity and access

Who can connect AI tools to company data, and with what permissions. Overshared drives turn one careless prompt into a company-wide exposure.

Deliverables

What you hold at the end.

AI inventory and exposure map

Every tool, account, and integration in use, with a map of what sensitive data goes where. This becomes your ongoing register.

Risk-ranked findings report

Each finding scored by likelihood and impact, in plain language for executives with technical detail attached. No padding, no scare graphics.

Policy and 90-day plan

An acceptable use policy ready to adopt, plus a remediation plan with owners and sequence, presented in a working session.

The other side of AI risk

Attackers adopted AI faster than you did.

Attackers use the same models your employees experiment with to write flawless phishing, clone executive voices, and stage deepfake video calls that approve wire transfers.

$3.04Bin business email compromise losses logged by the FBI in 2025 alone.FBI IC3 annual report, 2025

We test how your payment approvals, identity verification, and executive communications hold up against AI-assisted fraud, and we run deepfake tabletop exercises through our cybersecurity consulting practice.

Questions

Straight answers on AI security assessments

How long does an AI security assessment take?

Two to four weeks for most companies with 25 to 1,000 employees. Week one is discovery, weeks two and three are analysis and testing, and you get the written report and remediation plan in a working session, not an inbox drop.

We only use ChatGPT and Copilot. Do we still need this?

That is the exact profile that needs it. The risk is rarely the sanctioned tool; it is the personal accounts, free tools with training rights over your data, and AI features quietly switched on inside software you already own.

What do we get at the end?

Five deliverables: an inventory of every AI tool in use, a data exposure map, a risk-ranked findings report, an acceptable use policy ready to adopt, and a 90-day remediation plan with owners.

Will you tell us to ban AI tools?

No. Bans push AI use onto personal devices where you have no visibility. We pair controls with a sanctioned path: an approved tool, clear rules for what data can go into it, and training so people use it well.

See your AI exposure before someone else does.

Start with the free ten-minute readiness assessment. It scores your AI use and data controls and shows you where a full assessment would dig in first.

Take the free AI Assessment