Posts

Showing posts with the label Financial Services POST:

The Five Questions Every Director Must Answer: Professor Kai London on Board Cyber Risk

Image
  By the Ezeiza Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com Cyber risk has moved decisively from the server room to the boardroom, and many directors are unsure what they are actually accountable for. Professor Kai London , a senior CISO and board advisor, offers a disarmingly simple test. “Every board should be able to walk into a room and answer five questions,” he says. “If they cannot, they are not governing cyber risk — they are hoping.” “What could break, who owns it, what it would cost, which control holds it, and where the evidence is. Those five questions are the whole of board-level cyber governance.” From delegation to accountability London notes that modern regulation deliberately places cyber accountability on senior leadership, who can be held liable for failures. “It has moved cyber from something the board hears about to something the board answers for,” he says. The five questions, unpacked Wha...

Seven Principles for Secure AI: Professor Kai London on Governing AI in Airlines and Banks

Image
  By the Ezeiza Times Business Desk Professor Kai London — Founder & CEO, Quantum AI Systems Security. Credit: professorkailondon.com Airlines and banks are among the most aggressive adopters of artificial intelligence — for pricing, fraud detection, operations and customer service. That makes them, argues Professor Kai London , a senior CISO, the sectors where AI governance matters most. “Securing AI is not about tools or policies in isolation,” he says. “It is about building a business control system that makes AI defensible, auditable, resilient, governed and commercially trusted.” “Enterprises that can prove how their AI is governed will move faster than those that merely claim to be innovative.” The seven principles London frames secure AI around seven board-legible principles: identity first (every model and agent runs under a managed identity); zero trust by design (assume any input can be hostile); evidence before claims (no audit trail, no assurance); human accounta...