Burden of Proof by Kai London
The question put to security leaders has changed. It is no longer "are we secure?" but "show me". Regulators, customers, insurers and courts now want demonstrated control effectiveness — and the organisations that cannot produce it are judged as though they had none.
Available on Amazon.
What is inside
Who is asking, and why
Regulators, customers, insurers, investors and litigants — four different definitions of proof arriving at the same door.
Assertion versus evidence
Why maturity scores and policy libraries collapse under challenge, and what survives it instead.
Building the evidence capability
Continuous control monitoring, testing cadence and an evidence base produced as a by-product of operating, not of reporting season.
Third parties and the chain
Demanding proof from suppliers, and supplying it to customers, without drowning both sides in questionnaires.
The board's position
What directors need to see, how often, and what they are personally answerable for when it turns out to be wrong.
After an incident
What is examined when the breach becomes a case file — and the decisions made months earlier that decide the outcome.
Who it is for: CISOs and assurance leaders facing rising scrutiny, board directors and audit committee members, general counsel and risk officers, and anyone preparing an organisation to be examined rather than trusted.
Assurance is not what you believe about your controls. It is what you can put in front of someone who does not believe you.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.