Khwaja Naveed Rasheed Cybersecurity GRC · AI Security

Video

Talks, tutorials & episodes

Short explainers on the instruments, longer walk-throughs of the methods, and conversations about where AI governance is actually landing inside enterprises.

Podcast

A Gate You Can Bypass Is Not a Gate

Twelve scanners in the pipeline and a dashboard that is mostly green, and the assessor still dismantles the programme in four questions. The four structural failures that make a DevSecOps programme unprovable: the gate that is not a gate, five registers pretending to be one, coverage without a denominator, and evidence a human had to assemble.

  • DevSecOps
  • Secure SDLC
  • AppSec
  • Audit Evidence
Watch on YouTube
Podcast

It Doesn’t Crash. It Answers Confidently, And It’s Wrong.

Every incident process ever written assumes something breaks. This one stays up, stays fast, and is confidently wrong — and nothing in your estate is built to notice. The operating manual from AI Security Strategy: the inventory, the classification instrument, five assurance gates and thirty-six agentic controls.

  • AI Security
  • Prompt Injection
  • Agentic AI
  • Red Teaming
Watch on YouTube
Podcast

Your ISO 42001 Certificate Does Not Answer the Auditor’s Question

An auditor asks one question: show me how you know this model is safe. A certificate cannot answer it, because it certifies your management system and the auditor is asking about your model. Where each AI instrument stops, and the crosswalk that turns a blank cell into a finding.

  • AI Governance
  • EU AI Act
  • ISO/IEC 42001
  • Assurance
Watch on YouTube
Podcast

The Line Every Cloud Provider Draws

Shared responsibility is a contract about who gets blamed, not a diagram. Where the line actually sits, how the deployment model moves it, and why whoever holds the encryption keys holds the risk.

  • Cloud Security
  • Shared Responsibility
  • Zero Trust
  • Encryption
Watch on YouTube