Joshuva A / Work

Work

Case studies

Selected work.
Clear outcomes.

Each case is told as it happened: where it started, what I did, and what changed. Read the outcome, then open the case for the story.

  1. 01 / 2025–present; audits held Sep 2026

    AI governance and ISO/IEC 42001 readiness

    Author and programme owner; auditee and owner of the IT Cybersecurity AI controls

    • AI governance
    • GRC
    • ISO/IEC 42001
    • NIST AI RMF

    Outcome

    Every AI initiative now goes through an impact assessment before it is deployed, and auditors have seen the controls behind it. The ISO/IEC 42001 Stage-1 external audit and the internal audit covering my AI controls were held in Sep 2026.

    Open full case study
    Where it started
    In 2025 teams across LatentView Analytics were starting to use AI in their own ways, and nobody had one set of rules to apply. Leadership wanted to say yes to AI without guessing at the risk, and to be able to show an auditor how each decision was made.
    What I did
    • I started with the rules. I wrote the AI governance framework, aligned to ISO/IEC 42001 and NIST AI RMF, as 8 plain-language control statements a project lead can read in ten minutes, and attached a pre-deployment impact assessment so every AI initiative is looked at before it goes live.
    • Then I looked at where AI enters the company. Before any tool was chosen I assessed a multi-LLM gateway and an AI-guard product. Since Aug 2026 the Zscaler gateway blocks personal AI logins, with guidance to staff on what to use instead.
    • In Sep 2026 I wrote the AI Security Policy for the AI management system (AIMS).
    • When the audits came, I was the auditee. I own the IT Cybersecurity AI controls: AI risk assessment, DLP, AI app monitoring, AIDR and SIEM integration, AI incident management and third-party AI security.
    Frameworks and tools
    ISO/IEC 42001 (readiness) · NIST AI RMF · AI impact assessments · Zscaler ZIA
  2. 02 / Jul–Sep 2026

    CrowdStrike Falcon AIDR across the AI entry points

    Customer-side lead

    • Cyber
    • AI security
    • CrowdStrike Falcon
    • ISO/IEC 42001

    Outcome

    Falcon AIDR covers the AI entry points: the browser, internal apps through the SDK, and the network, with the rollout problems addressed. The vendor confirmed the implementation objectives were met.

    Open full case study
    Where it started
    By mid-2026 people reached AI models from three places: the browser, internal apps and the network. Each one needed detection and response, and whatever we added had to work alongside the security stack we already ran.
    What I did
    • I began in Jul 2026 by mapping CrowdStrike Falcon AIDR to the ISO/IEC 42001 controls, so the rollout was tied to the governance programme from day one rather than bolted on later.
    • I wrote the success criteria before anything was deployed, then ran a staged rollout with CrowdStrike: the browser first, then the internal apps through the SDK, then the network.
    • Not everything worked the first time. I worked the rollout problems through with the vendor, including how AIDR sat alongside the existing stack, and kept a plan of action open until each one was closed.
    Frameworks and tools
    CrowdStrike Falcon AIDR · SDK for internal apps · ISO/IEC 42001 control mapping
  3. 03 / Ongoing; CXO Chef 2026 paper won Aug 2026

    Cyber risk quantification on SAFE Security

    CRQM model owner; member of team DataCraft for the paper

    • CRQM
    • SAFE Security
    • FAIR-CAM
    • Risk

    Outcome

    Leadership decisions now start from loss scenarios built on validated evidence rather than from colours. The winning paper takes the method into procurement: a POC starts only for a quantified risk above appetite.

    Open full case study
    Where it started
    Heat maps gave leadership colours, not answers. When they asked which cyber risk to treat first, or whether a purchase was worth it, a red square could not tell them. They wanted risk as loss scenarios, built on control evidence they could trust.
    What I did
    • I own the cyber risk quantification model (CRQM) on SAFE Security, built on the FAIR-CAM method. It turns control evidence and telemetry into loss scenarios that leadership can compare side by side.
    • Underneath it sit 68 CRQM controls, each with validated maturity evidence, so a scenario is only as strong as the proof behind the control.
    • Six API control integrations feed SAFE Security, among them CrowdStrike, Google Workspace and every multicloud platform. VAPT and phishing-simulation data are uploaded by hand.
    • In Aug 2026 the same thinking went into a competition. As part of team DataCraft I entered CXO Chef 2026 on the “Cyber budget optimization” problem statement. Our paper, “Cyber Budget Optimization — Risk-Quantified Security Investment and Procurement Governance”, won.
    Frameworks and tools
    SAFE Security · FAIR and FAIR-CAM · NIST IR 8286 series
  4. 04 / Ongoing; process revamp Dec 2025; RFC builder 2026

    Patch management across Windows, macOS and Linux

    Programme owner; builder and operator of the RFC builder (Draft-Only)

    • IT
    • Patch management
    • Change approval
    • Automation

    Outcome

    Patching runs to defined SLAs, tracked per patch, and each RFC with its results is the audit trail. The builder only drafts (Draft-Only); a person approves the change before deployment.

    Open full case study
    Where it started
    Windows, macOS and Linux endpoints had to be patched to defined SLAs, with change approval and an audit trail. Every weekday someone assembled the RFC workbook by hand from two exports, and it took most of an afternoon.
    What I did
    • In Dec 2025 I rebuilt the deployment process with the patch owner on my team: defined SLAs, per-patch tracking in ManageEngine Endpoint Central, and a documented change-approval step before anything deploys.
    • I approve the weekday patch RFCs myself, graded Critical, Important, Moderate or Low.
    • Then I built the RFC builder. An agent finds the day’s inputs and runs one Python builder; there is no model call in the build path, so the workbook comes out the same way every time. About three hours of assembly became under ten minutes.
    Frameworks and tools
    ManageEngine Endpoint Central · CrowdStrike CVE telemetry · Claude skill · Python
  5. 05 / 2026–present

    Security automation, with people in control

    Author and operator of the Zscaler review; builder of the CEO report generator, the AI Trust Control Plane and DSR Pro

    • AI use cases
    • Security operations
    • Read-Only
    • Draft-Only

    Outcome

    Two workflows now support recurring security work each month: a read-only configuration review and a drafted leadership report. Neither changes a system; people review the outputs and authorise any change that follows.

    Open full case study
    Where it started
    Some security work repeats every cycle: a monthly configuration review, a monthly leadership report, a weekly critical-tasks update. I wanted agents to prepare that work, but I was not willing to let them change a system or skip an evidence check.
    What I did
    • First I gave every automation a tier. Read-Only reads and reports. Draft-Only prepares work that a person approves. Action-Allowed is a narrow, reversible, audited exception, never the default.
    • The monthly Zscaler ZIA/ZCC configuration review now runs through a read-only MCP server. If no data comes back, the review stops rather than guessing.
    • The monthly CEO cybersecurity report starts as a draft from a generator I built; a person reviews it before it goes anywhere.
    • AI Trust Control Plane Phase 1 checks synthetic AI systems against ISO/IEC 42001, the OWASP LLM Top 10 and DPDP, fail-closed. High and critical risks wait for human sign-off. It passes 28 of 28 tests on 6 synthetic AI systems and 8 controls; the live golden-set run has not happened yet.
    • With no model call at all, I built DSR Pro, the cyber team’s task and governance platform: daily tasks, recurring governance and compliance obligations and the weekly critical-tasks update, with deny-by-default access and every change and login written to an audit log.
    Frameworks and tools
    Claude skills · read-only Zscaler MCP server · Python · OWASP LLM Top 10 · DPDP · Zscaler ZIA/ZCC · human review · change control

Day-to-day responsibility

Programmes I own

Three programmes owned end to end: patch management, secure application hosting and AI governance. Across these and the wider security practice, I lead eight people across 15+ security domains.