“When auditors arrive, a public commitment must survive scrutiny, not just satisfy an unread policy; the safest control is the one that is used.”

When auditors arrive, a public commitment must survive scrutiny, not just satisfy an unread policy; the safest control is the one that is used. — Kai London (Professor Kai London), CISO. Principle 3296 of 10000 from the book “Trustquake” — cybersecurity, AI security and OT resilience doctrine. Official sites: professorkailondon.com · kailondon.co.uk