Build a threat model and engagement plan prior to execution: define the target, likely adversary profiles, attack paths, success criteria, and safety constraints before any action is taken.
Conduct social engineering, physical, and process-focused assessments to validate the human and procedural layers of defense, not just the technical stack.
Assess emerging technologies — particularly AI/ML systems, LLM applications, and their pipelines — for adversarial, prompt-injection, data-poisoning, model-extraction, and supply-chain exposures.
...