Leadership · Assurance

Burden of Proof by Kai London

The question put to security leaders has changed. It is no longer "are we secure?" but "show me". Regulators, customers, insurers and courts now want demonstrated control effectiveness — and the organisations that cannot produce it are judged as though they had none.

Available on Amazon.

What is inside

Who is asking, and why

Regulators, customers, insurers, investors and litigants — four different definitions of proof arriving at the same door.

Assertion versus evidence

Why maturity scores and policy libraries collapse under challenge, and what survives it instead.

Building the evidence capability

Continuous control monitoring, testing cadence and an evidence base produced as a by-product of operating, not of reporting season.

Third parties and the chain

Demanding proof from suppliers, and supplying it to customers, without drowning both sides in questionnaires.

The board's position

What directors need to see, how often, and what they are personally answerable for when it turns out to be wrong.

After an incident

What is examined when the breach becomes a case file — and the decisions made months earlier that decide the outcome.

Who it is for: CISOs and assurance leaders facing rising scrutiny, board directors and audit committee members, general counsel and risk officers, and anyone preparing an organisation to be examined rather than trusted.

NIS2DORAISO/IEC 27001NIST CSF 2.0
“

Assurance is not what you believe about your controls. It is what you can put in front of someone who does not believe you.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.