Books that put cyber, AI & resilience on the boardroom table.
Professor Kai London writes the field manuals that CIOs, CISOs, General Counsel and boards keep on the desk — turning fast-moving regulation and frontier technology into doctrine you can deploy on Monday morning. Forty-four titles spanning enterprise AI architecture, AI security and governance, agentic AI, post-quantum cryptography, identity and wireless defence, OT/ICS and SCADA security, and trust-led cyber resilience.
The library
Forty-four books. One mission: govern the risk, prove the control.
Each title maps cleanly to the frameworks your auditors and regulators are using right now — DORA, NIS2, the EU AI Act, IEC 62443, GDPR, ISO/IEC 27001:2022, ISO/IEC 42001 and NIST CSF 2.0.
Flagship titles
The AI Architects
We don't need more software. We need intelligence. The enterprise blueprint for AI that survives production, security and the board — reference architecture, RAG and cognitive search, the AI SDLC, and the governance a board can stand behind.
AI on Trial
Justice must answer. The practitioner's field guide to governing AI so every consequential decision is explainable, auditable and defensible — featuring the Evidence Chain Model™ and the SCALES™ framework.
The Last Login
Every breach begins with a login that should have been stopped. The board-level playbook for the identity era — VERIFY · LIMIT · DETECT · PROVE — with a Conditional Access library, KQL detections and a 90-day roadmap.
The Invisible Airborne Perimeter
Your wireless network is wide open. The complete enterprise wireless security programme — the S.I.G.N.A.L. framework, the Airborne Zero-Trust Model (AZT-7), evil-twin defence and NIS2 compliance.
Trustquake
When trust breaks, the business breaks. Find the fault before it finds you — seven practical instruments, real dated case studies, and a funded 90-day plan your board will approve. Maps to the CRISC domains and NIST CSF 2.0.
Breachproof
The executive's battle plan for the new business war — leading through ransomware, AI-driven deception, and the fight to keep customer and regulator trust when the attack lands.
No Logs, No Launch
The C-suite command system for deploying AI in regulated enterprises in 90 days — with the logging, governance and audit trail required before go-live.
The AI Control Architecture
The 90-day system for building governed, regulated, revenue-ready AI — a control plane that keeps autonomous systems accountable. When the machine decides, someone must answer.
The Breach Had Permission
The attacker did not break in. It signed in. How AI, identity failure and Zero Trust decide which companies survive the next cyber war — and how to leave attackers nothing to sign in with.
AI All-in-One series
AI Attacks on Critical Infrastructure All-in-One
Generative and agentic AI have been turned on the plant floor. The enterprise defence handbook for OT, ICS, SCADA, energy, manufacturing, transport and industrial systems under AI-driven attack.
AI Cybersecurity All-in-One
The complete enterprise reference for generative AI and LLM security, agentic AI, adversarial machine learning, AI red teaming, Zero Trust and SOC automation.
AI for CISOs All-in-One
The executive handbook for AI security strategy, governance, risk, architecture, regulation, investment and board-level leadership.
AI Security Architecture All-in-One
The definitive enterprise architecture handbook for LLMs, AI agents, RAG, MCP, APIs, identity, data security, cloud and Zero Trust AI platforms.
Post-Quantum Cybersecurity All-in-One
The enterprise migration handbook for quantum risk, post-quantum cryptography, PKI, TLS, identity, cloud and cryptographic transformation.
Agentic AI Security All-in-One
Securing autonomous AI agents end to end — LLMs, MCP, RAG, tool calling, multi-agent systems, red teaming, governance and AI cyber defence.
AI Red Teaming & Offensive AI Security All-in-One
Prompt injection, agent exploitation, LLM attacks, RAG poisoning and MCP abuse — the professional handbook for testing AI before somebody else does.
AI-Powered SOC All-in-One
Building the autonomous security operations centre — AI agents, SIEM, SOAR, detection engineering, threat hunting and incident response automation.
Agentic AI Governance, Risk & Compliance All-in-One
Autonomous AI under control — security controls, AI risk, audit evidence, the EU AI Act, ISO/IEC 42001, the NIST AI RMF and responsible AI.
Cyber Security All-in-One series
Volume 1: Foundations and Threats
Security principles, threat actors, attack lifecycles, networks, endpoints, Zero Trust and defensible enterprise architecture.
Volume 2: Identity and Cloud Security
IAM, PAM, Zero Trust, AWS, Azure, Google Cloud, SaaS, application and API security, Kubernetes and the software supply chain.
Volume 3: Security Operations and Response
SOC, SIEM, SOAR, detection engineering, threat hunting, threat intelligence, forensics, ransomware and crisis response.
Volume 4: Governance, Risk and Resilience
Boards, CISOs, cyber risk quantification, ISO 27001, NIST CSF 2.0, NIS2, DORA, crisis command and board assurance.
OT Security All-in-One series
Volume 1: Foundations of OT, ICS and SCADA Security
Operational technology from the ground up — PLCs, HMIs, RTUs, DCS, historians, safety systems, industrial protocols and the Purdue model.
Volume 2: Industrial Cyber Defence and Engineering Controls
Segmentation, industrial DMZs, remote access, PAM, vendor risk, vulnerability management and OT detection.
Volume 3: IEC 62443, Governance, Compliance and Board
NIS2, the Cyber Resilience Act, NERC CIP, NIST 800-82, ISO 27001, supplier risk, audit evidence and executive reporting.
Volume 4: Ransomware Resilience, Recovery and AI Risk
OT incident response, cyber recovery, manual fallback, digital twins and critical infrastructure continuity.
OT, ICS & SCADA field guides
OT Asset Discovery & Vulnerability Management
Finding every PLC, HMI, RTU, server, firmware risk, CVE and hidden industrial exposure — you cannot defend what you cannot see.
Water & Wastewater OT Cybersecurity
Protecting PLCs, SCADA, pumps, treatment plants and drinking-water infrastructure from cyberattack.
IEC 62443 Implementation & Audit Handbook
A practical guide to zones, conduits, security levels, risk assessment, evidence and audit readiness.
AI Attacks on OT & Critical Infrastructure
How AI is rewriting ICS, SCADA and critical-infrastructure defence — and what has to change before the next attack.
OT SOC & Detection Engineering
Industrial threat detection, SIEM, network monitoring, ATT&CK for ICS, threat hunting and incident triage.
OT Remote Access & Vendor Security
Securing engineers, contractors, OEMs, VPNs, jump servers, PAM and every third party with a route into your plant.
OT Ransomware Incident Response Playbook
The first 24 hours of an ICS/SCADA cyberattack — safety, isolation, manual operations, recovery and return to production.
Power Grid & Power Plant Cybersecurity
OT, ICS, SCADA, DER, BESS, relays, remote access and cyber resilience for modern electricity infrastructure.
Industrial AI Security All-in-One
Securing AI agents, digital twins, machine learning, robotics, IIoT and autonomous industrial operations.
Resilience All-in-One series
The Resilient Enterprise All-in-One
Business continuity, disaster recovery, crisis governance and evidence-first operational survival.
Cyber Recovery All-in-One
Identity, cloud, ransomware, data, backup, logging and Zero Trust continuity — getting the business back on its feet.
AI Resilience All-in-One
Shadow AI, model risk, AI incident response, secure AI operations and digital trust.
OT & Critical Infrastructure Resilience All-in-One
SCADA, ICS, IEC 62443, manual operations, safety and control room continuity when the screens go dark.
AI Security & Governance series
AI Security & Governance: Main Manual
The complete practitioner guide to securing, governing, evidencing and defending AI systems.
AI Security & Governance Workbook & Toolkit
Templates, registers, checklists, dashboards, clauses, workflows and implementation worksheets you can use on Monday.
AI Security & Governance Review Questions & Case Scenarios
Practitioner, audit, board and scenario questions with answers and explanations.
AI Security & Governance Annual Update Methodology
Keeping the programme current — regulation, standards, threats, incidents, controls, assurance, board reporting and evidence.
Map the fault. Hold the line. Prove it held. Every title turns fast-moving regulation into an operating discipline a board can stand behind.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor, and Founder & CEO of Quantum AI Systems Security LLC — writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.