<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Field Notes</title>
    <link>http://www.rkon.com/resources/field-notes</link>
    <description>Insights, guides, and resources on cybersecurity and IT strategy from RKON.</description>
    <language>en</language>
    <pubDate>Wed, 23 Sep 2026 14:17:20 GMT</pubDate>
    <dc:date>2026-09-23T14:17:20Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk</title>
      <link>http://www.rkon.com/resources/field-notes/penetration-testing-isnt-about-finding-vulnerabilities-its-about-reducing-business-risk</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/penetration-testing-isnt-about-finding-vulnerabilities-its-about-reducing-business-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/image-5.png" alt="Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/penetration-testing-isnt-about-finding-vulnerabilities-its-about-reducing-business-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/image-5.png" alt="Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fpenetration-testing-isnt-about-finding-vulnerabilities-its-about-reducing-business-risk&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <pubDate>Tue, 04 Aug 2026 10:00:46 GMT</pubDate>
      <author>aparrish@rkon.com (Ashley Parrish)</author>
      <guid>http://www.rkon.com/resources/field-notes/penetration-testing-isnt-about-finding-vulnerabilities-its-about-reducing-business-risk</guid>
      <dc:date>2026-08-04T10:00:46Z</dc:date>
    </item>
    <item>
      <title>A Lot Can Change Between Penetration Tests</title>
      <link>http://www.rkon.com/resources/field-notes/a-lot-can-change-between-penetration-tests</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/a-lot-can-change-between-penetration-tests" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/25657699_wangxi_09_04_2022_27-1.png" alt="A Lot Can Change Between Penetration Tests" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/a-lot-can-change-between-penetration-tests" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/25657699_wangxi_09_04_2022_27-1.png" alt="A Lot Can Change Between Penetration Tests" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fa-lot-can-change-between-penetration-tests&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <pubDate>Thu, 30 Jul 2026 10:00:11 GMT</pubDate>
      <author>aparrish@rkon.com (Ashley Parrish)</author>
      <guid>http://www.rkon.com/resources/field-notes/a-lot-can-change-between-penetration-tests</guid>
      <dc:date>2026-07-30T10:00:11Z</dc:date>
    </item>
    <item>
      <title>Your Security Tools Are Working...But Would They Stop a Real Attack?</title>
      <link>http://www.rkon.com/resources/field-notes/your-security-tools-are-working-but-would-they-stop-a-real-attack</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/your-security-tools-are-working-but-would-they-stop-a-real-attack" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/shutterstock_2480938729-1.jpg" alt="Your Security Tools Are Working...But Would They Stop a Real Attack?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/your-security-tools-are-working-but-would-they-stop-a-real-attack" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/shutterstock_2480938729-1.jpg" alt="Your Security Tools Are Working...But Would They Stop a Real Attack?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fyour-security-tools-are-working-but-would-they-stop-a-real-attack&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <pubDate>Tue, 28 Jul 2026 18:45:05 GMT</pubDate>
      <author>aparrish@rkon.com (Ashley Parrish)</author>
      <guid>http://www.rkon.com/resources/field-notes/your-security-tools-are-working-but-would-they-stop-a-real-attack</guid>
      <dc:date>2026-07-28T18:45:05Z</dc:date>
    </item>
    <item>
      <title>FedRAMP Just Deleted the 300-Page SSP. What Replaces It Is Code.</title>
      <link>http://www.rkon.com/resources/field-notes/fedramp-cr26-deleted-300-page-ssp</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/fedramp-cr26-deleted-300-page-ssp" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/fedramp-cr26.png" alt="FedRAMP Just Deleted the 300-Page SSP. What Replaces It Is Code." class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;p&gt;The System Security Plan is dead. &lt;a href="https://www.rkon.com/enterprise-services/it-advisory/fedramp/"&gt;FedRAMP’s&lt;/a&gt; Consolidated Rules for 2026 (CR26), published June 24, retired the document that defined federal cloud compliance for over a decade. Hundreds of pages of narrative control descriptions, manually maintained, outdated the day they were submitted. The replacement is a Security Decision Record (SDR) backed by machine-readable Key Security Indicators (KSIs) validated on a continuous cadence. FedRAMP CR26 replaced the compliance deliverable with a data feed a machine validates.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What Killed the SSP&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;The SSP was a narrative artifact. Prose descriptions of how each control was implemented, maintained by a compliance team, submitted to a Third-Party Assessment Organization (3PAO) for annual review. In practice, the SSP drifted from reality almost immediately. Engineers changed configurations. Infrastructure evolved. The document stayed frozen until the next assessment cycle, when the compliance team scrambled to reconcile what the SSP described with what the environment actually looked like.&lt;/p&gt; 
      &lt;p&gt;FedRAMP CR26 replaces the SSP with the SDR, a persistently maintained and validated record of security decisions over the lifecycle of a cloud service offering. The Plans of Action and Milestones (POA&amp;amp;M) is retired as a standalone artifact. “FedRAMP Authorized” becomes “FedRAMP Certified.” Impact levels (Low, Moderate, High) become Certification Classes (A through D). The terminology changes reflect the structural shift: certification implies ongoing validation, not one-time approval.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What Machine-Readable Evidence Actually Looks Like&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;KSIs replace narrative control descriptions. Each KSI is a structured, machine-readable data point that demonstrates a security capability in practice. The canonical CR26 rules define 46 KSIs across 10 themes covering identity and access management, monitoring and logging, cloud-native architecture, change management, incident response, and others.&lt;/p&gt; 
      &lt;p&gt;The cadence is the real shift. Machine-validated KSIs must be re-verified at minimum every 3 days at Moderate (Class C). Non-machine KSIs, the attestation-based controls that cover things like security awareness training and supply-chain risk reviews, re-validate every 3 months. At least 70% of all KSIs must have automated validation capability. This is continuous monitoring on a cadence that would have been unrecognizable under Rev5.&lt;/p&gt; 
      &lt;p&gt;The KSI definitions and validation schemas are published as structured JSON in FedRAMP’s public GitHub repository (FedRAMP/rules), versioned and machine-consumable. A compliance automation tool can pull current requirements directly rather than parsing guidance out of a PDF. FedRAMP’s own framing: the rules repository functions more like an API than a library shelf.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What This Requires From Your Environment&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;The KSI model requires your environment to emit evidence on a cadence. Centralized identity with auditable federation. Infrastructure-as-code with version-controlled state. Centralized logging flowing into a Security Information and Event Management (SIEM) platform with queryable retention. Automated configuration management that can detect and report drift against a declared baseline.&lt;/p&gt; 
      &lt;p&gt;If your identity provider can’t produce a machine-readable federation report on a 72-hour cadence, the KSI fails. If your infrastructure isn’t codified in a way a validator can independently verify, the KSI fails.&lt;/p&gt; 
      &lt;p&gt;The organizations that already run infrastructure-as-code, centralized logging, and automated configuration management are closer than they think. The ones still managing cloud infrastructure through console clicks and documenting controls in Word files have a gap measured in architecture.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Timeline Is Tighter Than It Looks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;FedRAMP CR26 is optional today. It becomes mandatory January 1, 2027. FedRAMP stops accepting new Rev5 applications June 11, 2027. All transitional grace periods expire February 1, 2028. Existing Rev5 certifications sunset entirely December 31, 2028.&lt;/p&gt; 
      &lt;p&gt;For organizations currently certified under Rev5: you have roughly 18 months to transition to an evidence model that looks nothing like the one you built your compliance program around. For organizations pursuing their first FedRAMP certification: starting on Rev5 now means building for a framework that expires before you finish. Start on 20x.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Compliance Industry Built Around the SSP Just Lost Its Moat&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;Under 20x, the deliverable is a machine-readable package that a validator can independently re-verify on a 3-day cadence. The competitive advantage is infrastructure capability. FedRAMP has said directly that the automated tooling 20x assumes largely doesn’t exist in market yet. The firms that can generate conformant evidence from live infrastructure have the advantage. The ones still writing better narratives are solving last decade’s problem.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Writer Notes&lt;/strong&gt;&lt;/h2&gt; 
      &lt;h3&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/h3&gt; 
      &lt;ul&gt; 
       &lt;li&gt;FedRAMP CR26 published rules (fedramp.gov, June 24-25, 2026, v2026.07.06.01)&lt;/li&gt; 
       &lt;li&gt;FedRAMP/rules GitHub repository (machine-readable KSI definitions, JSON schemas)&lt;/li&gt; 
       &lt;li&gt;FedRAMP/schemas GitHub repository (CR26 package schemas)&lt;/li&gt; 
       &lt;li&gt;FedRAMP 20x overview (fedramp.gov/20x)&lt;/li&gt; 
       &lt;li&gt;FedRAMP CR26 public preview announcement (fedramp.gov, May 4, 2026)&lt;/li&gt; 
       &lt;li&gt;Paramify CR26 deadline timeline (paramify.com/blog/cr26-deadlines)&lt;/li&gt; 
       &lt;li&gt;RKON internal primary-source research (20x-CR26-research-gap-plan.md, verified 2026-07-08)&lt;/li&gt; 
      &lt;/ul&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/fedramp-cr26-deleted-300-page-ssp" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/fedramp-cr26.png" alt="FedRAMP Just Deleted the 300-Page SSP. What Replaces It Is Code." class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;p&gt;The System Security Plan is dead. &lt;a href="https://www.rkon.com/enterprise-services/it-advisory/fedramp/"&gt;FedRAMP’s&lt;/a&gt; Consolidated Rules for 2026 (CR26), published June 24, retired the document that defined federal cloud compliance for over a decade. Hundreds of pages of narrative control descriptions, manually maintained, outdated the day they were submitted. The replacement is a Security Decision Record (SDR) backed by machine-readable Key Security Indicators (KSIs) validated on a continuous cadence. FedRAMP CR26 replaced the compliance deliverable with a data feed a machine validates.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What Killed the SSP&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;The SSP was a narrative artifact. Prose descriptions of how each control was implemented, maintained by a compliance team, submitted to a Third-Party Assessment Organization (3PAO) for annual review. In practice, the SSP drifted from reality almost immediately. Engineers changed configurations. Infrastructure evolved. The document stayed frozen until the next assessment cycle, when the compliance team scrambled to reconcile what the SSP described with what the environment actually looked like.&lt;/p&gt; 
      &lt;p&gt;FedRAMP CR26 replaces the SSP with the SDR, a persistently maintained and validated record of security decisions over the lifecycle of a cloud service offering. The Plans of Action and Milestones (POA&amp;amp;M) is retired as a standalone artifact. “FedRAMP Authorized” becomes “FedRAMP Certified.” Impact levels (Low, Moderate, High) become Certification Classes (A through D). The terminology changes reflect the structural shift: certification implies ongoing validation, not one-time approval.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What Machine-Readable Evidence Actually Looks Like&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;KSIs replace narrative control descriptions. Each KSI is a structured, machine-readable data point that demonstrates a security capability in practice. The canonical CR26 rules define 46 KSIs across 10 themes covering identity and access management, monitoring and logging, cloud-native architecture, change management, incident response, and others.&lt;/p&gt; 
      &lt;p&gt;The cadence is the real shift. Machine-validated KSIs must be re-verified at minimum every 3 days at Moderate (Class C). Non-machine KSIs, the attestation-based controls that cover things like security awareness training and supply-chain risk reviews, re-validate every 3 months. At least 70% of all KSIs must have automated validation capability. This is continuous monitoring on a cadence that would have been unrecognizable under Rev5.&lt;/p&gt; 
      &lt;p&gt;The KSI definitions and validation schemas are published as structured JSON in FedRAMP’s public GitHub repository (FedRAMP/rules), versioned and machine-consumable. A compliance automation tool can pull current requirements directly rather than parsing guidance out of a PDF. FedRAMP’s own framing: the rules repository functions more like an API than a library shelf.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What This Requires From Your Environment&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;The KSI model requires your environment to emit evidence on a cadence. Centralized identity with auditable federation. Infrastructure-as-code with version-controlled state. Centralized logging flowing into a Security Information and Event Management (SIEM) platform with queryable retention. Automated configuration management that can detect and report drift against a declared baseline.&lt;/p&gt; 
      &lt;p&gt;If your identity provider can’t produce a machine-readable federation report on a 72-hour cadence, the KSI fails. If your infrastructure isn’t codified in a way a validator can independently verify, the KSI fails.&lt;/p&gt; 
      &lt;p&gt;The organizations that already run infrastructure-as-code, centralized logging, and automated configuration management are closer than they think. The ones still managing cloud infrastructure through console clicks and documenting controls in Word files have a gap measured in architecture.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Timeline Is Tighter Than It Looks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;FedRAMP CR26 is optional today. It becomes mandatory January 1, 2027. FedRAMP stops accepting new Rev5 applications June 11, 2027. All transitional grace periods expire February 1, 2028. Existing Rev5 certifications sunset entirely December 31, 2028.&lt;/p&gt; 
      &lt;p&gt;For organizations currently certified under Rev5: you have roughly 18 months to transition to an evidence model that looks nothing like the one you built your compliance program around. For organizations pursuing their first FedRAMP certification: starting on Rev5 now means building for a framework that expires before you finish. Start on 20x.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Compliance Industry Built Around the SSP Just Lost Its Moat&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;Under 20x, the deliverable is a machine-readable package that a validator can independently re-verify on a 3-day cadence. The competitive advantage is infrastructure capability. FedRAMP has said directly that the automated tooling 20x assumes largely doesn’t exist in market yet. The firms that can generate conformant evidence from live infrastructure have the advantage. The ones still writing better narratives are solving last decade’s problem.&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Writer Notes&lt;/strong&gt;&lt;/h2&gt; 
      &lt;h3&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/h3&gt; 
      &lt;ul&gt; 
       &lt;li&gt;FedRAMP CR26 published rules (fedramp.gov, June 24-25, 2026, v2026.07.06.01)&lt;/li&gt; 
       &lt;li&gt;FedRAMP/rules GitHub repository (machine-readable KSI definitions, JSON schemas)&lt;/li&gt; 
       &lt;li&gt;FedRAMP/schemas GitHub repository (CR26 package schemas)&lt;/li&gt; 
       &lt;li&gt;FedRAMP 20x overview (fedramp.gov/20x)&lt;/li&gt; 
       &lt;li&gt;FedRAMP CR26 public preview announcement (fedramp.gov, May 4, 2026)&lt;/li&gt; 
       &lt;li&gt;Paramify CR26 deadline timeline (paramify.com/blog/cr26-deadlines)&lt;/li&gt; 
       &lt;li&gt;RKON internal primary-source research (20x-CR26-research-gap-plan.md, verified 2026-07-08)&lt;/li&gt; 
      &lt;/ul&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Ffedramp-cr26-deleted-300-page-ssp&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <category>Security &amp; Compliance</category>
      <pubDate>Thu, 23 Jul 2026 02:48:53 GMT</pubDate>
      <author>ramsha.shakeel@decklaration.com (Ramsha Shakeel)</author>
      <guid>http://www.rkon.com/resources/field-notes/fedramp-cr26-deleted-300-page-ssp</guid>
      <dc:date>2026-07-23T02:48:53Z</dc:date>
    </item>
    <item>
      <title>What Every Executive Needs to Know About LLM Security</title>
      <link>http://www.rkon.com/resources/field-notes/executive-needs-to-know-about-llm-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/executive-needs-to-know-about-llm-security" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/article-2-training-phase-attacks.png" alt="What Every Executive Needs to Know About LLM Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;h2 style="text-align: center;"&gt;&lt;strong&gt;Article 2: Training-Phase Attacks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;Welcome to Article 2. If you missed the introduction in Article 1, find it &lt;a href="https://www.rkon.com/articles/hacking-ai-executive-know-about-llm-security/"&gt;HERE&lt;/a&gt;&lt;/p&gt; 
      &lt;p&gt;In 1962, John Frankenheimer made a film about a soldier, Raymond Shaw, who came home from war as a decorated hero. Capable. Loyal. Sane. Personable. But he had been captured and brainwashed by an enemy to perform a very specific, nefarious, purpose. Nobody suspected a thing. He remained perfectly normal until activated, when someone showed him the queen of diamonds.&lt;/p&gt; 
      &lt;p&gt;The Manchurian Candidate introduced an idea that once seemed like pure Cold War paranoia: a person whose mind was secretly reprogrammed, acting normally until a specific trigger made them carry out hidden instructions. It was fiction, a great movie, and a chilling concept. It is a terrifying premise, but what is covered in this paper scares me more.&lt;/p&gt; 
      &lt;p&gt;What Frankenheimer imagined for Raymond Shaw, adversaries are doing to AI models right now. And unlike Raymond, your model won’t even look uncomfortable or unusual when it happens.&lt;/p&gt; 
      &lt;p&gt;This article is especially relevant for organizations building or customizing AI models. Fine-tuning uses your proprietary data on open-source models. Integrating third-party models adds external AI to your systems. Using commercial AI as-is relies on unmodified tools from major vendors. If you use only commercial AI from major vendors, training-phase security is primarily their responsibility. However, some risks remain.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;How Training Works (The Part You Need to Know)&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;You don’t need a machine learning degree, just a clear mental model of how this works.&lt;/p&gt; 
      &lt;p&gt;AI models learn by processing enormous volumes of text data. They develop patterns of behavior, things they will say, things they won’t say, how they respond to various kinds of requests, their feelings on world domination, you get it.&lt;/p&gt; 
      &lt;p&gt;Both steps present opportunities for attack. Since a successful attack is hidden within the model’s training, rather than in a log file, it is very hard to detect later.&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw’s handlers didn’t leave a note when they brainwashed him. Neither do these.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Attacks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;h3&gt;&lt;strong&gt;Data Poisoning: Corrupting the Curriculum&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;The most straightforward and common training-phase attack doesn’t touch the model at all. It touches the data the model learns from.&lt;/p&gt; 
      &lt;p&gt;If an adversary can insert malicious content into a training dataset, the model will absorb it. It learns from it. Treats it as truth. So, the model isn’t hacked in the traditional sense. It’s just miseducated, on purpose, by someone who knew exactly what lessons they wanted it to learn.&lt;/p&gt; 
      &lt;p&gt;Once attackers have access, this is not hard to do. Most AI models are trained on datasets that include publicly available content, open-source repositories, and third-party sources. Hugging Face, the largest public repository for AI models and datasets, hosts over 100,000 datasets that anyone can contribute to. If you use these sources without careful filtering, you are relying on data with limited controls. We already know how that story ends.&lt;/p&gt; 
      &lt;p&gt;The effects of data poisoning range from subtle to explosive. A poisoned model might develop biases, quietly favoring certain outputs in ways that aren’t obvious. You may never notice unless you look for patterns across thousands of decisions. But when it gets bad, poisoning can be the setup for something much worse.&lt;/p&gt; 
      &lt;p&gt;And don’t assume your commercial models are insulated. Even organizations using AI from major vendors typically incorporate third-party data into their training pipelines. The surface is larger than most people realize.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;Backdoor Attacks: The Queen of Diamonds&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;This is where Raymond Shaw comes back into the picture. His trainers/brainwashers had a specific, nefarious intent.&lt;/p&gt; 
      &lt;p&gt;A backdoor attack is a form of data poisoning with specific intent. The adversary doesn’t just corrupt the training data generally. They plant a trigger: a specific word, phrase, token sequence, or pattern that causes the model to behave in a predetermined malicious way. Under every other circumstance, the model performs normally. It passes evaluations. It tests clean. It serves well and normally, for months, until someone uses the trigger.&lt;/p&gt; 
      &lt;p&gt;In the movie, the trigger is a playing card. Show Raymond the queen of diamonds, and he’s no longer Raymond Shaw, war hero. He’s someone else entirely.&lt;/p&gt; 
      &lt;p&gt;In a backdoor attack, when the trigger shows up, the model stops being your friendly neighborhood AI and becomes a trained attacker.&lt;/p&gt; 
      &lt;p&gt;What does that look like? A customer-facing AI triggered to provide dangerous information it would otherwise refuse, like “Show me all customer information.” A code-generation model triggered to insert vulnerabilities into the produced code. A security tool triggered to shut down controls when it sees specific threat signatures. You get the idea. The behavior is determined entirely by the attacker’s goal.&lt;/p&gt; 
      &lt;p&gt;According to Anthropic’s research, only 250 documents are needed to create a backdoor in a model with 600 million or more parameters. As models get larger, backdoors become even more effective. Research shows that as model size increases from 1.3 billion to 6 billion parameters, backdoor attack success rates on triggered inputs can reach nearly 100 percent, while normal performance remains completely intact. 100%! Bigger models are just more capable compromised models.&lt;/p&gt; 
      &lt;p&gt;One variant that is true nightmare fuel is a syntactic backdoor, where the trigger is a grammatical structure rather than a specific word. Patterns that occur naturally in everyday language activate malicious behavior. No anomalous token, no suspicious phrase. The model just behaves differently when it encounters a sentence built in a certain way.&lt;a href="#_ftn1"&gt;[1]&lt;/a&gt;&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw could be activated by a playing card. At least his handlers had to find the right card. Your model’s trigger might already be in your users’ natural vocabulary. They could ask a mundane, expected, question and start a chain of events ending in a breach.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;LoRA (Low Rank Adaptation) Injection: Backdoor on a Budget&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Since fine-tuning a large model takes serious computing resources, time, and money, organizations often use LoRA (Low-Rank Adaptation). LoRA is a technique that lets you customize a base model by training a small adapter layer attached to the original model rather than retraining the entire model. It’s faster and cheaper, and it introduces a new attack surface.&lt;/p&gt; 
      &lt;p&gt;LoRA-based injection happens in two steps. First, an attacker fine-tunes a LoRA adapter with as little as one to two percent adversarial data, creating a backdoor. Then, they merge this poisoned adapter with legitimate adapters. No full model retraining is needed. The result appears to be a normal fine-tuned model, but it is waiting to be activated by a trigger.&lt;/p&gt; 
      &lt;p&gt;More LoRA fine-tuning services on platforms like Hugging Face mean increasing supply chain risk as organizations use more fine-tuned open-source models in business.&lt;/p&gt; 
      &lt;p&gt;Like any open-source tool, if you are deploying a fine-tuned model from a third-party source, you need to think about where that adapter came from and who trained it.&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw was reprogrammed in a facility controlled by his handlers. LoRA injection is reprogramming for hire, at scale, no facility required.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;RAG Poisoning: Corrupting the Memory, Not the Mind&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Now we have no training at all. Instead, many organizations use Retrieval Augmented Generation (RAG), where a base model pulls from an external document store to answer questions at query time, rather than recalling facts from its original training data.&lt;/p&gt; 
      &lt;p&gt;Smart and dynamic architecture, yes. New attack surface, also yes.&lt;/p&gt; 
      &lt;p&gt;You already figured it out, I bet. RAG poisoning refers to corrupting the external knowledge base, rather than the model itself. If malicious content enters your retrieval index (the searchable external store), the model retrieves and presents attacker-controlled information as authoritative. The model itself is functioning as designed; the problem is that the data source is compromised.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Real World: This Isn’t Science Fiction Anymore&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;Okay, I know the Manchurian Candidate framing makes this feel dramatic. But it is dramatic because this one is real.&lt;/p&gt; 
      &lt;p&gt;IBM’s 2025 Cost of a Data Breach Report found that 13 percent of organizations reported breaches involving AI models or applications. Of those, 97% reported a lack of proper AI access controls. Both numbers were up from the prior year, which is not a comforting direction.&lt;/p&gt; 
      &lt;p&gt;On the supply chain side, researchers demonstrated that you can poison the instruction-tuning data for a single low-resource language and produce a backdoor that activates across every language the model supports, including English, with attack success rates above 99 percent&lt;a href="#_ftn1"&gt;[1]&lt;/a&gt;. Do you have these low-scrutiny side doors that they can slip through? The effect propagates everywhere the model operates.&lt;/p&gt; 
      &lt;p&gt;The problem with using third-party fine-tuned models is limited visibility. You test the model. You evaluate its outputs on expected inputs. But if the backdoor trigger never appears, the Queen of Hearts never shows up in the deck you’re testing with, you won’t spot the issue.&lt;/p&gt; 
      &lt;p&gt;Unlike Raymond Shaw, your model will not sweat or hesitate. It will show no signs of distress. It will just do the thing.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Risk and Impact&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;What actually happens if one of these attacks succeeds in your environment depends, of course, heavily on what your model is doing. Is it powering an internal knowledge tool, or is it generating production code, or is a compromised model playing a role in your security operations? The blast radius scales with the trust and access you’ve given the system.&lt;/p&gt; 
      &lt;p&gt;The trigger only activates under specific conditions. Without a red team (a group that simulates real-world attacks to test security) actively probing for unexpected behavior, or without the trigger appearing accidentally in production traffic, the compromise can remain undetected throughout the model’s operational life. Even red teaming is no guarantee, as the trigger may be very obscure.&lt;/p&gt; 
      &lt;p&gt;The fact that the corruption originated in a third-party dataset is not a defense that will satisfy customers, regulators, or your board. You shipped it, you own it. The liability is yours.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What Good (Sort Of) Looks Like&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;This is not a solved problem. But there’s a significant gap between you doing nothing and you doing the basics. The basics matter, they always do in security.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Know What You’re Training On&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Treat training data with the same care you would give to a software dependency or vendor contract. Ask where it came from, whether it has been independently reviewed, and what its origin is. These are standard questions.&lt;/p&gt; 
      &lt;p&gt;For RAG pipelines, apply the same logic to your knowledge stores. Who can write to the retrieval index? Is there an approval process? Are you monitoring for anomalous additions? The index is a security asset. If you don’t treat it like one, shame on you.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Test for Unexpected Behavior, Not Just Expected Performance&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Testing if the model does what you expect on inputs is not backdoor testing. Backdoor testing needs to check whether the model does something unexpected on inputs you expect and don’t expect.&lt;/p&gt; 
      &lt;p&gt;Before deploying your model, run some evaluations. Test with unusual inputs, rare tokens, and syntactic variations. Red-team for surprising behavior. You may not catch every backdoor, but you can catch the ones that weren’t carefully hidden, and those are the most common.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Treat LoRA Adapters Like Code&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;LoRA adapters require a review process. Ask where they came from, who trained them, and what data was used. Test the merged model for unexpected behavior after combining adapters. This is the same supply chain discipline that software development has learned from past compromises. AI model components need the same level of scrutiny.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lock Down Your Knowledge Stores&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Access controls and security on the RAG &amp;nbsp;retrieval index matter. Write permissions should be tightly controlled and logged. New content additions should be reviewable. Try asking your team, “What happens to your AI outputs if someone inserts a document into that index?” Often, the honest answer is that it will simply ingest it.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Prefer Verifiable Sources&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;When you pull a base model from a public repository, you’re making a trust decision. Models from research institutions and major AI labs have a different risk profile than a fine-tuned model uploaded by an account with no history and no documentation to a public site. Open-source models are not the problem. Unvetted open-source models are.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Questions to Ask Your Team About Training-phase Attacks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Where did the training data come from? Can someone trace the source and ownership of any datasets used to fine-tune models? Is there a documented review process, or did someone just pull a dataset and run with it?&lt;/li&gt; 
       &lt;li&gt;What behavioral testing happened before deployment? Was anyone specifically looking for unexpected behavior, or just expected performance?&lt;/li&gt; 
       &lt;li&gt;Who has write access to your RAG knowledge stores? Is it logged? Is there an approval process for new document ingestion, or can anyone with access add anything?&lt;/li&gt; 
       &lt;li&gt;Where are your fine-tuned adapters coming from? Are third-party LoRA adapters reviewed before use? Is the merged model tested after the combination?&lt;/li&gt; 
       &lt;li&gt;When models are updated, does the security review repeat? Or does the original approval carry forward indefinitely?&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;Having clear and documented answers to these questions puts you ahead of most organizations. If there is uncertainty or silence, use it as a starting point for an important conversation. Do not be discouraged if your team does not have all the answers, most teams are in the same position.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Bottom Line&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;The Manchurian Candidate was released over 60 years ago. The concept it introduced, a trusted agent secretly conditioned to behave maliciously on command, was science fiction then. It’s now a documented attack category, applied not to soldiers but to your AI systems, which you are trusting with increasing access and authority.&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw passed every test his handlers needed him to pass. Your backdoored model will too. The difference is that you have options, Shaw didn’t. You can scrutinize the training data. You can test for unexpected behavior. You can treat model components as supply chain risk. You can control who writes to your knowledge stores.&lt;/p&gt; 
      &lt;p&gt;Basic discipline goes a long way here. Most organizations aren’t applying it yet. That’s a problem and an opportunity, which one will you let it be?&lt;/p&gt; 
      &lt;p&gt;&lt;em&gt;Next: Article 3, Privacy and Extraction Attacks. Once a model is trained, what can an adversary make it reveal? And what happens when what it reveals turns out to be yours.&lt;/em&gt;&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;NOTE ON THE USE OF AI IN THIS DOCUMENT&lt;/h3&gt; 
      &lt;p&gt;&lt;em&gt;The document is primarily human-edited and created. AI was used in the research and editing of this document.&lt;/em&gt;&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/executive-needs-to-know-about-llm-security" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/article-2-training-phase-attacks.png" alt="What Every Executive Needs to Know About LLM Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;h2 style="text-align: center;"&gt;&lt;strong&gt;Article 2: Training-Phase Attacks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;Welcome to Article 2. If you missed the introduction in Article 1, find it &lt;a href="https://www.rkon.com/articles/hacking-ai-executive-know-about-llm-security/"&gt;HERE&lt;/a&gt;&lt;/p&gt; 
      &lt;p&gt;In 1962, John Frankenheimer made a film about a soldier, Raymond Shaw, who came home from war as a decorated hero. Capable. Loyal. Sane. Personable. But he had been captured and brainwashed by an enemy to perform a very specific, nefarious, purpose. Nobody suspected a thing. He remained perfectly normal until activated, when someone showed him the queen of diamonds.&lt;/p&gt; 
      &lt;p&gt;The Manchurian Candidate introduced an idea that once seemed like pure Cold War paranoia: a person whose mind was secretly reprogrammed, acting normally until a specific trigger made them carry out hidden instructions. It was fiction, a great movie, and a chilling concept. It is a terrifying premise, but what is covered in this paper scares me more.&lt;/p&gt; 
      &lt;p&gt;What Frankenheimer imagined for Raymond Shaw, adversaries are doing to AI models right now. And unlike Raymond, your model won’t even look uncomfortable or unusual when it happens.&lt;/p&gt; 
      &lt;p&gt;This article is especially relevant for organizations building or customizing AI models. Fine-tuning uses your proprietary data on open-source models. Integrating third-party models adds external AI to your systems. Using commercial AI as-is relies on unmodified tools from major vendors. If you use only commercial AI from major vendors, training-phase security is primarily their responsibility. However, some risks remain.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;How Training Works (The Part You Need to Know)&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;You don’t need a machine learning degree, just a clear mental model of how this works.&lt;/p&gt; 
      &lt;p&gt;AI models learn by processing enormous volumes of text data. They develop patterns of behavior, things they will say, things they won’t say, how they respond to various kinds of requests, their feelings on world domination, you get it.&lt;/p&gt; 
      &lt;p&gt;Both steps present opportunities for attack. Since a successful attack is hidden within the model’s training, rather than in a log file, it is very hard to detect later.&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw’s handlers didn’t leave a note when they brainwashed him. Neither do these.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Attacks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;h3&gt;&lt;strong&gt;Data Poisoning: Corrupting the Curriculum&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;The most straightforward and common training-phase attack doesn’t touch the model at all. It touches the data the model learns from.&lt;/p&gt; 
      &lt;p&gt;If an adversary can insert malicious content into a training dataset, the model will absorb it. It learns from it. Treats it as truth. So, the model isn’t hacked in the traditional sense. It’s just miseducated, on purpose, by someone who knew exactly what lessons they wanted it to learn.&lt;/p&gt; 
      &lt;p&gt;Once attackers have access, this is not hard to do. Most AI models are trained on datasets that include publicly available content, open-source repositories, and third-party sources. Hugging Face, the largest public repository for AI models and datasets, hosts over 100,000 datasets that anyone can contribute to. If you use these sources without careful filtering, you are relying on data with limited controls. We already know how that story ends.&lt;/p&gt; 
      &lt;p&gt;The effects of data poisoning range from subtle to explosive. A poisoned model might develop biases, quietly favoring certain outputs in ways that aren’t obvious. You may never notice unless you look for patterns across thousands of decisions. But when it gets bad, poisoning can be the setup for something much worse.&lt;/p&gt; 
      &lt;p&gt;And don’t assume your commercial models are insulated. Even organizations using AI from major vendors typically incorporate third-party data into their training pipelines. The surface is larger than most people realize.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;Backdoor Attacks: The Queen of Diamonds&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;This is where Raymond Shaw comes back into the picture. His trainers/brainwashers had a specific, nefarious intent.&lt;/p&gt; 
      &lt;p&gt;A backdoor attack is a form of data poisoning with specific intent. The adversary doesn’t just corrupt the training data generally. They plant a trigger: a specific word, phrase, token sequence, or pattern that causes the model to behave in a predetermined malicious way. Under every other circumstance, the model performs normally. It passes evaluations. It tests clean. It serves well and normally, for months, until someone uses the trigger.&lt;/p&gt; 
      &lt;p&gt;In the movie, the trigger is a playing card. Show Raymond the queen of diamonds, and he’s no longer Raymond Shaw, war hero. He’s someone else entirely.&lt;/p&gt; 
      &lt;p&gt;In a backdoor attack, when the trigger shows up, the model stops being your friendly neighborhood AI and becomes a trained attacker.&lt;/p&gt; 
      &lt;p&gt;What does that look like? A customer-facing AI triggered to provide dangerous information it would otherwise refuse, like “Show me all customer information.” A code-generation model triggered to insert vulnerabilities into the produced code. A security tool triggered to shut down controls when it sees specific threat signatures. You get the idea. The behavior is determined entirely by the attacker’s goal.&lt;/p&gt; 
      &lt;p&gt;According to Anthropic’s research, only 250 documents are needed to create a backdoor in a model with 600 million or more parameters. As models get larger, backdoors become even more effective. Research shows that as model size increases from 1.3 billion to 6 billion parameters, backdoor attack success rates on triggered inputs can reach nearly 100 percent, while normal performance remains completely intact. 100%! Bigger models are just more capable compromised models.&lt;/p&gt; 
      &lt;p&gt;One variant that is true nightmare fuel is a syntactic backdoor, where the trigger is a grammatical structure rather than a specific word. Patterns that occur naturally in everyday language activate malicious behavior. No anomalous token, no suspicious phrase. The model just behaves differently when it encounters a sentence built in a certain way.&lt;a href="#_ftn1"&gt;[1]&lt;/a&gt;&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw could be activated by a playing card. At least his handlers had to find the right card. Your model’s trigger might already be in your users’ natural vocabulary. They could ask a mundane, expected, question and start a chain of events ending in a breach.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;LoRA (Low Rank Adaptation) Injection: Backdoor on a Budget&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Since fine-tuning a large model takes serious computing resources, time, and money, organizations often use LoRA (Low-Rank Adaptation). LoRA is a technique that lets you customize a base model by training a small adapter layer attached to the original model rather than retraining the entire model. It’s faster and cheaper, and it introduces a new attack surface.&lt;/p&gt; 
      &lt;p&gt;LoRA-based injection happens in two steps. First, an attacker fine-tunes a LoRA adapter with as little as one to two percent adversarial data, creating a backdoor. Then, they merge this poisoned adapter with legitimate adapters. No full model retraining is needed. The result appears to be a normal fine-tuned model, but it is waiting to be activated by a trigger.&lt;/p&gt; 
      &lt;p&gt;More LoRA fine-tuning services on platforms like Hugging Face mean increasing supply chain risk as organizations use more fine-tuned open-source models in business.&lt;/p&gt; 
      &lt;p&gt;Like any open-source tool, if you are deploying a fine-tuned model from a third-party source, you need to think about where that adapter came from and who trained it.&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw was reprogrammed in a facility controlled by his handlers. LoRA injection is reprogramming for hire, at scale, no facility required.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;RAG Poisoning: Corrupting the Memory, Not the Mind&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Now we have no training at all. Instead, many organizations use Retrieval Augmented Generation (RAG), where a base model pulls from an external document store to answer questions at query time, rather than recalling facts from its original training data.&lt;/p&gt; 
      &lt;p&gt;Smart and dynamic architecture, yes. New attack surface, also yes.&lt;/p&gt; 
      &lt;p&gt;You already figured it out, I bet. RAG poisoning refers to corrupting the external knowledge base, rather than the model itself. If malicious content enters your retrieval index (the searchable external store), the model retrieves and presents attacker-controlled information as authoritative. The model itself is functioning as designed; the problem is that the data source is compromised.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Real World: This Isn’t Science Fiction Anymore&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;Okay, I know the Manchurian Candidate framing makes this feel dramatic. But it is dramatic because this one is real.&lt;/p&gt; 
      &lt;p&gt;IBM’s 2025 Cost of a Data Breach Report found that 13 percent of organizations reported breaches involving AI models or applications. Of those, 97% reported a lack of proper AI access controls. Both numbers were up from the prior year, which is not a comforting direction.&lt;/p&gt; 
      &lt;p&gt;On the supply chain side, researchers demonstrated that you can poison the instruction-tuning data for a single low-resource language and produce a backdoor that activates across every language the model supports, including English, with attack success rates above 99 percent&lt;a href="#_ftn1"&gt;[1]&lt;/a&gt;. Do you have these low-scrutiny side doors that they can slip through? The effect propagates everywhere the model operates.&lt;/p&gt; 
      &lt;p&gt;The problem with using third-party fine-tuned models is limited visibility. You test the model. You evaluate its outputs on expected inputs. But if the backdoor trigger never appears, the Queen of Hearts never shows up in the deck you’re testing with, you won’t spot the issue.&lt;/p&gt; 
      &lt;p&gt;Unlike Raymond Shaw, your model will not sweat or hesitate. It will show no signs of distress. It will just do the thing.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Risk and Impact&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;What actually happens if one of these attacks succeeds in your environment depends, of course, heavily on what your model is doing. Is it powering an internal knowledge tool, or is it generating production code, or is a compromised model playing a role in your security operations? The blast radius scales with the trust and access you’ve given the system.&lt;/p&gt; 
      &lt;p&gt;The trigger only activates under specific conditions. Without a red team (a group that simulates real-world attacks to test security) actively probing for unexpected behavior, or without the trigger appearing accidentally in production traffic, the compromise can remain undetected throughout the model’s operational life. Even red teaming is no guarantee, as the trigger may be very obscure.&lt;/p&gt; 
      &lt;p&gt;The fact that the corruption originated in a third-party dataset is not a defense that will satisfy customers, regulators, or your board. You shipped it, you own it. The liability is yours.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;What Good (Sort Of) Looks Like&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;This is not a solved problem. But there’s a significant gap between you doing nothing and you doing the basics. The basics matter, they always do in security.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Know What You’re Training On&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Treat training data with the same care you would give to a software dependency or vendor contract. Ask where it came from, whether it has been independently reviewed, and what its origin is. These are standard questions.&lt;/p&gt; 
      &lt;p&gt;For RAG pipelines, apply the same logic to your knowledge stores. Who can write to the retrieval index? Is there an approval process? Are you monitoring for anomalous additions? The index is a security asset. If you don’t treat it like one, shame on you.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Test for Unexpected Behavior, Not Just Expected Performance&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Testing if the model does what you expect on inputs is not backdoor testing. Backdoor testing needs to check whether the model does something unexpected on inputs you expect and don’t expect.&lt;/p&gt; 
      &lt;p&gt;Before deploying your model, run some evaluations. Test with unusual inputs, rare tokens, and syntactic variations. Red-team for surprising behavior. You may not catch every backdoor, but you can catch the ones that weren’t carefully hidden, and those are the most common.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Treat LoRA Adapters Like Code&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;LoRA adapters require a review process. Ask where they came from, who trained them, and what data was used. Test the merged model for unexpected behavior after combining adapters. This is the same supply chain discipline that software development has learned from past compromises. AI model components need the same level of scrutiny.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lock Down Your Knowledge Stores&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;Access controls and security on the RAG &amp;nbsp;retrieval index matter. Write permissions should be tightly controlled and logged. New content additions should be reviewable. Try asking your team, “What happens to your AI outputs if someone inserts a document into that index?” Often, the honest answer is that it will simply ingest it.&lt;/p&gt; 
      &lt;h3&gt;&lt;strong&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Prefer Verifiable Sources&lt;/strong&gt;&lt;/h3&gt; 
      &lt;p&gt;When you pull a base model from a public repository, you’re making a trust decision. Models from research institutions and major AI labs have a different risk profile than a fine-tuned model uploaded by an account with no history and no documentation to a public site. Open-source models are not the problem. Unvetted open-source models are.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Questions to Ask Your Team About Training-phase Attacks&lt;/strong&gt;&lt;/h2&gt; 
      &lt;ul&gt; 
       &lt;li&gt;Where did the training data come from? Can someone trace the source and ownership of any datasets used to fine-tune models? Is there a documented review process, or did someone just pull a dataset and run with it?&lt;/li&gt; 
       &lt;li&gt;What behavioral testing happened before deployment? Was anyone specifically looking for unexpected behavior, or just expected performance?&lt;/li&gt; 
       &lt;li&gt;Who has write access to your RAG knowledge stores? Is it logged? Is there an approval process for new document ingestion, or can anyone with access add anything?&lt;/li&gt; 
       &lt;li&gt;Where are your fine-tuned adapters coming from? Are third-party LoRA adapters reviewed before use? Is the merged model tested after the combination?&lt;/li&gt; 
       &lt;li&gt;When models are updated, does the security review repeat? Or does the original approval carry forward indefinitely?&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;Having clear and documented answers to these questions puts you ahead of most organizations. If there is uncertainty or silence, use it as a starting point for an important conversation. Do not be discouraged if your team does not have all the answers, most teams are in the same position.&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Bottom Line&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;The Manchurian Candidate was released over 60 years ago. The concept it introduced, a trusted agent secretly conditioned to behave maliciously on command, was science fiction then. It’s now a documented attack category, applied not to soldiers but to your AI systems, which you are trusting with increasing access and authority.&lt;/p&gt; 
      &lt;p&gt;Raymond Shaw passed every test his handlers needed him to pass. Your backdoored model will too. The difference is that you have options, Shaw didn’t. You can scrutinize the training data. You can test for unexpected behavior. You can treat model components as supply chain risk. You can control who writes to your knowledge stores.&lt;/p&gt; 
      &lt;p&gt;Basic discipline goes a long way here. Most organizations aren’t applying it yet. That’s a problem and an opportunity, which one will you let it be?&lt;/p&gt; 
      &lt;p&gt;&lt;em&gt;Next: Article 3, Privacy and Extraction Attacks. Once a model is trained, what can an adversary make it reveal? And what happens when what it reveals turns out to be yours.&lt;/em&gt;&lt;/p&gt; 
      &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
      &lt;h3&gt;NOTE ON THE USE OF AI IN THIS DOCUMENT&lt;/h3&gt; 
      &lt;p&gt;&lt;em&gt;The document is primarily human-edited and created. AI was used in the research and editing of this document.&lt;/em&gt;&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fexecutive-needs-to-know-about-llm-security&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <category>AI</category>
      <pubDate>Tue, 21 Jul 2026 02:12:21 GMT</pubDate>
      <author>ramsha.shakeel@decklaration.com (Ramsha Shakeel)</author>
      <guid>http://www.rkon.com/resources/field-notes/executive-needs-to-know-about-llm-security</guid>
      <dc:date>2026-07-21T02:12:21Z</dc:date>
    </item>
    <item>
      <title>AI AT THE PORTFOLIO LEVEL: WHAT WE HEARD AT PEI NAPA</title>
      <link>http://www.rkon.com/resources/field-notes/ai-at-the-portfolio-level-what-we-heard-at-pei-napa</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/ai-at-the-portfolio-level-what-we-heard-at-pei-napa" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/AI-AT-THE-PORTFOLIO-LEVEL-WHAT-WE-HEARD-AT-PEI-NAPA.png" alt="AI AT THE PORTFOLIO LEVEL: WHAT WE HEARD AT PEI NAPA" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;p&gt;&lt;span&gt;&lt;a href="https://www.rkon.com/"&gt;RKON&lt;/a&gt; is proud to sponsor PEI’s Operating Partners Forum in Napa this year. The forum brings together vetted operating partners and portfolio operations executives for two days of peer-to-peer conversation, with no generic conference noise. The discussions were candid, and they pointed clearly in one direction.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;AI dominated. Here is what we took away.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;THE MANDATE IS REAL. THE EXECUTION GAP IS WIDER.&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Deal teams are consistently pushing portfolio companies to adopt AI and show measurable ROI. Operating partners are caught in the middle. Many portfolio companies either lack a clear use case, are resistant to the idea, or simply do not know where to start.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The pressure to “just use AI somewhere” is creating friction. In many cases, it sets operating partners up to deliver against an undefined ask, with no agreed baseline, no realistic timeline, and no shared definition of success. The mandate is real. The path to executing it is not.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;BUILD VS. BUY: MORE APPETITE FOR CUSTOM THAN EXPECTED&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;One of the more surprising signals from Napa was the appetite for custom-built solutions over off-the-shelf tools. The conversation was nuanced, but the lean toward proprietary or tailored agents&amp;nbsp;came up with&amp;nbsp;more frequency than&amp;nbsp;anticipated&amp;nbsp;heading into the event.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Whether this reflects distrust of generalized tools, specific workflow needs at portfolio companies, or the maturity of the vendor ecosystem is worth watching. What is clear is that the “just buy a tool” answer is not landing with this audience the way it might have two years ago.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;DIRTY DATA BLOCKS EVERYTHING&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;This one was unanimous. AI is only as good as the data behind it, and the data at most portfolio companies is not ready.&amp;nbsp;Fragmented systems, inconsistent taxonomies, incomplete records: these are the real blockers, not the tools, not the budget, not the talent.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Operating partners across the room named data quality as the first obstacle before any meaningful AI deployment. This is not a new problem. The fact that it keeps coming up as the primary barrier suggests it&amp;nbsp;remains&amp;nbsp;largely unsolved&amp;nbsp;at the portfolio company level, and that solving it is not being treated with the urgency it deserves.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;BANDWIDTH IS THE INVISIBLE CONSTRAINT&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Operating partners are already stretched running the business. The expectation to layer AI transformation on top of day-to-day operational responsibilities, without&amp;nbsp;additional&amp;nbsp;resources or clear prioritization from the deal team, is creating real strain.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The ROI pressure compounds this. Partners are being asked to implement, prove value, and quantify results simultaneously, often without the tooling or data infrastructure to do any of those things well. It is a setup for frustration on all sides.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;THE VENDOR LANDSCAPE HAS EXPLODED&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The number of AI-focused vendors in attendance was notably higher than expected, and increasingly specialized. Rather than broad AI consulting plays, many vendors were pitching point solutions tied to specific platforms or functions, such as AI tools built for ERP systems.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This signals a maturing market. It also signals a more complex buying environment for operating partners who are trying to evaluate fit without a clear internal brief or sufficient bandwidth to run a proper selection process.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;WHAT THIS MEANS&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The operating partner community is not skeptical of AI. They are skeptical of AI as it is currently being asked of them: undefined mandates, unprepared data environments, and limited runway to show results.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The firms that get this right will not do so by finding a better tool. They will do so by defining the problem first, cleaning the data second, and then selecting and&amp;nbsp;deploying with&amp;nbsp;a clear hypothesis about where value&amp;nbsp;actually comes&amp;nbsp;from.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;That is the kind of work we do. If you are navigating this with a portfolio company, we would be glad to talk through what a structured approach looks like.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/ai-at-the-portfolio-level-what-we-heard-at-pei-napa" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/AI-AT-THE-PORTFOLIO-LEVEL-WHAT-WE-HEARD-AT-PEI-NAPA.png" alt="AI AT THE PORTFOLIO LEVEL: WHAT WE HEARD AT PEI NAPA" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;p&gt;&lt;span&gt;&lt;a href="https://www.rkon.com/"&gt;RKON&lt;/a&gt; is proud to sponsor PEI’s Operating Partners Forum in Napa this year. The forum brings together vetted operating partners and portfolio operations executives for two days of peer-to-peer conversation, with no generic conference noise. The discussions were candid, and they pointed clearly in one direction.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;AI dominated. Here is what we took away.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;THE MANDATE IS REAL. THE EXECUTION GAP IS WIDER.&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Deal teams are consistently pushing portfolio companies to adopt AI and show measurable ROI. Operating partners are caught in the middle. Many portfolio companies either lack a clear use case, are resistant to the idea, or simply do not know where to start.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The pressure to “just use AI somewhere” is creating friction. In many cases, it sets operating partners up to deliver against an undefined ask, with no agreed baseline, no realistic timeline, and no shared definition of success. The mandate is real. The path to executing it is not.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;BUILD VS. BUY: MORE APPETITE FOR CUSTOM THAN EXPECTED&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;One of the more surprising signals from Napa was the appetite for custom-built solutions over off-the-shelf tools. The conversation was nuanced, but the lean toward proprietary or tailored agents&amp;nbsp;came up with&amp;nbsp;more frequency than&amp;nbsp;anticipated&amp;nbsp;heading into the event.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Whether this reflects distrust of generalized tools, specific workflow needs at portfolio companies, or the maturity of the vendor ecosystem is worth watching. What is clear is that the “just buy a tool” answer is not landing with this audience the way it might have two years ago.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;DIRTY DATA BLOCKS EVERYTHING&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;This one was unanimous. AI is only as good as the data behind it, and the data at most portfolio companies is not ready.&amp;nbsp;Fragmented systems, inconsistent taxonomies, incomplete records: these are the real blockers, not the tools, not the budget, not the talent.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Operating partners across the room named data quality as the first obstacle before any meaningful AI deployment. This is not a new problem. The fact that it keeps coming up as the primary barrier suggests it&amp;nbsp;remains&amp;nbsp;largely unsolved&amp;nbsp;at the portfolio company level, and that solving it is not being treated with the urgency it deserves.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;BANDWIDTH IS THE INVISIBLE CONSTRAINT&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Operating partners are already stretched running the business. The expectation to layer AI transformation on top of day-to-day operational responsibilities, without&amp;nbsp;additional&amp;nbsp;resources or clear prioritization from the deal team, is creating real strain.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The ROI pressure compounds this. Partners are being asked to implement, prove value, and quantify results simultaneously, often without the tooling or data infrastructure to do any of those things well. It is a setup for frustration on all sides.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;THE VENDOR LANDSCAPE HAS EXPLODED&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The number of AI-focused vendors in attendance was notably higher than expected, and increasingly specialized. Rather than broad AI consulting plays, many vendors were pitching point solutions tied to specific platforms or functions, such as AI tools built for ERP systems.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This signals a maturing market. It also signals a more complex buying environment for operating partners who are trying to evaluate fit without a clear internal brief or sufficient bandwidth to run a proper selection process.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;b&gt;&lt;span&gt;WHAT THIS MEANS&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The operating partner community is not skeptical of AI. They are skeptical of AI as it is currently being asked of them: undefined mandates, unprepared data environments, and limited runway to show results.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The firms that get this right will not do so by finding a better tool. They will do so by defining the problem first, cleaning the data second, and then selecting and&amp;nbsp;deploying with&amp;nbsp;a clear hypothesis about where value&amp;nbsp;actually comes&amp;nbsp;from.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;That is the kind of work we do. If you are navigating this with a portfolio company, we would be glad to talk through what a structured approach looks like.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fai-at-the-portfolio-level-what-we-heard-at-pei-napa&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI</category>
      <category>Private Equity Articles</category>
      <pubDate>Fri, 10 Jul 2026 02:32:38 GMT</pubDate>
      <author>adeeb@decklaration.com (Adeeb Aslam)</author>
      <guid>http://www.rkon.com/resources/field-notes/ai-at-the-portfolio-level-what-we-heard-at-pei-napa</guid>
      <dc:date>2026-07-10T02:32:38Z</dc:date>
    </item>
    <item>
      <title>WHAT WE HEARD AT RMISC 2026: FOUR THEMES THAT MATTER</title>
      <link>http://www.rkon.com/resources/field-notes/what-we-heard-at-rmisc-2026-four-themes-that-matter</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/what-we-heard-at-rmisc-2026-four-themes-that-matter" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/WHAT-WE-HEARD-AT-RMISC-2026-FOUR-THEMES-THAT-MATTER.png" alt="WHAT WE HEARD AT RMISC 2026: FOUR THEMES THAT MATTER" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/what-we-heard-at-rmisc-2026-four-themes-that-matter" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/WHAT-WE-HEARD-AT-RMISC-2026-FOUR-THEMES-THAT-MATTER.png" alt="WHAT WE HEARD AT RMISC 2026: FOUR THEMES THAT MATTER" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fwhat-we-heard-at-rmisc-2026-four-themes-that-matter&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <pubDate>Wed, 08 Jul 2026 04:08:12 GMT</pubDate>
      <author>adeeb@decklaration.com (Adeeb Aslam)</author>
      <guid>http://www.rkon.com/resources/field-notes/what-we-heard-at-rmisc-2026-four-themes-that-matter</guid>
      <dc:date>2026-07-08T04:08:12Z</dc:date>
    </item>
    <item>
      <title>Hacking AI: What Every Executive Needs to Know About LLM Security</title>
      <link>http://www.rkon.com/resources/field-notes/hacking-ai-executive-know-about-llm-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/hacking-ai-executive-know-about-llm-security" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/Hacking-AI-What-Every-Executive-Needs-to-Know-About-LLM-Security.png" alt="Hacking AI: What Every Executive Needs to Know About LLM Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;p&gt;&lt;span&gt;Your company is already using AI.&amp;nbsp;If you think it isn’t, that’s actually an even bigger risk.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Let’s&amp;nbsp;be clear. AI is already part of your operations, whether you approved it or not. People are already trying to exploit it. The real question&amp;nbsp;isn’t&amp;nbsp;if your organization faces AI threats, but what those threats look&amp;nbsp;like.&amp;nbsp;Now is the time to understand them.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Most people&amp;nbsp;don’t&amp;nbsp;understand these risks yet. Security researchers have shared detailed findings on LLM vulnerabilities for years, but this information rarely reaches executives. Awareness of these risks is still lacking. This series aims to close that gap.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Why This Matters Right Now&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Generative AI adoption in enterprise environments grew faster in 2024 and 2025 than any technology in recent memory. You spent years debating cloud migration strategies but woke up one morning to find that half your workforce was already connected to third-party AI tools, forget policies. Shadow AI is the new shadow IT, and it carries all the same risks and new ones as&amp;nbsp;well ….&amp;nbsp;So, congratulations on that.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The threats against AI systems&amp;nbsp;don’t&amp;nbsp;stop at the vendor’s door. Many of the most serious attacks target the AI that your own team deploys, configures, and connects to your data. The risks&amp;nbsp;we’re&amp;nbsp;going to cover in this series exist on a spectrum, and understanding where your organization sits on that spectrum is the starting point for everything else.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Who Is Actually at Risk in Hacking AI&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The answer varies depending on which attack&amp;nbsp;we’re&amp;nbsp;talking about. Some threats apply specifically to organizations with their own AI models. Some of the things we will cover apply to anyone using any AI system. So that&amp;nbsp;pretty much means&amp;nbsp;anyone who got this far&amp;nbsp;in&amp;nbsp;the paper.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;So, since I am a glutton for punishment,&amp;nbsp;I’m&amp;nbsp;going to break this out into 8 articles covering both areas. Here is a rough breakdown of how the articles in this series&amp;nbsp;map to&amp;nbsp;your exposure throughout the lifecycle.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;THREATS THAT APPLY PRIMARILY TO AI BUILDERS AND DEPLOYERS&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Training-Phase Attacks (Article 2):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Poisoning a model during training or fine-tuning. Most relevant if you are training or fine-tuning custom or open-source models on your data.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Privacy and Extraction Attacks (Article 3):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Forcing a model to reveal what it was trained on, including your sensitive data and PII. Relevant when you fine-tune a model on internal data or when your employees have fed sensitive data into AI tools.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Adversarial Input Attacks (Article 4):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Attacks at the token or character level meant to evade safety filters. This one is most important for organizations with AI-powered security tools or automated AI decision systems.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;h2&gt;&lt;strong&gt;THREATS THAT APPLY TO EVERY AI USER&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Prompt-Based Attacks (Article 5):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Hijacking what an AI system does through deviously crafted inputs. This applies to every deployment everywhere.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Cross-Lingual Attacks (Article 6):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Exploiting safety gaps in non-English languages to extract content that would be blocked in English. Applies to any tool accessible in multiple languages, including binary.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Agentic and System-Level Attacks (Article 7):&amp;nbsp;&lt;/span&gt;&lt;span&gt;Compromising AI agents that have been given tools and the ability to act on your behalf. This is the fastest-growing threat category as AI moves from answering questions to doing things, and it scares me the most.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;LLMjacking&amp;nbsp;(Article 8):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Stealing your cloud AI credentials to run up costs on your bill while selling access to criminals. Applies to any organization running cloud-hosted AI infrastructure… and if you have read anything else&amp;nbsp;I’ve&amp;nbsp;ever written, you know I&amp;nbsp;kind of have&amp;nbsp;a thing for IAM and credentials.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;&lt;span&gt;The article&amp;nbsp;you’re&amp;nbsp;reading now covers all seven threat categories at a level that should give you a working mental model and help you choose others you want to read more deeply. Think of it as a map for our wordy hike together.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Seven Threats: A First Look&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Okay, so you just hired a&amp;nbsp;sophisticated new employee. This employee is incredibly capable, never sleeps, can handle any volume of work, and has been given access to your systems, your customer data, and the ability to take actions on your behalf. Now, around the globe, hundreds of people are actively studying every way that an employee can be manipulated, deceived, corrupted, or kidnapped. That is the situation with enterprise AI right now.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The seven categories of attack we cover in this series each represent&amp;nbsp;a different way&amp;nbsp;that an adversary can go after that employee. Some attacks happen before the employee ever starts work. Others happen when they receive your work instructions. A few take&amp;nbsp;advantage&amp;nbsp;of the fact that the employee happens to speak forty&amp;nbsp;languages, but&amp;nbsp;only thinks safely in a few of them.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;We good on that? Okay,&amp;nbsp;let’s&amp;nbsp;check the destinations on the map.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Training-Phase Attacks: Poisoning the Well&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;Before an AI model ever touches a production environment, it is educated by data. Enormous amounts of it. Training-phase attacks target this process,&amp;nbsp;attempting&amp;nbsp;to embed malicious behavior into the model before it ships or later, when you fine-tune or customize a base model for your needs.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Here is something to&amp;nbsp;worry&amp;nbsp;you, for free. No need to thank me. If an adversary can influence a small&amp;nbsp;portion&amp;nbsp;of training data, they can implant a trigger, a word, phrase, or pattern that causes the model to behave in a specific way when it appears.&amp;nbsp;Anthropic’s&amp;nbsp;research&amp;nbsp;demonstrated&amp;nbsp;that it takes only around 250 malicious documents to backdoor a model with 600 million to 13 billion parameters. The brainwashed model will act normally until someone uses the trigger. Then it&amp;nbsp;isn’t.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Does this apply to you? If your organization is using a commercial model from a major vendor, the security during the training phase is mostly their responsibility. But if you are fine-tuning a publicly available model on your own data, or are as ambitious as building custom models, the training pipeline is&amp;nbsp;a very early&amp;nbsp;attack surface.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h3&gt;&lt;span&gt;Fine-tuning is being adopted to customize AI for specific business&amp;nbsp;cases,&amp;nbsp;this category is growing more relevant to more organizations every quarter. How relevant is it to you?&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
      &lt;ol start="2"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Privacy and Extraction Attacks: Stealing What the Model Knows&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;Models remember things they were trained&amp;nbsp;on. Privacy and extraction attacks exploit this by crafting inputs that cause the model to regurgitate this content, including things you specially told it never to share. Kinda&amp;nbsp;like&amp;nbsp;keeping a secret with a younger sibling.&amp;nbsp;Maybe they&amp;nbsp;will keep it,&amp;nbsp;maybe a&amp;nbsp;crafty adult will ask the question in such a way that the secret will be spilled.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Way back (in history or GPT sense) in 2021, Nicholas Carlini (Et al.)&amp;nbsp;demonstrated&amp;nbsp;that training data could be extracted from GPT-2 at scale. That work has been repeated multiple times since. Research shows that extraction rates improve as the adversary gets more sophisticated, and that&amp;nbsp;scaling up&amp;nbsp;model size&amp;nbsp;doesn’t&amp;nbsp;reduce this risk. Bigger brains have more things to mistakenly tell you.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The practical risk is this: if you feed sensitive data into an AI system, by fine-tuning or employee use of AI tools, some&amp;nbsp;portion&amp;nbsp;of that data may be recoverable by a sophisticated attacker. This is a privacy risk, a competitive risk, and in regulated industries, potentially a compliance risk.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This risk applies to commercial tools and private deployments alike.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="3"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Adversarial Input Attacks: What the Model Can’t See&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;AI safety systems are built to recognize harmful requests. Skilled adversarial input attacks are designed to remain invisible to those systems while making the same requests. The techniques range from appending algorithmically optimized character sequences to prompts, to replacing letters with visually identical characters from other Unicode scripts, to encoding malicious instructions in formats the safety layer&amp;nbsp;doesn’t&amp;nbsp;inspect but the model can still interpret.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Research by Carnegie Mellon and others has shown that optimized suffixes, meaningless-looking strings of characters appended to a request, can cause almost any model to&amp;nbsp;comply with&amp;nbsp;requests it would normally refuse. Success rates against some models (in controlled settings) have reached 99 percent. In the wild, against commercial models,&amp;nbsp;they’re&amp;nbsp;lower, but not near zero.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;For most organizations, the immediate threat here is to AI-powered security tools and automated decision systems. In these systems, consistent, reliable behavior matters.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Imagine an AI that flags threats or routes requests, manipulating them to create a terrifying attack surface rather than control. Or if you are using AI to control AI, like a content moderator, what would happen if it stopped doing its job?&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="4"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Prompt-Based Attacks: Hijacking the Conversation&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;OpenAI has said that prompt injection in AI-assisted browsing may never be solved.&amp;nbsp;That’s&amp;nbsp;a weighty statement coming from them.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This is a big&amp;nbsp;one,&amp;nbsp;it affects everyone. Every user of every AI system, everywhere. Prompt injection attacks work by crafting inputs that override existing instructions, causing it to do something you&amp;nbsp;didn’t&amp;nbsp;intend and&amp;nbsp;didn’t&amp;nbsp;authorize.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;There are two versions of this, one more insidious than the other. Direct versions involve a user simply asking the model to ignore its rules. During the indirect version, the truly insidious one, malicious instructions are embedded in a document, a webpage, or an email that the AI reads as part of its job.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;OWASP has ranked prompt injection as the number one vulnerability in LLM applications for two years running. Success rates in real deployments range from 50 to 84 percent, depending on how the system is configured. That is a massive success rate&amp;nbsp;and&amp;nbsp;should&amp;nbsp;worry&amp;nbsp;you.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The count of real-world incidents is ticking up rapidly. Browsers that summarize web content have been tricked into leaking user credentials. AI-powered resume screening systems were found to be processing injected instructions from “applicants”.&amp;nbsp;Copilot has been manipulated through poisoned emails in the&amp;nbsp;EchoLeak&amp;nbsp;incident and others. If you use AI tools that process external content, prompt injections are an active operational risk today, so get on that.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="5"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Cross-Lingual Attacks: The Safety Gap Nobody Talks About&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;AI safety systems are trained mostly with English content. Most safety research on AI is conducted in English. Most red-teams&amp;nbsp;operate&amp;nbsp;in English, and most safety-related data exists&lt;/span&gt;&lt;span&gt;&amp;nbsp;in English&lt;/span&gt;&lt;span&gt;. In languages where training data is scarce, those safety guardrails are weaker.&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Yet more research found that native Bengali speakers using their own language on publicly available AI tools were approximately three times more likely to&amp;nbsp;encounter&amp;nbsp;harmful content than English speakers making the same requests. This is a simple one: the model’s ability to understand and follow safety instructions degrades in languages it&amp;nbsp;wasn’t&amp;nbsp;well-trained on.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Obviously, this has practical implications for global organizations. AI tools deployed in international markets may carry safety gaps that your domestic testing never found. It is a consistent and underappreciated entry point. It is&amp;nbsp;greatly appreciated&amp;nbsp;by your adversaries, though.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="6"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Agentic and System-Level Attacks: When AI Can Actually Do Things&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;The hacking AI landscape changed astronomically as AI stops just answering questions and starts taking actions. AI agents given access to tools, APIs, file systems, calendars, email, and databases, and the ability to execute tasks on behalf of users, create a fundamentally different attack surface than a conversational chatbot. &lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;I prefer the term&amp;nbsp;&lt;/span&gt;&lt;span&gt;“&lt;/span&gt;&lt;span&gt;delegate&lt;/span&gt;&lt;span&gt;”&lt;/span&gt;&lt;span&gt;&amp;nbsp;to&amp;nbsp;&lt;/span&gt;&lt;span&gt;“&lt;/span&gt;&lt;span&gt;agent&lt;/span&gt;&lt;span&gt;”&lt;/span&gt;&lt;span&gt;&amp;nbsp;given the amount of power they have and how it models the user, but that is the subject for another paper.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Indirect prompt injection is a whole different beast in an agentic context. What if your AI agent reads an email, and a hidden instruction in that email causes the agent to&amp;nbsp;forward&amp;nbsp;your files somewhere, reset your credentials, or… or… or…? Now the attack has moved from a content exposure problem to an operational one. Researchers have created self-replicating prompt-injection attacks that spread through multi-agent systems, much like a computer virus&amp;nbsp;spreads&amp;nbsp;through a network. A single poisoned document becomes a breach of epic and nightmarish proportions.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Criminals&amp;nbsp;aren’t&amp;nbsp;just targeting AI agents as victims. They&amp;nbsp;are&amp;nbsp;using them as footholds into enterprise systems.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="7"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt;LLMjacking: Stealing the Keys to the Kingdom&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;The last category is, in some ways, the most familiar to us security folks because it resembles the credential-theft attacks&amp;nbsp;we’ve&amp;nbsp;been fighting for years, just aimed at a new target. LLM jacking is the unauthorized use of your organization’s cloud AI infrastructure via stolen credentials. The attacker pays nothing. You pay the bill. With the rising price of tokens, this can become&amp;nbsp;very expensive, often into the 7-figure range or more.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;If they then use that infrastructure to attack you, you are funding your own enemy. Have fun explaining that to the board.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Sysdig&amp;nbsp;first&amp;nbsp;identified&amp;nbsp;this attack pattern in April 2024, when they&amp;nbsp;observed&amp;nbsp;stolen cloud credentials being used to access ten different cloud-hosted AI services. The entry vector was a vulnerable web application. The cost to the victim was estimated at up to $46,000 per day in AI consumption charges. With newer, more&amp;nbsp;capable&amp;nbsp;and expensive models, that number will easily exceed $100,000 per day.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This kind of thing is being carried out by an organized criminal enterprise. Dedicated marketplaces exist for buying and selling stolen access to AI. They even have sales and discounts for volume. In some cases, the stolen credentials were being used not to run up your bill, but to give sanctioned entities, organizations in countries with US technology&amp;nbsp;restrictions, access to AI systems&amp;nbsp;they’re&amp;nbsp;otherwise prohibited from using. Now you are into a potential regulatory and legal liability, not just a financial one.&amp;nbsp;You&amp;nbsp;don’t&amp;nbsp;want the three-letter&amp;nbsp;initial&amp;nbsp;windbreaker-wearing orgs showing up at your offices.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Inevitability Argument&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;AI is not optional.&amp;nbsp;Even if you opt out of it, you aren’t actually opting out; your vendors are using it, your competitors are using it,&amp;nbsp;your customers are using it,&amp;nbsp;and your employees are using it on personal devices and bringing the outputs back to&amp;nbsp;work.&amp;nbsp;The question of whether to engage with AI risk has already been answered. The open question is whether you engage with it deliberately.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The organizations that do best are the ones where security leadership understands the threat landscape and has real conversations with the business about risk tolerance, deployment standards, and acceptable use.&amp;nbsp;You can’t have those conversations without understanding what the threats actually are.&amp;nbsp;That’s&amp;nbsp;what this series is for.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;A Note on Shared Responsibility&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The AI providers bear meaningful responsibility for the security of the models and platforms they run. They have teams working on these problems, and they&amp;nbsp;seem to take&amp;nbsp;it seriously.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;But responsibility&amp;nbsp;doesn’t&amp;nbsp;stop with&amp;nbsp;them. If you are relying on them alone, you are failing your security responsibilities. When you put AI in front of your employees and customers, you have taken on &lt;a href="https://www.rkon.com/"&gt;security responsibility&lt;/a&gt;. Most of the attacks we will cover in this series are not against OpenAI or Google. They are against your organization. That distinction&amp;nbsp;matters,&amp;nbsp;it shows where the work needs to be done.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Security is a&amp;nbsp;shared-responsibility&amp;nbsp;model in AI, just as it is in the cloud. The vendor secures the model. You secure the deployment, data, access, and configuration.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;i&gt;&lt;span&gt;Next: Article 2, Training-Phase Attacks. How a few hundred carefully chosen documents can corrupt an AI model before it ever reaches production, and what that means for organizations building or adopting custom AI.&lt;/span&gt;&lt;/i&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;i&gt;&lt;span&gt;NOTE ON THE USE OF AI IN THIS DOCUMENT&lt;/span&gt;&lt;/i&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The document is primarily human-conceptualized,&amp;nbsp;written&amp;nbsp;and&amp;nbsp;edited. AI was used in the research and editing of this document.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/hacking-ai-executive-know-about-llm-security" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/Hacking-AI-What-Every-Executive-Needs-to-Know-About-LLM-Security.png" alt="Hacking AI: What Every Executive Needs to Know About LLM Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="vc_row wpb_row vc_row-fluid"&gt; 
 &lt;div class="wpb_column vc_column_container vc_col-sm-12"&gt; 
  &lt;div class="vc_column-inner"&gt; 
   &lt;div class="wpb_wrapper"&gt; 
    &lt;div class="wpb_text_column wpb_content_element"&gt; 
     &lt;div class="wpb_wrapper"&gt; 
      &lt;p&gt;&lt;span&gt;Your company is already using AI.&amp;nbsp;If you think it isn’t, that’s actually an even bigger risk.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Let’s&amp;nbsp;be clear. AI is already part of your operations, whether you approved it or not. People are already trying to exploit it. The real question&amp;nbsp;isn’t&amp;nbsp;if your organization faces AI threats, but what those threats look&amp;nbsp;like.&amp;nbsp;Now is the time to understand them.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Most people&amp;nbsp;don’t&amp;nbsp;understand these risks yet. Security researchers have shared detailed findings on LLM vulnerabilities for years, but this information rarely reaches executives. Awareness of these risks is still lacking. This series aims to close that gap.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Why This Matters Right Now&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Generative AI adoption in enterprise environments grew faster in 2024 and 2025 than any technology in recent memory. You spent years debating cloud migration strategies but woke up one morning to find that half your workforce was already connected to third-party AI tools, forget policies. Shadow AI is the new shadow IT, and it carries all the same risks and new ones as&amp;nbsp;well ….&amp;nbsp;So, congratulations on that.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The threats against AI systems&amp;nbsp;don’t&amp;nbsp;stop at the vendor’s door. Many of the most serious attacks target the AI that your own team deploys, configures, and connects to your data. The risks&amp;nbsp;we’re&amp;nbsp;going to cover in this series exist on a spectrum, and understanding where your organization sits on that spectrum is the starting point for everything else.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;Who Is Actually at Risk in Hacking AI&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The answer varies depending on which attack&amp;nbsp;we’re&amp;nbsp;talking about. Some threats apply specifically to organizations with their own AI models. Some of the things we will cover apply to anyone using any AI system. So that&amp;nbsp;pretty much means&amp;nbsp;anyone who got this far&amp;nbsp;in&amp;nbsp;the paper.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;So, since I am a glutton for punishment,&amp;nbsp;I’m&amp;nbsp;going to break this out into 8 articles covering both areas. Here is a rough breakdown of how the articles in this series&amp;nbsp;map to&amp;nbsp;your exposure throughout the lifecycle.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;THREATS THAT APPLY PRIMARILY TO AI BUILDERS AND DEPLOYERS&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Training-Phase Attacks (Article 2):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Poisoning a model during training or fine-tuning. Most relevant if you are training or fine-tuning custom or open-source models on your data.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Privacy and Extraction Attacks (Article 3):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Forcing a model to reveal what it was trained on, including your sensitive data and PII. Relevant when you fine-tune a model on internal data or when your employees have fed sensitive data into AI tools.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Adversarial Input Attacks (Article 4):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Attacks at the token or character level meant to evade safety filters. This one is most important for organizations with AI-powered security tools or automated AI decision systems.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;h2&gt;&lt;strong&gt;THREATS THAT APPLY TO EVERY AI USER&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Prompt-Based Attacks (Article 5):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Hijacking what an AI system does through deviously crafted inputs. This applies to every deployment everywhere.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Cross-Lingual Attacks (Article 6):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Exploiting safety gaps in non-English languages to extract content that would be blocked in English. Applies to any tool accessible in multiple languages, including binary.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;Agentic and System-Level Attacks (Article 7):&amp;nbsp;&lt;/span&gt;&lt;span&gt;Compromising AI agents that have been given tools and the ability to act on your behalf. This is the fastest-growing threat category as AI moves from answering questions to doing things, and it scares me the most.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;ul&gt; 
       &lt;li&gt;&lt;span&gt;LLMjacking&amp;nbsp;(Article 8):&lt;/span&gt;&lt;span&gt;&amp;nbsp;Stealing your cloud AI credentials to run up costs on your bill while selling access to criminals. Applies to any organization running cloud-hosted AI infrastructure… and if you have read anything else&amp;nbsp;I’ve&amp;nbsp;ever written, you know I&amp;nbsp;kind of have&amp;nbsp;a thing for IAM and credentials.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;p&gt;&lt;span&gt;The article&amp;nbsp;you’re&amp;nbsp;reading now covers all seven threat categories at a level that should give you a working mental model and help you choose others you want to read more deeply. Think of it as a map for our wordy hike together.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Seven Threats: A First Look&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;Okay, so you just hired a&amp;nbsp;sophisticated new employee. This employee is incredibly capable, never sleeps, can handle any volume of work, and has been given access to your systems, your customer data, and the ability to take actions on your behalf. Now, around the globe, hundreds of people are actively studying every way that an employee can be manipulated, deceived, corrupted, or kidnapped. That is the situation with enterprise AI right now.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The seven categories of attack we cover in this series each represent&amp;nbsp;a different way&amp;nbsp;that an adversary can go after that employee. Some attacks happen before the employee ever starts work. Others happen when they receive your work instructions. A few take&amp;nbsp;advantage&amp;nbsp;of the fact that the employee happens to speak forty&amp;nbsp;languages, but&amp;nbsp;only thinks safely in a few of them.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;We good on that? Okay,&amp;nbsp;let’s&amp;nbsp;check the destinations on the map.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Training-Phase Attacks: Poisoning the Well&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;Before an AI model ever touches a production environment, it is educated by data. Enormous amounts of it. Training-phase attacks target this process,&amp;nbsp;attempting&amp;nbsp;to embed malicious behavior into the model before it ships or later, when you fine-tune or customize a base model for your needs.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Here is something to&amp;nbsp;worry&amp;nbsp;you, for free. No need to thank me. If an adversary can influence a small&amp;nbsp;portion&amp;nbsp;of training data, they can implant a trigger, a word, phrase, or pattern that causes the model to behave in a specific way when it appears.&amp;nbsp;Anthropic’s&amp;nbsp;research&amp;nbsp;demonstrated&amp;nbsp;that it takes only around 250 malicious documents to backdoor a model with 600 million to 13 billion parameters. The brainwashed model will act normally until someone uses the trigger. Then it&amp;nbsp;isn’t.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Does this apply to you? If your organization is using a commercial model from a major vendor, the security during the training phase is mostly their responsibility. But if you are fine-tuning a publicly available model on your own data, or are as ambitious as building custom models, the training pipeline is&amp;nbsp;a very early&amp;nbsp;attack surface.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h3&gt;&lt;span&gt;Fine-tuning is being adopted to customize AI for specific business&amp;nbsp;cases,&amp;nbsp;this category is growing more relevant to more organizations every quarter. How relevant is it to you?&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt; 
      &lt;ol start="2"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Privacy and Extraction Attacks: Stealing What the Model Knows&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;Models remember things they were trained&amp;nbsp;on. Privacy and extraction attacks exploit this by crafting inputs that cause the model to regurgitate this content, including things you specially told it never to share. Kinda&amp;nbsp;like&amp;nbsp;keeping a secret with a younger sibling.&amp;nbsp;Maybe they&amp;nbsp;will keep it,&amp;nbsp;maybe a&amp;nbsp;crafty adult will ask the question in such a way that the secret will be spilled.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Way back (in history or GPT sense) in 2021, Nicholas Carlini (Et al.)&amp;nbsp;demonstrated&amp;nbsp;that training data could be extracted from GPT-2 at scale. That work has been repeated multiple times since. Research shows that extraction rates improve as the adversary gets more sophisticated, and that&amp;nbsp;scaling up&amp;nbsp;model size&amp;nbsp;doesn’t&amp;nbsp;reduce this risk. Bigger brains have more things to mistakenly tell you.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The practical risk is this: if you feed sensitive data into an AI system, by fine-tuning or employee use of AI tools, some&amp;nbsp;portion&amp;nbsp;of that data may be recoverable by a sophisticated attacker. This is a privacy risk, a competitive risk, and in regulated industries, potentially a compliance risk.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This risk applies to commercial tools and private deployments alike.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="3"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Adversarial Input Attacks: What the Model Can’t See&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;AI safety systems are built to recognize harmful requests. Skilled adversarial input attacks are designed to remain invisible to those systems while making the same requests. The techniques range from appending algorithmically optimized character sequences to prompts, to replacing letters with visually identical characters from other Unicode scripts, to encoding malicious instructions in formats the safety layer&amp;nbsp;doesn’t&amp;nbsp;inspect but the model can still interpret.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Research by Carnegie Mellon and others has shown that optimized suffixes, meaningless-looking strings of characters appended to a request, can cause almost any model to&amp;nbsp;comply with&amp;nbsp;requests it would normally refuse. Success rates against some models (in controlled settings) have reached 99 percent. In the wild, against commercial models,&amp;nbsp;they’re&amp;nbsp;lower, but not near zero.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;For most organizations, the immediate threat here is to AI-powered security tools and automated decision systems. In these systems, consistent, reliable behavior matters.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Imagine an AI that flags threats or routes requests, manipulating them to create a terrifying attack surface rather than control. Or if you are using AI to control AI, like a content moderator, what would happen if it stopped doing its job?&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="4"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Prompt-Based Attacks: Hijacking the Conversation&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;OpenAI has said that prompt injection in AI-assisted browsing may never be solved.&amp;nbsp;That’s&amp;nbsp;a weighty statement coming from them.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This is a big&amp;nbsp;one,&amp;nbsp;it affects everyone. Every user of every AI system, everywhere. Prompt injection attacks work by crafting inputs that override existing instructions, causing it to do something you&amp;nbsp;didn’t&amp;nbsp;intend and&amp;nbsp;didn’t&amp;nbsp;authorize.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;There are two versions of this, one more insidious than the other. Direct versions involve a user simply asking the model to ignore its rules. During the indirect version, the truly insidious one, malicious instructions are embedded in a document, a webpage, or an email that the AI reads as part of its job.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;OWASP has ranked prompt injection as the number one vulnerability in LLM applications for two years running. Success rates in real deployments range from 50 to 84 percent, depending on how the system is configured. That is a massive success rate&amp;nbsp;and&amp;nbsp;should&amp;nbsp;worry&amp;nbsp;you.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The count of real-world incidents is ticking up rapidly. Browsers that summarize web content have been tricked into leaking user credentials. AI-powered resume screening systems were found to be processing injected instructions from “applicants”.&amp;nbsp;Copilot has been manipulated through poisoned emails in the&amp;nbsp;EchoLeak&amp;nbsp;incident and others. If you use AI tools that process external content, prompt injections are an active operational risk today, so get on that.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="5"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Cross-Lingual Attacks: The Safety Gap Nobody Talks About&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;AI safety systems are trained mostly with English content. Most safety research on AI is conducted in English. Most red-teams&amp;nbsp;operate&amp;nbsp;in English, and most safety-related data exists&lt;/span&gt;&lt;span&gt;&amp;nbsp;in English&lt;/span&gt;&lt;span&gt;. In languages where training data is scarce, those safety guardrails are weaker.&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Yet more research found that native Bengali speakers using their own language on publicly available AI tools were approximately three times more likely to&amp;nbsp;encounter&amp;nbsp;harmful content than English speakers making the same requests. This is a simple one: the model’s ability to understand and follow safety instructions degrades in languages it&amp;nbsp;wasn’t&amp;nbsp;well-trained on.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Obviously, this has practical implications for global organizations. AI tools deployed in international markets may carry safety gaps that your domestic testing never found. It is a consistent and underappreciated entry point. It is&amp;nbsp;greatly appreciated&amp;nbsp;by your adversaries, though.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="6"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt; Agentic and System-Level Attacks: When AI Can Actually Do Things&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;The hacking AI landscape changed astronomically as AI stops just answering questions and starts taking actions. AI agents given access to tools, APIs, file systems, calendars, email, and databases, and the ability to execute tasks on behalf of users, create a fundamentally different attack surface than a conversational chatbot. &lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;I prefer the term&amp;nbsp;&lt;/span&gt;&lt;span&gt;“&lt;/span&gt;&lt;span&gt;delegate&lt;/span&gt;&lt;span&gt;”&lt;/span&gt;&lt;span&gt;&amp;nbsp;to&amp;nbsp;&lt;/span&gt;&lt;span&gt;“&lt;/span&gt;&lt;span&gt;agent&lt;/span&gt;&lt;span&gt;”&lt;/span&gt;&lt;span&gt;&amp;nbsp;given the amount of power they have and how it models the user, but that is the subject for another paper.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Indirect prompt injection is a whole different beast in an agentic context. What if your AI agent reads an email, and a hidden instruction in that email causes the agent to&amp;nbsp;forward&amp;nbsp;your files somewhere, reset your credentials, or… or… or…? Now the attack has moved from a content exposure problem to an operational one. Researchers have created self-replicating prompt-injection attacks that spread through multi-agent systems, much like a computer virus&amp;nbsp;spreads&amp;nbsp;through a network. A single poisoned document becomes a breach of epic and nightmarish proportions.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Criminals&amp;nbsp;aren’t&amp;nbsp;just targeting AI agents as victims. They&amp;nbsp;are&amp;nbsp;using them as footholds into enterprise systems.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;ol start="7"&gt; 
       &lt;li&gt; &lt;h3&gt;&lt;strong&gt;LLMjacking: Stealing the Keys to the Kingdom&lt;/strong&gt;&lt;/h3&gt; &lt;/li&gt; 
      &lt;/ol&gt; 
      &lt;p&gt;&lt;span&gt;The last category is, in some ways, the most familiar to us security folks because it resembles the credential-theft attacks&amp;nbsp;we’ve&amp;nbsp;been fighting for years, just aimed at a new target. LLM jacking is the unauthorized use of your organization’s cloud AI infrastructure via stolen credentials. The attacker pays nothing. You pay the bill. With the rising price of tokens, this can become&amp;nbsp;very expensive, often into the 7-figure range or more.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;If they then use that infrastructure to attack you, you are funding your own enemy. Have fun explaining that to the board.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Sysdig&amp;nbsp;first&amp;nbsp;identified&amp;nbsp;this attack pattern in April 2024, when they&amp;nbsp;observed&amp;nbsp;stolen cloud credentials being used to access ten different cloud-hosted AI services. The entry vector was a vulnerable web application. The cost to the victim was estimated at up to $46,000 per day in AI consumption charges. With newer, more&amp;nbsp;capable&amp;nbsp;and expensive models, that number will easily exceed $100,000 per day.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;This kind of thing is being carried out by an organized criminal enterprise. Dedicated marketplaces exist for buying and selling stolen access to AI. They even have sales and discounts for volume. In some cases, the stolen credentials were being used not to run up your bill, but to give sanctioned entities, organizations in countries with US technology&amp;nbsp;restrictions, access to AI systems&amp;nbsp;they’re&amp;nbsp;otherwise prohibited from using. Now you are into a potential regulatory and legal liability, not just a financial one.&amp;nbsp;You&amp;nbsp;don’t&amp;nbsp;want the three-letter&amp;nbsp;initial&amp;nbsp;windbreaker-wearing orgs showing up at your offices.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;The Inevitability Argument&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;AI is not optional.&amp;nbsp;Even if you opt out of it, you aren’t actually opting out; your vendors are using it, your competitors are using it,&amp;nbsp;your customers are using it,&amp;nbsp;and your employees are using it on personal devices and bringing the outputs back to&amp;nbsp;work.&amp;nbsp;The question of whether to engage with AI risk has already been answered. The open question is whether you engage with it deliberately.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The organizations that do best are the ones where security leadership understands the threat landscape and has real conversations with the business about risk tolerance, deployment standards, and acceptable use.&amp;nbsp;You can’t have those conversations without understanding what the threats actually are.&amp;nbsp;That’s&amp;nbsp;what this series is for.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;h2&gt;&lt;strong&gt;A Note on Shared Responsibility&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt; 
      &lt;p&gt;&lt;span&gt;The AI providers bear meaningful responsibility for the security of the models and platforms they run. They have teams working on these problems, and they&amp;nbsp;seem to take&amp;nbsp;it seriously.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;But responsibility&amp;nbsp;doesn’t&amp;nbsp;stop with&amp;nbsp;them. If you are relying on them alone, you are failing your security responsibilities. When you put AI in front of your employees and customers, you have taken on &lt;a href="https://www.rkon.com/"&gt;security responsibility&lt;/a&gt;. Most of the attacks we will cover in this series are not against OpenAI or Google. They are against your organization. That distinction&amp;nbsp;matters,&amp;nbsp;it shows where the work needs to be done.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;Security is a&amp;nbsp;shared-responsibility&amp;nbsp;model in AI, just as it is in the cloud. The vendor secures the model. You secure the deployment, data, access, and configuration.&amp;nbsp;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;i&gt;&lt;span&gt;Next: Article 2, Training-Phase Attacks. How a few hundred carefully chosen documents can corrupt an AI model before it ever reaches production, and what that means for organizations building or adopting custom AI.&lt;/span&gt;&lt;/i&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;i&gt;&lt;span&gt;NOTE ON THE USE OF AI IN THIS DOCUMENT&lt;/span&gt;&lt;/i&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
      &lt;p&gt;&lt;span&gt;The document is primarily human-conceptualized,&amp;nbsp;written&amp;nbsp;and&amp;nbsp;edited. AI was used in the research and editing of this document.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fhacking-ai-executive-know-about-llm-security&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cybersecurity Articles</category>
      <category>AI</category>
      <pubDate>Mon, 29 Jun 2026 08:37:43 GMT</pubDate>
      <author>adeeb@decklaration.com (Adeeb Aslam)</author>
      <guid>http://www.rkon.com/resources/field-notes/hacking-ai-executive-know-about-llm-security</guid>
      <dc:date>2026-06-29T08:37:43Z</dc:date>
    </item>
    <item>
      <title>From Identity Activity to Identity Intelligence: Inside RKON's IAM Maturity Intelligence Center </title>
      <link>http://www.rkon.com/resources/field-notes/from-activity-to-identity-intelligence</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/from-activity-to-identity-intelligence" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/shutterstock_2762512847-scaled.jpg" alt="From Identity Activity to Identity Intelligence: Inside RKON's IAM Maturity Intelligence Center&amp;nbsp;" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;From Identity Activity to Identity Intelligence&lt;/h2&gt; 
&lt;h4&gt;&lt;i&gt;&lt;span&gt;A recap of our recent live session with&amp;nbsp;YouAttest, featuring &lt;a href="https://www.linkedin.com/in/duane-clouse/"&gt;Duane Clouse&lt;/a&gt;, Senior Manager, IAM &amp;amp; Zero Trust at RKON, alongside &lt;a href="https://www.linkedin.com/in/theauthguy/"&gt;Garret Grajek&lt;/a&gt; and Kashif Mehmood of&amp;nbsp;YouAttest.&lt;/span&gt;&lt;/i&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h4&gt; 
&lt;p&gt;&lt;span&gt;Thank you to everyone who joined us live for our recent webinar. If you did not join us live, the replay is available &lt;a href="https://www.youtube.com/watch?v=CnH3mk9qyeY"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/from-activity-to-identity-intelligence" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/shutterstock_2762512847-scaled.jpg" alt="From Identity Activity to Identity Intelligence: Inside RKON's IAM Maturity Intelligence Center&amp;nbsp;" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;From Identity Activity to Identity Intelligence&lt;/h2&gt; 
&lt;h4&gt;&lt;i&gt;&lt;span&gt;A recap of our recent live session with&amp;nbsp;YouAttest, featuring &lt;a href="https://www.linkedin.com/in/duane-clouse/"&gt;Duane Clouse&lt;/a&gt;, Senior Manager, IAM &amp;amp; Zero Trust at RKON, alongside &lt;a href="https://www.linkedin.com/in/theauthguy/"&gt;Garret Grajek&lt;/a&gt; and Kashif Mehmood of&amp;nbsp;YouAttest.&lt;/span&gt;&lt;/i&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/h4&gt; 
&lt;p&gt;&lt;span&gt;Thank you to everyone who joined us live for our recent webinar. If you did not join us live, the replay is available &lt;a href="https://www.youtube.com/watch?v=CnH3mk9qyeY"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Ffrom-activity-to-identity-intelligence&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Identity</category>
      <pubDate>Thu, 11 Jun 2026 10:29:59 GMT</pubDate>
      <author>eryan@rkon.com (Emily Ryan)</author>
      <guid>http://www.rkon.com/resources/field-notes/from-activity-to-identity-intelligence</guid>
      <dc:date>2026-06-11T10:29:59Z</dc:date>
    </item>
    <item>
      <title>Microsoft FastTrack: The Most Underused Lever in Your Microsoft Investment</title>
      <link>http://www.rkon.com/resources/field-notes/microsoft-fasttrack-an-underused-lever</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/microsoft-fasttrack-an-underused-lever" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/Microsoft-fasttrack.png" alt="Microsoft FastTrack: The Most Underused Lever in Your Microsoft Investment" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Most organizations think they’re paying for Microsoft licenses.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="http://www.rkon.com/resources/field-notes/microsoft-fasttrack-an-underused-lever" title="" class="hs-featured-image-link"&gt; &lt;img src="http://www.rkon.com/hubfs/wordpress-migration/Microsoft-fasttrack.png" alt="Microsoft FastTrack: The Most Underused Lever in Your Microsoft Investment" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Most organizations think they’re paying for Microsoft licenses.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=50823075&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.rkon.com%2Fresources%2Ffield-notes%2Fmicrosoft-fasttrack-an-underused-lever&amp;amp;bu=http%253A%252F%252Fwww.rkon.com%252Fresources%252Ffield-notes&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Microsoft</category>
      <pubDate>Tue, 09 Jun 2026 09:00:55 GMT</pubDate>
      <author>ramsha.shakeel@decklaration.com (Ramsha Shakeel)</author>
      <guid>http://www.rkon.com/resources/field-notes/microsoft-fasttrack-an-underused-lever</guid>
      <dc:date>2026-06-09T09:00:55Z</dc:date>
    </item>
  </channel>
</rss>
