PhiloCyber / AI security practice
Your systems now think.Their security model has to catch up.
I secure what teams are shipping with GenAI: LLM applications, autonomous agents and MCP integrations. Threat modeling, penetration testing and policy — scoped and fixed-fee, executed and signed by the specialist who wrote the research. No scanner output, no handoffs.
Explore the practiceLLMs • Agents • MCP
Offensive security • Threat modeling • Advisory
Work at the point where models, tools and business logic meet.
Each engagement turns a vague concern about AI risk into boundaries, attack paths and decisions your team can act on. AI-accelerated, expert-validated: automation covers breadth, and every finding is reproduced and chained by hand before it reaches your report — the part a $3,500 scanner cannot do.
- Threat Modeling for AI SystemsA structured security review of how your agents, LLM features and MCP integrations could be misused, delivered one week after a single session with the people who built it.
- Penetration Testing for Agents, LLMs and MCPsAuthorized adversarial testing of your deployed AI application, from prompt injection and tool abuse to complete data-exfiltration chains. Retest included.
- AI Security Policy and GovernancePractical rules, review paths and evidence requirements for using and shipping AI without turning governance into a bottleneck.
- Advisory and ConsultationsIndependent judgment for one concrete AI security decision, without committing to a full assessment.
- AI Security EnablementHands-on workshops that give engineering, product and security a repeatable way to review AI systems before release.
Read the thinking before you hire it.
A few pieces that show how I work. The full archive lives on the blog.
What people who worked with me say.
LinkedIn recommendations, verbatim. The full set lives on the about page.
More about me“I had the pleasure of working with Richie when he first moved to New Zealand. He stood out to me during the interview process, partly because he was friendly and personable but mostly because he clearly demonstrated a passion for cyber security, particularly with web applications, and an eagerness to develop and hone his skills. These were the core characteristics he brought to his role. He was always looking to learn and do his best on every engagement and would actively try to do better on the next one. His penchant for development wasn't limited to himself as he would also actively share his knowledge and help other members of the team. It's been exciting to see Richie be so involved with both local and online security communities and I would happily jump at the chance to work with him again.”
Eleanor Wright
Managing Security Consultant
Bastion Security Group, New Zealand
Something already in production you are not sure about?
Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.
Tell me what you are building
