AI for CISOs All-in-One by Kai London
The board has already approved the AI programme. The regulator will ask who owns it. This is the executive handbook for the security leader in the middle — how to set the strategy, fund it, architect it, govern it, and report on it without either blocking the business or signing something indefensible.
Available on Amazon.
What is inside
An AI security strategy that survives contact
Scope, sequencing and the decisions only the CISO can make — stated in terms a CEO will fund.
Governance and accountability
Who owns a model, who approves a use case, and how the AI risk committee actually functions between meetings.
Risk in business language
Quantifying AI exposure so it sits alongside the other risks on the register rather than beside them in a separate slide.
Architecture the CISO must insist on
The non-negotiable control points — identity, data boundaries, logging, human review — and the trade-offs behind each.
Regulation without paralysis
Reading the EU AI Act, ISO/IEC 42001 and the NIST AI RMF as an operating plan, not a compliance backlog.
Investment and board reporting
Building the business case, defending the budget, and giving the board a view it can genuinely challenge.
Who it is for: CISOs, deputy CISOs, CIOs with security accountability, heads of technology risk, and non-executive directors sitting on risk and audit committees.
The board does not want your model architecture. It wants to know who answers when it is wrong.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.