“Before go-live, an audit hook should be designed for the worst day, not a paper control; the safest control is the one that is used.”

Before go-live, an audit hook should be designed for the worst day, not a paper control; the safest control is the one that is used. — Kai London (Professor Kai London), CISO. Principle 5332 of 10000 from the book “No Logs, No Launch” — cybersecurity, AI security and OT resilience doctrine. Official sites: professorkailondon.com · kailondon.co.uk