Book · Safe Lab Paper · Two Colab Collections

Cybersecurity in the Age of Autonomous AI

A pedagogical introduction to agentic threats, financial risk, and governance-first defense.

A complete learning journey for financial practitioners who must understand how AI changes the speed, reach, persistence, and economics of cyber risk—and how institutions can respond without surrendering human authority.

The Governance-First Method

Capability must never become authority by accident.

Cybersecurity is taught here as financial, operational, and governance risk. The course begins with business purpose, protected assets, dependencies, actors, and decision rights—then connects policy to architecture, measurable controls, credible evidence, and accountable action.

01

Understand

Map the process, assets, identities, data, models, tools, dependencies, and accountable owners.

02

Assess & control

Identify plausible threats and loss channels; constrain access, authority, data flows, and high-impact actions.

03

Monitor & respond

Turn telemetry into decision-grade evidence, then escalate, contain, recover, and communicate.

04

Learn

Convert incidents, tests, and near misses into stronger controls, clearer accountability, and institutional memory.

Pedagogical Roadmap · Ten Stages

From first principles to professional judgment.

The sequence is cumulative. Each chapter translates technical reality into financial language, while each notebook turns the argument into a safe, transparent, synthetic, and reproducible exercise.

01
Foundations

Cybersecurity Without Mystification

Assets, threats, vulnerabilities, controls, residual exposure, and loss.

Professional outcome

Explain cyber risk in business and financial terms.

02
Threat objectives

What Attackers Try to Achieve

Confidentiality, integrity, availability, fraud, disruption, and monetization.

Professional outcome

Interpret attacker objectives as institutional loss channels.

03
Defensive visibility

What a Defensive Platform Actually Sees

From events and alerts to cases, incidents, and management decisions.

Professional outcome

Distinguish raw telemetry from decision-useful evidence.

04
Identity & authority

Identity, Passwords, and Access Risk

Authentication, least privilege, segregation of duties, and machine identity.

Professional outcome

Evaluate who—or what—is permitted to act.

05
Integrity

Applications, Data, and Integrity Risk

Prompt injection, memory poisoning, manipulated data, and tool misuse.

Professional outcome

Protect the integrity of AI-enabled workflows.

06
Security operations

Detection, Monitoring, and Security Operations

Behavioral detection, vulnerability discovery, triage, and response priority.

Professional outcome

Detect fast, adaptive, AI-enabled threats.

07
Resilience

Incident Response and Business Continuity

Escalation, containment, recovery, continuity, and communication.

Professional outcome

Make disciplined decisions during evolving incidents.

08
Measurement

Quantifying Cyber and AI-Enabled Operational Risk

Frequency, severity, scenarios, control effects, and capability multipliers.

Professional outcome

Translate uncertainty into decision-relevant estimates.

09
Accountability

Governance, Third Parties, and Accountability

Board oversight, risk appetite, three lines, ecosystems, and concentration.

Professional outcome

Assign ownership across the institution and its dependencies.

10
Integrated practice

A Finance Professional’s Cyber-Risk Playbook

Understand · Assess · Control · Monitor · Respond · Learn.

Professional outcome

Bring the entire governance-first discipline together.

The Learning System

Read the argument. Run the evidence.

The book, the Safe Lab paper, and two notebook collections work as one architecture. Prose develops judgment; executable laboratories expose assumptions, control performance, stress, and residual risk.

The Book · Complete PDF

Principles of Cybersecurity in the Age of Autonomous AI

Ten progressive chapters translate cyber concepts into the language of finance while keeping the emerging agentic threat at the center.

Read the book ↗
Research Paper · Safe Lab

Governing Autonomous Cyber Risk

The professional rationale, safety architecture, governance boundaries, and pedagogical progression behind controlled experiments in autonomous cyber risk.

Read the paper ↗
Advanced Collection · 10 Notebooks

Progressive Safe Lab Series

From baseline threat modeling to adaptive red–blue interaction, trust poisoning, compromised memory, state equivocation, deterministic containment, and causal recovery.

Explore the 10 Safe Labs ↗
Book Companions · 10 Notebooks

Governance-First Colab Laboratories

Ten newly updated chapter companions, each combining extensive pedagogical explanation with ten executable exercises using synthetic data and bounded defensive scenarios.

Open companion notebooks ↗

Advanced Safe Lab Series · Chapters 1–10

From one protected record to systemic causal recovery.

The sequence is intentionally cumulative. It begins with the simplest integrity-control example and progressively introduces agentic authority, adaptive adversarial reasoning, red–blue interaction, credential and memory compromise, false consensus, state equivocation, deterministic containment, and recovery.

The Professional Obligation

Cybersecurity is part of the fiduciary language of finance.

Financial professionals do not need to operate security tools. They do have a responsibility to understand exposures, challenge assumptions, evaluate controls, interpret evidence, and remain accountable for decisions made by AI-enabled institutions.
Protect institutional trustConfidentiality, integrity, availability, and credible control are foundations of financial value.
Govern automated authorityModels and agents require bounded permissions, independent review, escalation, and reversal.
Connect cyber events to financeIncidents can become liquidity, capital, valuation, regulatory, operational, and reputational events.
Demand decision-grade evidenceBoards and management need limitations, residual exposure, control performance, and accountable owners.

The Learning Experience

Built for movement—from recognition to judgment.

Every stage asks the learner to combine conceptual understanding with observable evidence, management interpretation, and responsible action.

01

Read

Establish the vocabulary, mechanisms, threats, and governance questions.

02

Run

Use synthetic Colab exercises to make assumptions and control effects visible.

03

Challenge

Stress scenarios, test boundaries, inspect false confidence, and identify what breaks.

04

Decide

Translate findings into an accountable management, risk committee, or board action.

AR

Academic Direction

Alejandro Reynoso

Honorary Fellow and Lecturer at Cambridge Judge Business School; Founder and Chief Scientist of DEFI Capital Research; financial-markets practitioner, researcher, and educator.

The course brings together cybersecurity, autonomous AI, finance, institutional governance, and professional responsibility in a single pedagogical architecture.