HOLSTER holstersecurity.com
Research & Insights

Adversarial AI. Governance.
Practical security intelligence.

Research, threat briefings, and technical guidance from the Holster team — covering the real-world risks of AI systems, regulatory developments, and operational security for SMEs.

EU AI Act: What UK Organisations Need to Do Before August 2026

The EU AI Act's high-risk AI obligations take full effect in August 2026. For UK organisations with EU customers, staff, or partners, this is not a distant deadline. We walk through the six obligations that apply first, how to determine whether your AI systems fall within the high-risk classification, and the documentation you need to produce before the enforcement date. Includes a link to our free EU AI Act Compliance Checklist.

Read checklist →
Indirect Prompt Injection in RAG Systems: How We Find It and What Developers Miss

Indirect prompt injection — where adversarial instructions are embedded in documents retrieved by a RAG pipeline — is the most consistently underestimated attack class in production AI systems. In this technical briefing, we cover the three injection vectors we see most frequently in assessments, why chunking strategies affect exploitability, how to test for embedding-layer poisoning, and the defence controls that actually reduce risk versus those that create a false sense of security.

Get in touch
Cyber Essentials 2025: What Changed, What Still Trips Organisations Up, and How to Pass First Time

The IASME Cyber Essentials requirements are updated periodically, and the 2025 requirements continue a trend toward more precise technical expectations — particularly around patch management timelines, cloud service scope, and home working device coverage. We review the current requirements, document the five failure points we see most frequently in pre-assessment reviews, and explain the Montpellier questionnaire approach for organisations taking their first submission.

Take CE check →
Why Traditional SIEM Rules Fail on AI-Specific Attacks — and What to Replace Them With

Traditional SIEM detection rules are built around network, endpoint, and application telemetry. AI-specific attacks — prompt injection attempts, model output manipulation, agent tool abuse, and UEBA anomalies in AI-enabled workflows — produce telemetry patterns that standard rules rarely capture. In this briefing, we describe the detection engineering approach behind Holster Vanguard's 114-rule catalog, focusing on five AI-specific detection categories and how they differ from conventional rules in both data sources and logic.

Get in touch
AI-Augmented Social Engineering: What the Threat Landscape Looks Like for UK SMEs in 2026

Synthetic voice calls impersonating executives, AI-generated spear-phishing email at scale, and real-time deepfake video in business video calls are no longer emerging threats for large enterprises — they are operational techniques being used against UK SMEs in 2026. This briefing summarises the threat actor TTPs we are seeing, the UK sectors being targeted most frequently, and the detection and response controls that are most effective against AI-augmented social engineering.

Threat intel →
Building an AI Risk Register: Structure, Scoring, and What Your Board Actually Needs to See

An AI risk register that sits in a document repository and is never reviewed is not a governance control — it is a liability. This guide covers the structure of an effective AI risk register, how to score AI risks in a way that is meaningful for non-technical board members, the information each entry should capture, and how to connect the register to your incident response, vendor assessment, and regulatory mapping processes. Includes a worked example entry for a customer-facing LLM chatbot.

Governance guide →

Get new research when it publishes

We publish new briefings, checklists, and threat intelligence when there is something worth saying — not on a schedule. Contact us to be notified of new publications.

Get in touch →