Two views of the same problem. The scale shows how bad an outcome is and who it hits. The map shows where the breach happens. Every breach point links to the levels it feeds, and every level links back to its breach points.
Seven levels, ordered by how many people are hurt and how hard the damage is to reverse. Select a step for its detail.
Known causes, known controls. A good assessment and fix closes most of the exposure.
Intent is involved. Prevention is partial, so limits, detection and recovery matter as much.
Bigger than one client. Our job is resilience, early warning and getting the right authorities involved.
An AI system drawn as a data-flow diagram, with 36 numbered breach points. Dashed red marks what is outside your control. Filter by layer or by risk level, or play a full attack.
Select any numbered marker for how the attack works, a real case, and the defences. On a small screen, scroll the map sideways.
Situations, what stops them, a benchmark case, and when to escalate. Select a numbered breach point to open it.
All 36 points from the map, grouped by layer. Codes such as LLM01 refer to the OWASP Top 10 for LLM Applications, 2025 edition.
Severity alone doesn't set priority. Multiply the level by how easy the attack is to reach. Every finding on the map gets one number.
Fix now. Stop the affected feature or remove the permission until it is fixed.
Fix this quarter. Owner and date assigned, retested when done.
Schedule. Track it and review at the next retest.
Any finding at level 6 or 7 goes to the executive team and the board regardless of its score. Low likelihood does not make a catastrophic outcome a routine ticket.
At levels 6 and 7 no private firm negates the threat alone. We do not test whether a model will produce weapons or mass-casualty content; that work belongs to the model developers and government evaluators. What we do is make sure a client's agents cannot be used as a route into systems that matter, that someone notices quickly if they are, and that the client knows who to call: CISA and the FBI in the United States, plus the sector regulator.
A two-year sequence for a founder who builds with AI and is new to security. Each stage has something to learn, something to prove, and somewhere to practise in public.
Speak the frameworks and understand every point on the map.
Be able to run the technical part of an assessment alongside a contract tester.
Be credible with the CTO, general counsel and auditor, who often hold the budget.
Put senior, recognised credentials on the team, mostly through hires and advisers.
| Credential | Type | Cost | Needs | Covers on the map | Verdict |
|---|---|---|---|---|---|
| CAISPPractical DevSecOps | Hands-on exam: 5 challenges in 6 hours plus a report | $1,099 | Basic Linux. No ML or deep security background | Core, tools, data, build. Maps to OWASP, ATLAS, NIST, ISO 42001 | Start here |
| CMCPSEPractical DevSecOps | MCP security specialist | $699 | Not stated | Tools layer: points 17 to 20 | Add in stage 2 |
| AIGPIAPP | Governance, multiple choice | Check IAPP | None published | Governance around every level; no hands-on testing | Get in year 1 |
| ISO/IEC 42001 Lead ImplementerPECB and other training bodies | Management-system course and exam | Varies | None formal | Supports the vendor trust pack offer | If rung 3 sells |
| CompTIA SecAI+Launched February 2026 | Multiple choice, vendor neutral | £218 UK voucher | Recommended: Security+ and 2+ years in security | Securing AI systems, AI governance | Optional |
| CompTIA Security+ | General security foundation | About $425 | None | Classic security: points 2, 4, 28, 33 | Optional |
| OSAI (AI-300)OffSec | 24-hour proctored red-team exam | $1,749+ | OSCP-level skills recommended | Offensive testing across the whole map | For the technical lead |
| AAISMISACA | AI security management | $459 / $599 | Active CISM or CISSP | Security leadership for AI risk | For a senior hire |
| SANS SEC545GenAI and LLM application security | Instructor-led course | $8,260 | Security fundamentals | Core and tools layers | Later, company-paid |
Enterprise clients ask for it and acquirers require it. Start in year one; the audit period takes months.
Technology errors and omissions, cyber and general liability cover, plus written authorisation and rules of engagement for every test.
Two or three security advisers and contract testers whose credentials stand behind the work until the team has its own.
Certificates support credibility; they do not create it. The research found no evidence that buyers or acquirers weigh any of these credentials, and found that peer recommendations and original research move them most. A completion certificate from a training platform is learning, not a credential. Prices were checked in October 2026, mostly from third-party pages, and CAISP, CMCPSE and OSAI figures come from Practical DevSecOps, which sells two of them. Confirm with each provider before paying.
Six workstreams across three years. Revenue figures are planning targets worked out from the price bands in the research, not benchmarks from comparable firms.
| Days 1 to 90Prove demand | Months 3 to 12Prove the method | Year 2Make it recurring | Year 3Make it transferable | |
|---|---|---|---|---|
| Method and tooling |
|
|
|
|
| Offers and revenue |
|
|
|
|
| Team |
|
|
|
|
| Credibility |
|
|
|
|
| Company readiness |
|
|
|
|
| Exit readiness |
|
|
|
|
| Gate to pass | Five buyers will pay $15K or more, and a credible security practitioner puts their name on the work. | Clients renew, and at least a third of assessments convert to a subscription. | Delivery quality holds when the founder is not on the engagement. | A buyer's diligence finds recurring, transferable revenue. |
If the first gate fails on the second test, stop and rethink. Without a credible security practitioner attached, this is a media business about AI security, which is a smaller and different company.
The last rung is the business. Every assessment proposal includes the subscription as the default next step. The mapping sprint price is our own estimate; the others come from published price bands.
| Measure | End of year 1 | End of year 2 | End of year 3 | Why it matters |
|---|---|---|---|---|
| Recurring share of revenue | 25%+ | 50%+ | 60%+ | Worth two to four turns of valuation multiple |
| Largest client's share | Under 35% | Under 20% | Under 20% | Buyers reprice above about 20% |
| Active subscriptions | 3 to 4 | 6 to 8 | 13 to 19 | Derived from the revenue targets at about $8K a month |
| Delivery done without the founder | 20% | 60% | 90% | Founder dependence is the most common deal killer |
| Compliance | SOC 2 started | SOC 2 Type II | Maintained | Enterprise clients and acquirers both require it |
| Original research published | 1 report | 2 reports | Annual benchmark | Research has the strongest influence on security buyers |
All targets are our planning figures.
How we work, from the first engagement. These protect clients, protect us, and are what make the company worth buying.
| Risk | What it looks like | Our response |
|---|---|---|
| Platform absorption | Automated testing becomes a free feature of tools clients already own | Sell judgement, independence and governance on top of free tooling; never depend on one tool |
| Credibility | Polished material with thin technical depth, which buyers already penalise | Named advisers, contract testers, verified findings, public track record |
| Thin services margins | Project work that earns little after contractor costs | Fixed-fee offers, automation of repeat work, subscription as the default |
| Client concentration | One consulting relationship supplies most of the revenue | Track monthly; cap any client at 20% by year two |
| Liability | A test damages a client system, or a missed flaw is later exploited | Authorisation and scope on paper, insurance, liability caps in the master agreement |
| A dated atlas | The 36 points stop matching how systems are attacked | Quarterly review of the points against the incident feed |