AI All-in-One series · Executive leadership

AI for CISOs All-in-One by Kai London

The board has already approved the AI programme. The regulator will ask who owns it. This is the executive handbook for the security leader in the middle — how to set the strategy, fund it, architect it, govern it, and report on it without either blocking the business or signing something indefensible.

Available on Amazon.

What is inside

An AI security strategy that survives contact

Scope, sequencing and the decisions only the CISO can make — stated in terms a CEO will fund.

Governance and accountability

Who owns a model, who approves a use case, and how the AI risk committee actually functions between meetings.

Risk in business language

Quantifying AI exposure so it sits alongside the other risks on the register rather than beside them in a separate slide.

Architecture the CISO must insist on

The non-negotiable control points — identity, data boundaries, logging, human review — and the trade-offs behind each.

Regulation without paralysis

Reading the EU AI Act, ISO/IEC 42001 and the NIST AI RMF as an operating plan, not a compliance backlog.

Investment and board reporting

Building the business case, defending the budget, and giving the board a view it can genuinely challenge.

Who it is for: CISOs, deputy CISOs, CIOs with security accountability, heads of technology risk, and non-executive directors sitting on risk and audit committees.

EU AI ActISO/IEC 42001NIST AI RMFNIST CSF 2.0DORA

The board does not want your model architecture. It wants to know who answers when it is wrong.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.