<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Khwaja Naveed Rasheed — Articles</title><description>Writing on AI governance, cybersecurity GRC, regulation and assurance.</description><link>https://khnaveed.com/</link><language>en</language><item><title>A Gate You Can Bypass Is Not a Gate</title><link>https://khnaveed.com/articles/a-gate-you-can-bypass-is-not-a-gate/</link><guid isPermaLink="true">https://khnaveed.com/articles/a-gate-you-can-bypass-is-not-a-gate/</guid><description>Twelve scanners in the pipeline and the auditor still says no. Four structural failures that make a DevSecOps programme unprovable, and what replaces each one.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>DevSecOps</category><category>Assurance</category><category>Application Security</category></item><item><title>Four of the EU AI Act&apos;s obligation clocks are already running</title><link>https://khnaveed.com/articles/eu-ai-act-clocks-already-running/</link><guid isPermaLink="true">https://khnaveed.com/articles/eu-ai-act-clocks-already-running/</guid><description>The Act is discussed as though it arrives in the future. Four of its obligations took effect before most organisations finished reading it.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>Regulation</category><category>AI Governance</category></item><item><title>An AI inventory that survives an audit</title><link>https://khnaveed.com/articles/ai-inventory-that-survives-an-audit/</link><guid isPermaLink="true">https://khnaveed.com/articles/ai-inventory-that-survives-an-audit/</guid><description>Most AI inventories are lists of names. An auditor will ask questions a list of names cannot answer. Here is the minimum a record has to carry.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><category>AI TRiSM</category><category>Assurance</category><category>AI Governance</category></item><item><title>The economic singularity: you won&apos;t be replaced by AI, but by someone using it</title><link>https://khnaveed.com/articles/the-economic-singularity/</link><guid isPermaLink="true">https://khnaveed.com/articles/the-economic-singularity/</guid><description>An eight-level professional ladder, the ADAPT framework, and a role-by-role look at automation exposure. A career survival manual rather than a technology article.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate><category>AI Governance</category><category>Future of Work</category></item><item><title>From Die Hard to real war: wargaming a systemic cyber collapse</title><link>https://khnaveed.com/articles/wargaming-a-systemic-cyber-collapse/</link><guid isPermaLink="true">https://khnaveed.com/articles/wargaming-a-systemic-cyber-collapse/</guid><description>In 2007 Hollywood called it a fire sale. Today threat analysts call it systemic cyber risk — and the Mosaic Doctrine is how adversaries get past your perimeter.</description><pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate><category>Threat Intelligence</category><category>Resilience</category></item><item><title>From &apos;Bolt-On&apos; to &apos;Built-In&apos;: how to architect security before writing a single line of code</title><link>https://khnaveed.com/articles/from-bolt-on-to-built-in-secure-sdlc/</link><guid isPermaLink="true">https://khnaveed.com/articles/from-bolt-on-to-built-in-secure-sdlc/</guid><description>Security discovered two weeks before launch is an architecture problem, not a testing problem. Five phases of a Secure SDLC, told through the failures each one prevents.</description><pubDate>Fri, 19 Dec 2025 00:00:00 GMT</pubDate><category>DevSecOps</category><category>Assurance</category></item><item><title>Think before you share: a strategic guide to private sector data sharing in Saudi Arabia</title><link>https://khnaveed.com/articles/think-before-you-share-saudi-data-sharing/</link><guid isPermaLink="true">https://khnaveed.com/articles/think-before-you-share-saudi-data-sharing/</guid><description>Every outbound dataset is a handshake. A practical guide to PDPL, SDAIA, NDMO, SAMA and NCA obligations for private sector organisations in the Kingdom.</description><pubDate>Fri, 27 Jun 2025 00:00:00 GMT</pubDate><category>Saudi Regulation</category><category>Data Protection</category><category>Third-Party Risk</category></item><item><title>The ultimate guide to data loss prevention</title><link>https://khnaveed.com/articles/the-ultimate-guide-to-data-loss-prevention/</link><guid isPermaLink="true">https://khnaveed.com/articles/the-ultimate-guide-to-data-loss-prevention/</guid><description>Seven pillars of a DLP programme, from discovering the data you have forgotten about to building the human firewall that stops the rest.</description><pubDate>Sun, 09 Mar 2025 00:00:00 GMT</pubDate><category>Data Protection</category><category>Assurance</category></item><item><title>Cybersecurity in change management: why every click and byte matters</title><link>https://khnaveed.com/articles/cybersecurity-in-change-management/</link><guid isPermaLink="true">https://khnaveed.com/articles/cybersecurity-in-change-management/</guid><description>Most breaches trace back to a change nobody assessed. A step-by-step look at where security belongs in the change process, and what happens when it is missing.</description><pubDate>Sat, 01 Feb 2025 00:00:00 GMT</pubDate><category>Assurance</category><category>DevSecOps</category></item><item><title>Third-party risk management: shielding your business from hidden threats</title><link>https://khnaveed.com/articles/third-party-risk-management/</link><guid isPermaLink="true">https://khnaveed.com/articles/third-party-risk-management/</guid><description>Your cybersecurity is only as strong as your weakest vendor. Five components of a TPRM framework that actually finds the risk before it finds you.</description><pubDate>Sat, 18 Jan 2025 00:00:00 GMT</pubDate><category>Third-Party Risk</category><category>Assurance</category></item><item><title>IAM: the secret formula to safeguard your digital kingdom</title><link>https://khnaveed.com/articles/iam-framework-safeguard-your-digital-kingdom/</link><guid isPermaLink="true">https://khnaveed.com/articles/iam-framework-safeguard-your-digital-kingdom/</guid><description>Identity has become the control plane. The five building blocks of an IAM framework that enables the business rather than obstructing it.</description><pubDate>Sat, 11 Jan 2025 00:00:00 GMT</pubDate><category>Identity &amp; Access</category><category>Assurance</category></item><item><title>Building a cloud security strategy that inspires confidence</title><link>https://khnaveed.com/articles/building-a-cloud-security-strategy/</link><guid isPermaLink="true">https://khnaveed.com/articles/building-a-cloud-security-strategy/</guid><description>Individual controls are tools in a backpack. A strategy is the map that turns them into a safety net — six things it has to settle.</description><pubDate>Fri, 10 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Resilience</category></item><item><title>Kubernetes security: a universal challenge</title><link>https://khnaveed.com/articles/kubernetes-security-a-universal-challenge/</link><guid isPermaLink="true">https://khnaveed.com/articles/kubernetes-security-a-universal-challenge/</guid><description>Hundreds of clusters, including Fortune 500 estates, found openly accessible. The misconfigurations do not care whether you run in cloud or on-premises — and neither should your response.</description><pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Assurance</category></item></channel></rss>