“When nobody is watching, an approved exception must be measured, or a forgotten grant will measure it for you; the safest control is the one that is used.”

When nobody is watching, an approved exception must be measured, or a forgotten grant will measure it for you; the safest control is the one that is used. — Kai London (Professor Kai London), CISO. Principle 9144 of 10000 from the book “The Breach Had Permission” — cybersecurity, AI security and OT resilience doctrine. Official sites: professorkailondon.com · kailondon.co.uk