Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Cybersecurity

Security for AI, connected devices and industrial systems.

F Creative Studio 360 helps organisations in any country protect artificial intelligence, the Internet of Things, operational technology, and the way that software is designed and released.

These systems fail differently from a typical application.

A language model can be steered by the text it is given. A connected device can be a way into the network behind it. A control system can be unsafe to test the way you would test a website. The same control catalogue does not cover all three.

F Creative Studio 360 scopes the work to the environment you actually run, in whichever country that environment sits. Nothing is tested until the organisation that owns it has authorised the engagement.

Systems that ordinary testing does not cover
Models, connected devices and plant systems fail in ways a web application test will not show. The work is scoped to those environments.
Proof, not a list of theoretical risks
Assessments try the issues that matter, within written rules, so you can see whether a weakness changes how the system behaves.
Security inside the way the system is built
Findings go back into design, training data, pipelines and operations, so the same issue is less likely to ship again.
A record leadership can use
The report separates what was examined, what was shown and what to change, in language a board and an engineering team can both use.

What the work covers

An engagement draws from the areas below. AI testing is planned against the OWASP Top 10 for Large Language Model Applications and MITRE ATLAS. Connected devices are reviewed with the OWASP Internet of Things project. Industrial work follows IEC 62443 and NIST SP 800-82.

AI and machine learning assessments
Review of models, the data that trains them, the pipelines that move that data, and the infrastructure and APIs around them.
Adversarial testing of AI systems
Authorised attempts to misuse a model: prompt injection, attempts to extract the model or its training data, and inputs crafted to change the output. The rules of the test are agreed first.
Secure development of AI systems
Practices for how a model is built, how training data is protected, how it is deployed, and how it is watched after it is in use.
AI governance
A practical framework for who may use a model, how bias and harmful output are handled, and which obligations apply where you operate.
IoT
Connected devices, the protocols they use and the systems behind them, assessed against the OWASP Internet of Things project where that fits the estate.
Operational technology
Industrial and control environments reviewed for segmentation, remote access and the safety constraints of the site. Testing that could affect operations is only included when it is written into the scope.
Security in delivery
Checks placed in design, build and release so weaknesses are found before a system, model or device image reaches production.

How an engagement runs

The sequence is the same in any country. What changes is the framework the report is written against.

  1. 1

    Scope the environment

    Agree which models, devices, plants or pipelines are in scope, what must not be touched, and who authorises the work.

  2. 2

    Understand how it is built

    Review architecture, data flows, access and the controls already in place before any testing starts.

  3. 3

    Test what was agreed

    Examine the in-scope systems against the written rules. Availability tests and anything that could disrupt operations stay out unless they are explicitly approved.

  4. 4

    Report and remediate

    A narrative for leadership and a technical record for the people who will fix it, then a retest of the items you have changed when that is part of the engagement.

What you receive

  • An executive summary of what was examined and what it means for the service.
  • Findings with evidence, rated by impact.
  • Remediation guidance written for the team that owns the model, device or pipeline.
  • Notes on governance, including who should own the control after the engagement.
  • A retest record when fixes are part of the scope.

Standards the work can align to

F Creative Studio 360 plans the engagement around the references that apply where you operate. For AI, those are commonly the NIST AI Risk Management Framework, ISO/IEC 42001 and, in the European Union, the EU AI Act. For how software is built and released, the NIST Secure Software Development Framework and OWASP SAMM are the usual starting points.

Alignment is not a certification. If a buyer or regulator needs a specific scheme, tell us during scoping and the engagement is written to that requirement.

Common questions

What does this service cover?+

F Creative Studio 360 assesses and tests environments that a standard application test does not fit: artificial intelligence and machine learning systems, Internet of Things devices, operational technology, and the way those systems are designed and released. The engagement is scoped to the estate you have.

Where do you deliver this?+

For organisations in any country. The technical work is the same. The governance section follows the obligations that apply where you operate, such as the EU AI Act in the European Union or a sector rule in your own country.

How is this different from a penetration test?+

A penetration test looks for weaknesses that can be exploited in agreed networks, applications and cloud systems. This work looks at models, training data, connected devices and industrial systems, and at whether security is part of how those systems are built. Many organisations use both.

Will you test a model we do not control?+

Only when the owner of that system has authorised the work in writing. F Creative Studio 360 does not test third-party services, client environments or production plants outside the agreed scope.

Can operational technology testing take a site offline?+

The rules are written to avoid that. Anything that could affect safety or operations is either left out of scope or agreed in advance with the people who run the site.

Which standards can the work follow?+

Common references are the OWASP Top 10 for Large Language Model Applications, the NIST AI Risk Management Framework, MITRE ATLAS, ISO/IEC 42001, IEC 62443 and NIST SP 800-82 for industrial systems, and the NIST Secure Software Development Framework for delivery. F Creative Studio 360 maps the engagement to the ones that apply to you. We do not claim that your organisation is certified because this work was done.

How much does it cost?+

It depends on the systems, how much access we are given and whether the work is an assessment, a test, or help putting controls into the development lifecycle. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Tell us which systems need a closer look.

F Creative Studio 360 will say whether the next step is an assessment, an authorised test, or help putting security into the way the system is built.