A real incident
A single email nearly turned Microsoft Copilot against its own user. The eight chapters next door are how you keep the same opening out of your product.
The chapters
59 min total
- Why AI gets attacked7 minYou inventory where text enters, what keys it holds, and what a hostile hour could cost.
- Threat modeling7 minYou turn the doors into a ranked list of threats, each written as one testable sentence.
- Identity: whose keys7 minYou scope every credential to its job, so a hijacked feature inherits the least authority.
- Data: what leaks out8 minYou trace each message to every copy, set retention, and filter retrieval by who is asking.
- The supply chain7 minYou register every model, library, and tool server you import, with publisher and pin status.
- Defense in layers8 minYou stack classifiers, code-enforced limits, and human gates so no single failure is fatal.
- Red-team your product7 minYou attack your own feature and turn each break into a test that runs on every release.
- The Security Posture8 minYou assemble it all into one signed page with a kill switch and a first-24-hours plan.
The sum
Worked in order, you move from a feature and a vague worry to threats ranked, keys scoped, data traced, imports pinned, layers stacked, and attacks rehearsed, all captured on one page you can sign and hand to whoever is on call.
The Security Posture is a fillable page; completing it leaves you with threats, keys, data, layers, and a kill switch in one place your on-call can act from.
The Security PostureFillable PDFDownload →