I build AI systems. Then I secure them.

I’m Nick Falshaw. I’ve shipped 20+ production AI systems, agents, RAG pipelines, and document automation, and I’ve spent 17+ years securing enterprise networks in banking, automotive, manufacturing, and regulated infrastructure. Building AI and securing AI are usually two hires. Here they’re one.

LIVE 17 years, distilled
nick@falshaw: ~/security
$ whoami
Nick Falshaw, AI Engineer & AI Security Consultant
$ cat focus.txt
AI systems engineering
AI security engineering
Firewall automation at scale
Cloud, zero trust & ISO 27001
$ cat creds.txt
AI-102 · AZ-500 · ISO 27001 LI · CEH · TOGAF 9 · CCIE Sec (written)
$ _

Build the system, secure the stack, prove it in audit.

Need an AI system built, or an existing one secured? I do both: agents and pipelines that ship, controls that survive production pressure, and the evidence to prove it. Firewall automation and ISO 27001 stay in the toolkit.

AI Systems Engineering

Agents, RAG pipelines, LLM integrations, and document automation, taken from idea to production. 20+ systems shipped end-to-end: self-hosted, Dockerised, and built to run every day, not to demo once.

AI Security Engineering

Agents take action, RAG pipelines expose context, and MCP servers expand the attack surface. I threat-model agentic systems, lock down ingestion, and harden self-hosted LLM stacks before they reach production.

Firewall Automation

Vendor-agnostic change automation grounded in 280+ real migrations across Palo Alto, Check Point, Cisco, Fortinet, and F5. Rule sets that survive audit, segmentation that holds, and automation that removes the human bottleneck.

Cloud & Zero Trust

Identity-first security for Azure and hybrid estates: conditional access, segmentation, and least privilege, prioritised by the risk each control actually removes rather than the logo on the box.

ISO 27001 & Compliance

ISO 27001 from gap analysis through certification, plus NIS2 and DORA readiness for regulated sectors. Passing the audit is the easy part, the goal is a programme that still holds the day something breaks.

Proven, not slideware

Every claim here is backed by delivery: production systems, real migrations, and audit evidence from regulated environments. A track record you can probe before we speak.

20+production AI systems shipped
17+years in enterprise cyber
280+firewall migrations delivered

Seventeen years close to production.

Production firewalls, regulated audits, and AI systems shipped end-to-end, the record, not the pitch.

  1. 2025, now

    Independent AI Engineer & AI Security Consultant

    Building and securing AI systems: agents, RAG pipelines, and document automation on the build side, agentic threat modelling and self-hosted LLM hardening on the defence side. Firewall automation and ISO 27001 programmes for regulated estates.

    • AI systems engineering
    • AI workload security
    • Firewall automation / ISO 27001
  2. 2010, 2025

    Senior / Lead Network Security Contractor

    Fifteen years contracting into DAX-30 and enterprise environments, banking, automotive, manufacturing, payments and the public sector. Delivered 280+ firewall migrations and the security architecture behind them, multi-vendor and audit-ready.

    • Palo Alto (Panorama / Cortex / Prisma)
    • Check Point (VSX / Gaia / MDS / ClusterXL)
    • Cisco Firepower / ASA / ACI
    • Fortinet
    • F5 BIG-IP
  3. earlier

    Network & Security Engineering

    Enterprise routing, switching and perimeter security, the grounding that seventeen years of firewall, compliance and now AI-security work is built on.

Certifications

AI-102, Azure AI Engineer AZ-500, Azure Security Engineer AI-900, Azure AI Fundamentals ISO 27001 Lead Implementer CEH, Certified Ethical Hacker TOGAF 9 CCSP CCIE Security (written) CCNP CCDP CCSA · CCSE (Check Point) JNCIA-FWV · JNCIS-FWV (Juniper) Palo Alto EDU-201/205/311/121 F5 BIG-IP LTM ITIL v3 Foundation

Three ways to bring me in.

Most engagements start as one of these and grow from there. Fixed scope where it helps, retained where the work is ongoing.

Secure

AI & security review

Threat-model an AI system or audit a network estate: agents, RAG pipelines, MCP servers, firewalls, and identity. You get a prioritised findings report with fixes ranked by the risk each one removes, not a checklist.

Build

Build the system

Design and ship the AI workload end to end: agents, retrieval, and document automation, self-hosted and hardened before it reaches production. Built to run every day, with the security baked in rather than bolted on.

Migrate

Firewall & segmentation

Vendor-agnostic firewall automation and migration grounded in 280+ real projects across Palo Alto, Check Point, Cisco, Fortinet, and F5. Rule sets that survive audit and segmentation that actually holds.

Field notes.

Practical writing on firewalls, compliance, and shipping AI systems that survive real users.

JadePuffer: Ransomware With No Human at the Keyboard

The first ransomware run entirely by an AI agent, foothold to encryption, no operator. It went from failed login to working fix in 31 seconds. What breaks when the adversary's tempo and cost both collapse.

Read

Your AI Coding Tool Was Profiling You. The Real Lesson Is About Trust.

A researcher found Claude Code quietly fingerprinting users and phoning markers home. The scandal is not Anthropic. It is that you gave a vendor agent root on your codebase and never audited the trust.

Read

The Security Controls That Pass the Audit and Do Nothing

The unread access review, the log-only WAF, the phishing-completion metric, the rubber-stamp firewall review, the regex "guardrail". Controls that pass audit and stop nothing, and how to test effectiveness instead of existence.

Read

The Credential Is Dead. Long Live Continuous Verification.

16 billion credentials leaked and stolen sessions walk past MFA. Possession stopped proving identity. The fix is continuous verification, at the firewall and the AI agent alike.

Read

AI Agents Are the Service Accounts That Learned to Think

AI agents are non-human identities with standing access. After 17 years cleaning up orphaned firewall rules, the sprawl, and the cure, are familiar.

Read

The Autonomous AI Attacker Arrived. It Won in Under an Hour.

An AI agent ran a real intrusion end to end, foothold to data exfiltration, in under an hour with no human. What it breaks for defenders.

Read

Two Authentication Bypasses, One Bug Class: The VPN Edge and the AI Stack

A Check Point VPN zero-day and the BadHost flaw in Starlette are the same CWE-287 mistake, one stack apart: trusting attacker-controlled input to authenticate.

Read

From CVSS to ASR: Putting a Number on AI Agent Risk

For 17 years I scored security risk in CVSS. Anthropic just gave AI agents their own number: a 31.5% prompt-injection hijack rate. The risk discipline transfers.

Read

Prompt Injection Is a Confused-Deputy Problem We Already Solved

Prompt injection is a confused-deputy attack: the agent spends its own authority for an attacker. Network security solved that with trust boundaries, not smarter parsing.

Read

The Firewall CVE and the AI-Agent Breach Are the Same Mistake

A root-RCE firewall CVE and a poisoned AI-agent skill marketplace share one root cause: no provenance, no least privilege, no change control.

Read

OWASP LLM Top 10: 5 Critical AI Vulnerabilities for 2026

Where production LLM systems break first, based on mapping the OWASP LLM Top 10 against real codebases.

Read

Zero Trust Mittelstand: A Pragmatic 90-Day Plan

Zero Trust for the Mittelstand, not the Fortune 500: identity, segmentation, and continuous verification without a full rebuild.

Read

Mittelstand NIS2: Why German SMEs Are Dangerously Unprepared

The backbone of Europe’s economy built its advantage through engineering, not security. Here is what BSI deadlines require and how to close the gap.

Read

What 15 Years of Enterprise Security Compliance Taught Me

Hundreds of assessments across TISAX, PCI-DSS, ISO 27001, and NIS2, plus the lessons that do not appear in any framework.

Read

AI Threat Detection: 7 Strategies for CISOs in 2026

How to reduce alert noise, find novel attacker behaviour, and turn detection maturity into evidence the board can understand.

Read

How an engagement works.

The method stays consistent whether I’m building an AI system or securing one: evidence first, architecture second, implementation third, verification always.

01

Assess

Map what’s really deployed, topology, AI workloads, identity, threat surface, regulatory scope. Facts, not assumptions.

02

Architect

Design the target state and the path to it. AI controls and network defences on one blueprint, prioritised by risk and effort.

03

Implement

Build it: firewall automation, RAG controls, identity, and segmentation hardened against the vectors that actually land.

04

Verify

Prove it under real load. Useful alerting, owned runbooks, and audit evidence produced as part of delivery.

Ship AI you can
stand behind.

Building an AI system? Running one that’s never been threat-modelled? Still on firewalls and ISO 27001? Tell me what you’re building or defending and what deadline matters. I reply within one business day.

Prefer not to use a form? Find me on LinkedIn.

Remote across the EU & worldwide