Automated Resilience Index
A security KPI centered on how much of the defensive cycle can detect, correlate, contain and recover automatically — shifting resilience from a static control view toward operational response speed.
Working at the intersection of cybersecurity, artificial intelligence, automated resilience and governance — with a focus on how organizations remain secure when AI agents move from assistants to autonomous actors.
Gianclaudio Moresi works on cybersecurity as an operating capability: how organizations detect, decide, contain and recover when digital environments become faster, more distributed and increasingly autonomous.
His current work extends that question into Agentic AI. When software can reason, use tools, call APIs and act on behalf of a company, identity, permissions, accountability and resilience need to be redesigned around a new type of actor.
The goal is practical: translate emerging AI risk into architectures, decision models, governance principles and measurable resilience that executives and security teams can use.
A collection of concepts and working frameworks developed to make cybersecurity and Agentic AI easier to reason about, govern and operationalize.
A security KPI centered on how much of the defensive cycle can detect, correlate, contain and recover automatically — shifting resilience from a static control view toward operational response speed.
A principles-based model designed to reduce complexity and help security leaders reason about the most important conditions for effective cyber defense.
A control layer that evaluates request, user, context, intent, sensitivity, risk, cost, tools, data and history before assigning the right agent, model, permissions and security policy.
Extend least privilege to autonomous AI: grant an agent only the autonomy, tools, data, memory and decision authority required to complete its task.
A structured way to challenge an autonomous AI deployment across multiple control dimensions before the system is trusted with business-impacting actions.
A decision model for structuring the relationship between AI autonomy, authority and risk so that increasing capability does not silently create uncontrolled agency.
A way to reason about how unknown or emerging weaknesses move from opportunity to exploitation, business impact and defensive response.
A concept for understanding what organizations surrender when reasoning is outsourced to external AI systems: context, dependencies, decision logic and potentially strategic knowledge.
A model for the risk created when AI gains access to enterprise tools and APIs: the intelligence may be external, but the actions execute with the organization's own authority.
A governance question for autonomous organizations: what happens to accountability, oversight and resilience as humans disappear from more and more operational decisions?
The transition from generative AI to Agentic AI creates a new enterprise actor: software that can pursue objectives, use tools, access data, make decisions and coordinate with other agents. As that capability scales, companies move from isolated AI assistants toward digital workforces — and eventually toward partially autonomous organizations.
Cybersecurity must therefore protect not only users, devices and applications, but also autonomous decision-makers whose actions may occur faster than traditional human review.
The books connect cybersecurity leadership with the next operating model of the enterprise: AI agents, autonomous workflows and the controls needed to keep them trustworthy.
A practical exploration of Agentic AI, autonomous organizations, AI governance and the cybersecurity architecture required when digital agents begin acting as part of the workforce.
Payment is processed by PayPal. For order questions, contact gm@swisscyberai.org.
A framework for simplifying cybersecurity thinking and focusing leadership attention on the conditions that determine whether an organization can prevent, withstand and recover from cyber attacks.
Speaking themes focus on the strategic decisions created by AI-driven security, autonomous systems and the need to operate at machine speed.
How AI agents evolve into digital workforces and what autonomous organizations mean for leadership, governance and cyber risk.
Why detection is no longer enough — and why organizations need measurable automated containment and recovery.
Identity, tools, permissions, memory, orchestration and Zero Trust for autonomous AI agents.
How executives can create guardrails that preserve speed and experimentation while keeping accountability intact.
Using the Automated Resilience Index as a way to discuss security performance in operational rather than purely compliance terms.
What happens to responsibility, control and trust when more enterprise decisions are delegated to autonomous systems?
Research, professional dialogue, publishing and community-building come together across several complementary platforms.
Independent Swiss organization for cybersecurity, artificial intelligence, research and education.
Executive-level exchange on cybersecurity, AI, risk, resilience and responsible technology.
Cybersecurity news, analysis and professional content for security leaders.
Ongoing commentary on cybersecurity, Agentic AI, resilience, governance and executive security leadership.
If you are working on Agentic AI, autonomous systems, cybersecurity resilience, AI governance or the future operating model of the enterprise, connect through SCAI or LinkedIn.