Adversarial AI. Governance.
Practical security intelligence.
Research, threat briefings, and technical guidance from the Holster team — covering the real-world risks of AI systems, regulatory developments, and operational security for SMEs.
Model Context Protocol (MCP) servers extend AI agent capability dramatically — and create an attack surface that most security and engineering teams have not yet assessed. In this briefing, we document the attack categories we test in MCP server assessments: tool poisoning, indirect prompt injection via MCP tool outputs, permission escalation through chained tool calls, and credential exposure in server configurations. Includes a methodology overview and a set of assessment questions to ask your AI engineering team.
The EU AI Act's high-risk AI obligations take full effect in August 2026. For UK organisations with EU customers, staff, or partners, this is not a distant deadline. We walk through the six obligations that apply first, how to determine whether your AI systems fall within the high-risk classification, and the documentation you need to produce before the enforcement date. Includes a link to our free EU AI Act Compliance Checklist.
Indirect prompt injection — where adversarial instructions are embedded in documents retrieved by a RAG pipeline — is the most consistently underestimated attack class in production AI systems. In this technical briefing, we cover the three injection vectors we see most frequently in assessments, why chunking strategies affect exploitability, how to test for embedding-layer poisoning, and the defence controls that actually reduce risk versus those that create a false sense of security.
The IASME Cyber Essentials requirements are updated periodically, and the 2025 requirements continue a trend toward more precise technical expectations — particularly around patch management timelines, cloud service scope, and home working device coverage. We review the current requirements, document the five failure points we see most frequently in pre-assessment reviews, and explain the Montpellier questionnaire approach for organisations taking their first submission.
Traditional SIEM detection rules are built around network, endpoint, and application telemetry. AI-specific attacks — prompt injection attempts, model output manipulation, agent tool abuse, and UEBA anomalies in AI-enabled workflows — produce telemetry patterns that standard rules rarely capture. In this briefing, we describe the detection engineering approach behind Holster Vanguard's 114-rule catalog, focusing on five AI-specific detection categories and how they differ from conventional rules in both data sources and logic.
Synthetic voice calls impersonating executives, AI-generated spear-phishing email at scale, and real-time deepfake video in business video calls are no longer emerging threats for large enterprises — they are operational techniques being used against UK SMEs in 2026. This briefing summarises the threat actor TTPs we are seeing, the UK sectors being targeted most frequently, and the detection and response controls that are most effective against AI-augmented social engineering.
An AI risk register that sits in a document repository and is never reviewed is not a governance control — it is a liability. This guide covers the structure of an effective AI risk register, how to score AI risks in a way that is meaningful for non-technical board members, the information each entry should capture, and how to connect the register to your incident response, vendor assessment, and regulatory mapping processes. Includes a worked example entry for a customer-facing LLM chatbot.