AI Governance Toolkit
The public maturity self-assessment and framework from CarbeneAI.
Services
A closed-loop practice for the AI-enabled SOC.
Audience
Security leaders, SOC teams, executives, and boards at organizations running an AI-enabled SOC, adopting agentic security tools, or putting AI agents into production.
The work
An AI SOC or agentic security tool shipped with the vendor's use cases, and nobody has tested them against your own risks.
AI agents are in production, and the incident response plan does not say who notices, who can shut one off, or who tells the business.
Tabletop findings stay in a report. They never become detections, and nobody re-tests them.
Executives and the board have not rehearsed AI agent misuse, shadow AI, or an incident at an AI vendor.
In the room
The method
Run the SOC and the business through the incident, including failure or manipulation of the SOC's own AI agents.
Write the AI security use cases the exercise exposes.
Test them against your telemetry. Keep the ones that fire. Record the ones that do not.
Turn results into AI governance controls and AI SOC design decisions, including autonomy limits and kill-switch rules.
Run it again and check that controls and detections hold.
Public MITRE knowledge bases. ATT&CK for adversary behavior, D3FEND for defensive countermeasures, ATLAS for attacks on AI and ML systems.
Services
Exercise the SOC, including failure or manipulation of its own AI agents. Derive and validate the use cases in your environment, set autonomy and kill-switch rules, and map evidence to NIST AI RMF and ISO 42001.
Executive and board exercise on AI agent misuse, shadow AI, and AI vendor incidents. After-action report and governance gap list.
Review of existing AI-related detections and agent telemetry. Coverage map, broken or missing use cases, prioritized backlog.
The loop on a yearly cadence: quarterly exercises, backlog upkeep, re-tests, and board reporting.
The practice
Our team has delivered tabletops and war games at Booz Allen Hamilton, EY and AT&T DFIR and built a SOC at Accenture.
We run the exercise, and we write and audit the detections.
Cyber Defense Tactics is a practice of CarbeneAI.
Free
Three things sit outside the engagements: a tabletop kit, the public library, and the Brief.
One scenario for an AI-agent incident, tied to NIST AI RMF risks and MITRE ATT&CK techniques. Confirm an address and the file arrives by email. It is separate from the engagements.
Public pages for adversary behavior, defensive countermeasures, and attacks on AI and ML systems. No account.
A monthly note. The public record of the method, the reference library, and what exercises show about AI in the SOC.
The public maturity self-assessment and framework from CarbeneAI.
Not ready for a scoping call? Subscribe to the Brief.