CXO Ready

    For CISO

    Your perimeter now includes tools nobody told you about.

    AI arrived in the business through procurement cards and free tiers, carrying real data. CXO Ready gives security the register, the exposure picture and the controls evidence for AI specifically.

    The exposure you have not been shown

    Someone in the business is pasting customer data into a free assistant. Someone else connected a vendor tool to a production data source because the integration was one click. Neither went through review, and neither shows up in any system you monitor.

    This is not a failure of policy — most organisations have one. It is that the tools are trivially easy to adopt and invisible once adopted, so the first time security learns about them is usually during an incident.

    What changes

    Shadow AI found before an incident does

    Discovery surveys surface what people are actually using, which is consistently a mix of tools worth sanctioning and a few worth stopping.

    Data exposure recorded per system

    What each AI system touches — personal data, customer data, special category — so exposure is assessed per system rather than assumed uniform.

    Kill-switch coverage made visible

    Whether each system can actually be stopped quickly. It is among the first questions asked after an incident, and among the least likely to have an answer.

    Vendor dependencies mapped

    Which third parties sit behind which systems, so a vendor compromise turns into a scoped list rather than a week of discovery.

    Your first week

    1. 1Run the discovery survey across the departments most likely to have adopted tools independently.
    2. 2Flag systems touching personal or customer data without a recorded security review.
    3. 3Check kill-switch coverage across production systems.
    4. 4Map vendor dependencies for your highest-exposure systems.

    What you are judged on

    Time to answer when something happens. If a vendor discloses a breach, the question is which of your systems depend on them and what data those systems touch — and whether that takes ten minutes or three days.

    CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.

    Before you start

    Questions from CISO

    Is CXO Ready a monitoring or detection tool?

    No. It is a system of record for governance, not an agent watching traffic. Shadow AI is surfaced through structured surveys rather than network detection, which finds tools that never touch a corporate network — the free assistant on a personal browser being the common case.

    How does this fit with our existing security programme?

    It covers the AI-specific layer your existing controls were not designed for: per-system data exposure, model kill-switches, AI vendor dependency, and the governance evidence that increasingly appears in customer security questionnaires. Evidence exports feed the GRC process you already run.

    What are the main AI-specific security risks?

    Data leaving the organisation through prompts, prompt injection in systems that act on untrusted input, over-permissioned integrations connecting AI tools to production data, and vendor dependency where the model is outside your control. All four are recorded against systems rather than treated as a general category of concern.

    How is your own platform secured?

    UK data residency, row-level security, encryption at rest and in transit, and optional multi-factor authentication, on infrastructure carrying SOC 2 and ISO 27001. We do not currently hold our own certification at application level — that is on the roadmap, and we would rather say so than imply otherwise.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy