Perspective on the forces reshaping enterprise cyber risk.
This is where Professor Kai London publishes analysis and commentary for the people who carry cyber risk to the top table. Each piece works through what DORA, NIS2, the EU AI Act, Zero Trust, post-quantum cryptography and AI governance actually mean for strategy, budgets and accountability — written for CISOs, risk leaders and boards who need a clear read on what is changing and why it matters now.
Why this writing exists
Cutting through the noise on regulation and AI.
Cyber leaders are not short of headlines. They are short of clear, honest interpretation — analysis that says what a new regulation or technology shift genuinely changes, what is hype, and what a board should decide next. That gap is what these insights set out to close.
Professor Kai London writes from the seat, not the sidelines. With 25+ years across Banking, Aviation, Defence, Government and Critical National Infrastructure — and roles spanning VP, CIO, CTO, CISO and Head of Cyber Security, alongside a Big Four background — his commentary is grounded in what it takes to actually implement DORA, NIS2, the EU AI Act, Zero Trust and AI governance under real-world constraints.
The aim is practitioner-first: each article connects the regulatory and technical detail back to the questions risk leaders are being asked in the room — about exposure, accountability, resilience and trade-offs — so the reader leaves with a position they can defend, not just a summary.
As Founder & CEO of Quantum AI Systems Security LLC and an Honorary Professor in Cybersecurity, AI & Quantum Computing and Researcher at UCL, Kai keeps this commentary anchored in current research as well as live practice.
The basis for the view
Commentary backed by deep accreditation.
The perspective offered here is informed by formal expertise across information security, cloud, AI governance and the EU regulatory landscape — not opinion in a vacuum.
Insight themes
The topics under analysis.
The commentary returns to six recurring themes — the regulations and technologies most likely to land on a board agenda over the next cycle.
DORA & Operational Resilience
Reading the Digital Operational Resilience Act beyond compliance — ICT risk, third-party oversight, incident reporting and resilience testing as a board issue.
NIS2
What the directive means for essential and important entities, where it converges with DORA, and the governance and accountability shifts it forces.
The EU AI Act
Risk tiers, obligations and timelines — and how to translate the AI Act into practical assurance rather than another policy binder.
Zero Trust
Cutting through Zero Trust marketing to NIST 800-207 fundamentals: what changes in architecture, identity and operating model, and what does not.
Post-Quantum Cryptography
Why the migration clock has already started, how to inventory cryptographic risk, and how to plan the transition before mandates arrive.
AI Governance & Board Cyber Risk
Governing AI adoption responsibly and reporting cyber risk to the board in language that informs decisions rather than obscures them.
Regulation and AI are not problems to be summarised — they are decisions waiting to be made. My aim with every piece is to give cyber and risk leaders a defensible position, not just a digest of the latest headline.
From the bookshelf
Long-form thinking, published.
Where the insights compress an idea into commentary, the books explore it in full — eight titles on AI, trust and the future of cyber security.
Follow the commentary
Keep up with the analysis.
New perspectives on cyber regulation, AI and resilience are shared on LinkedIn first. Follow along, or reach out there to discuss a piece or suggest a topic.