Foundations and Threats by Kai London
Every failed security programme skipped the same step: agreeing what it is defending, against whom, and on what architecture. Volume 1 establishes that ground — principles, adversaries, attack lifecycles and a defensible enterprise architecture — so the rest of the series has something solid to build on.
Available on Amazon.
What is inside
Security principles that hold
Least privilege, separation of duties, defence in depth and fail-safe design, explained through what happens when each is skipped.
Threat actors and motivation
Criminal, state-aligned and insider threat described by what they want and how they operate, not by logo.
Attack lifecycles
Initial access to objective, with the defender's opportunities marked at each stage.
Network security
Segmentation, perimeter reality, encryption in transit and the architecture that limits lateral movement.
Endpoint and workload defence
Hardening, EDR, patching and configuration management across a mixed and imperfect estate.
Zero Trust, properly framed
What the model actually requires, what it does not solve, and how to adopt it incrementally.
Who it is for: security practitioners building depth, architects and engineers, technology leaders needing a rigorous grounding, and anyone working through the full four-volume series.
Architecture is the only control that scales. Everything else is maintenance.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.