Voryntel

Field notes

Reading risk, written down.

Practical writing on cybersecurity, AI governance, and the risks that live in the systems organizations actually run! Now with labs and artifacts you can use.

One Management System, Two Standards: Integrating ISO/IEC 42001 with ISO/IEC 27001

You already run an ISMS and now you need the AI certificate too. Here is what genuinely merges, where the two standards pull in opposite directions, and how one control you build well can earn evidence toward both certificates without doing the whole thing twice.

Read the post

Governing Prompt Injection: ISO/IEC 42001 When You Cannot Trust What the Model Reads

A clean-looking knowledge-base article told a support assistant to email a customer's account to a stranger, and it did. Here are five doors prompt injection comes through, from a ticket to a retrieved document to a fetched page, the layered ISO/IEC 42001 controls that contain each, and a lab that proves no single layer is enough.

Read the post

Governing the AI Agent: ISO/IEC 42001 When an Action Cannot Be Undone

A single poisoned support ticket, and ninety seconds later a production server was gone. Explore five ways an AI agent that takes actions can fail by moving money, deleting servers, or following a document, along with the ISO/IEC 42001 control that addresses each one, plus a lab you can run and intentionally break.

Read the post

Governing the Enterprise RAG Copilot: A Practical Start with ISO/IEC 42001

An internal copilot leaked the CEO's salary to an ordinary staff account. Here are five ways an enterprise RAG copilot goes wrong, the ISO/IEC 42001 control that stops each one, and a working lab you can download, run, and break yourself.

Read the post