The Harm Surface

Advisory

The same desk, on your problem.

The Harm Surface exists because AI, cyber and autonomy have become one threat surface. Advisory work applies the same method — deterministic, inspectable, stated plainly — to a single organisation instead of a week of news.

Engagement shapes

Posture AI threat posture review. Where agents, models and autonomous systems actually touch your estate, what that changes about your threat model, and what to do before the guidance exists. Written output your board can read. Briefing Executive and board briefings. The quarter's developments in this domain, graded the way the brief grades them — what changed, how much to care, what to do about it. No vendor deck has an incentive to tell you this straight. Review Independent review. A second opinion on an AI-security plan, product claim or incident readback, from someone whose published record shows exactly how they weigh evidence.

Who you get

James Webb — CISO, educator and independent researcher. Every issue of the brief is a public, checkable record of judgement under uncertainty — read the archive before you write; that is what it is for.

How it starts

One email describing the problem. If it is not work this desk should do, you will be told so plainly — the same de-escalation promise the brief makes every week.

Advisory work never influences the brief: no client is covered more softly, and no engagement buys an item's score or placement. Published by Rational Mystic LLC, in a personal capacity — this work speaks for no employer.