AI Security — Governance, Risk & Secure AI Adoption Portfolio.
======================================================================================================================================
This repository demonstrates AI in cyber security — how organizations use artificial intelligence to strengthen SOC operations, threat detection, and fraud prevention — alongside governance for securing AI systems (LLMs, copilots, third-party AI tools).
The portfolio covers both sides of the AI + security equation: using AI to defend the enterprise, and protecting AI from abuse, data leakage, and regulatory risk.
- AI in Cyber Security — SOC automation, UEBA, phishing ML, fraud detection, threat hunting
- GenAI & LLM Security — Prompt injection, RAG security, jailbreak defense
- AI for Fraud Detection — Payment fraud, ATO, mobile money abuse
- AI for Phishing Detection — Email, BEC, smishing, AI-generated lures
- AI for Threat Intelligence — IOC extraction, OSINT, MISP/STIX automation
- AI for Malware Analysis — Sample triage, family classification, SOC integration
- AI for Vulnerability Prioritization — EPSS, KEV, asset context, exploit prediction
- Copilot Security — M365, GitHub, Copilot for Security governance
- AI Security Governance Framework
- AI Acceptable Use Policy Template
- AI for SOC — Detection & Automation
- AI Risk Assessment & Use-Case Classification
- Prompt Injection & OWASP LLM Top 10 Threats
- Secure AI Deployment & Acceptable Use
- Third-Party AI Vendor Risk Assessment
- AI Incident Response & Model Rollback
- Regulatory Alignment (EU AI Act, NIST AI RMF)
- NIST AI Risk Management Framework (AI RMF)
- ISO/IEC 42001 — AI Management System
- OWASP Top 10 for LLM Applications
- EU AI Act — Risk Classification
- MITRE ATLAS — Adversarial Threat Landscape for AI
- LLM platforms: Azure OpenAI, AWS Bedrock, on-premise models
- Guardrails: NeMo Guardrails, Azure Content Safety
- Monitoring: Model logging, prompt audit trails, anomaly detection
- Testing: Red teaming for LLMs, jailbreak testing frameworks
AI in cyber security strategy, policy, and governance committee structure.
AI for SOC detection, secure deployment checklist, and access control.
AI risk assessment methodology and use-case classification matrix.
OWASP LLM Top 10, prompt injection, data leakage, and model poisoning guides.
AI-specific incident playbooks and model rollback procedures.
For AI/ML system security (MLOps, model pipelines, adversarial ML, drift detection), see: ai-ml-security-operations
| Domain | Capabilities |
|---|---|
| Governance | AI policy, risk appetite, executive reporting |
| Risk | Use-case classification, DPIA integration, vendor assessment |
| Security | Prompt injection defense, data leakage prevention, access control |
| Operations | Model monitoring, audit logging, incident handling |
| Compliance | EU AI Act readiness, NIST AI RMF alignment |
Gitsimbanyi Prosper
Senior Manager | Cyber Security | AI Security | Governance