P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Guides

Start here.

Plain answers to the questions people actually ask: what a thing is, how it works, what the trade-offs are, and where to start. No publication dates, because these are meant to stay true; each one carries the date it was last reviewed instead.

GuideWhat is cyber threat intelligence?Threat intelligence is information analysed until it changes a decision. What NIST actually says, where the four types came from, and how to tell the two apart.Read the guide →
GuideWhat is an AI agent, and what is agentic AI?An agent is a model given tools and a loop, so its output becomes action. How the loop works, why long tasks fail arithmetically, and why permissions decide the risk.Read the guide →
GuideWhat is RAG?Retrieval-augmented generation: giving a model your documents at question time. How it works, why it beats fine-tuning, and what retrieval lets in.Read the guide →
GuideAI governance roadmap: your first 90 daysWhat to do first when you are handed AI governance. Inventory before policy, and the sequence that stops you writing rules for a landscape nobody has mapped.Read the guide →
GuideWhat is AI red teaming?Structured adversarial testing of AI behaviour. How it differs from a penetration test, why a clean result proves less than it looks, and what a useful finding contains.Read the guide →
GuideWhat is MCP, and why is it a security problem?The Model Context Protocol explained as a trust boundary: what a tool description is, why the user never sees it, and what tool poisoning and rug pulls actually do.Read the guide →
GuideWhat is the EU AI Act?Who it binds, the four risk tiers, what is in force today, and what the Digital Omnibus moved to 2027 and 2028.Read the guide →
GuideWhat is NIS2?Who NIS2 catches, what Article 21 actually demands, the 24 hour reporting clock, and why organisations outside its scope are being pulled in through their customers.Read the guide →
GuideWhat is an LLM?A large language model predicts the next token. What a token actually is, measured rather than described, and why almost every famous failure follows from it.Read the guide →
GuideWhat is Cyber Essentials?The UK government-backed certification for basic cyber hygiene. The five controls, what it costs, and the answers that fail you outright.Read the guide →
GuideWhat is prompt injection?The most consequential unsolved problem in applied AI security. What it is, why filtering does not fix it, and what actually reduces the exposure.Read the guide →
GuideWhat is ISO 42001?The certifiable standard for an AI management system. What it covers, how it differs from ISO 27001, and the one requirement people get wrong.Read the guide →
GuideWhat is ISO 27001?What the certificate actually certifies, why the scope statement matters more than the certificate, what changed in the 2022 revision, and the transition deadline that has already passed.Read the guide →
GuideCyber security career roadmapWhat the UK labour market data actually shows about getting in, why certification-first advice fails most people who take it, and the route the evidence supports.Read the guide →
GuideWhat is AI, actually?What artificial intelligence is, how it differs from ordinary software, which of the popular taxonomies is real, and the legal definition that decides what you must comply with.Read the guide →
GuideWhat is n8n?n8n is a workflow automation tool you can self-host. What it does, how it differs from Zapier and Make, and whether it suits you.Read the guide →