A practical policy and configuration guide for detecting prompt injection and jailbreak attempts before inference, then blocking unsafe content and sensitive-data disclosure before model output reaches a user, tool, or application.
After reading my post on AI firewalls, a friend asked for my take on prompt injection. Prompt injection becomes dangerous when untrusted content can steer a software principal into using authority that the content never possessed.
A reader of the Cybersecurity Architect's Handbook Second Edition recently asked whether the Kubernetes sidecar pattern discussed in Chapter 13 applies only when an organization hosts its own large language model. The short answer is no.
Part 2 puts the security in motion: services, the monitoring pipeline your log lines feed, wireless done currently, safe remote access, and where it all leads.
Part 1, The Machine and Its Evidence established one working rule: the GUI shows you what exists, and PowerShell is how you inspect it precisely and repeat the work across ten machines. Windows Server administration assumes you are somewhere else...
Your first job in this field will hand you a domain-joined Windows machine and expect competence by Friday. Nearly every security career runs through the Windows estate whether it was planned or not...
My first Linux distribution no longer exists. I mention that because it lands two points at once: Linux is old enough to have history, and the skills transfer anyway...
Yesterday I wrote about moving autonomous-agent secrets out of a flat .env file. Why I kept Vaultwarden for people and recovery, added HashiCorp Vault for workloads, and treated identity, audit, PKI, and tested recovery as part of the deployment rather than follow-up work.