Gianclaudio Moresi

Cybersecurity leadership for the age of Agentic AI.

Corporate CISO · Author · Speaker · Lecturer · Founder of Swiss Cyber AI

Working at the intersection of cybersecurity, artificial intelligence, automated resilience and governance — with a focus on how organizations remain secure when AI agents move from assistants to autonomous actors.

CybersecurityEnterprise security leadership
Agentic AISecurity for autonomous agents
Automated ResilienceDefending at machine speed
AI GovernanceControl without blocking innovation
Professional Focus

From cybersecurity controls to resilient operating models.

Gianclaudio Moresi works on cybersecurity as an operating capability: how organizations detect, decide, contain and recover when digital environments become faster, more distributed and increasingly autonomous.

His current work extends that question into Agentic AI. When software can reason, use tools, call APIs and act on behalf of a company, identity, permissions, accountability and resilience need to be redesigned around a new type of actor.

The goal is practical: translate emerging AI risk into architectures, decision models, governance principles and measurable resilience that executives and security teams can use.

Cybersecurity Strategy & GovernanceSecurity operating models, executive governance, risk, resilience and enterprise-scale controls.
Agentic AI SecurityIdentity, permissions, memory, tools, orchestration and control of AI agents acting autonomously.
Automated ResilienceMoving beyond visibility toward machine-speed detection, correlation, containment and recovery.
Responsible AI GovernanceGovernance models designed to preserve accountability while enabling useful AI autonomy.
Ideas & Frameworks

Models for a security world moving at machine speed.

A collection of concepts and working frameworks developed to make cybersecurity and Agentic AI easier to reason about, govern and operationalize.

3L

Three Laws of Cybersecurity

A principles-based model designed to reduce complexity and help security leaders reason about the most important conditions for effective cyber defense.

AIR

Agentic AI Router

A control layer that evaluates request, user, context, intent, sensitivity, risk, cost, tools, data and history before assigning the right agent, model, permissions and security policy.

7D

Seven-Dimension Checklist

A structured way to challenge an autonomous AI deployment across multiple control dimensions before the system is trusted with business-impacting actions.

A3M

A3M Matrix

A decision model for structuring the relationship between AI autonomy, authority and risk so that increasing capability does not silently create uncontrolled agency.

ZDK

Zero Day Kill Chain

A way to reason about how unknown or emerging weaknesses move from opportunity to exploitation, business impact and defensive response.

RM

The Rented Mind

A concept for understanding what organizations surrender when reasoning is outsourced to external AI systems: context, dependencies, decision logic and potentially strategic knowledge.

BH

The Borrowed Hands

A model for the risk created when AI gains access to enterprise tools and APIs: the intelligence may be external, but the actions execute with the organization's own authority.

Core Thesis

AI agents will not simply change software. They will change the organization itself.

The transition from generative AI to Agentic AI creates a new enterprise actor: software that can pursue objectives, use tools, access data, make decisions and coordinate with other agents. As that capability scales, companies move from isolated AI assistants toward digital workforces — and eventually toward partially autonomous organizations.

Cybersecurity must therefore protect not only users, devices and applications, but also autonomous decision-makers whose actions may occur faster than traditional human review.

1 · AI AssistantAnswers and recommendations remain primarily human-directed.
2 · AI AgentThe system can plan, use tools and execute actions toward an objective.
3 · Autonomous OrganizationMultiple agents coordinate business processes with progressively less human intervention.
Books & Publications

Turning emerging technology into practical models.

The books connect cybersecurity leadership with the next operating model of the enterprise: AI agents, autonomous workflows and the controls needed to keep them trustworthy.

Available now

The Last Human Workforce

How AI Agents Will Turn Companies into Autonomous Organizations – and How We Keep Them Under Control

A practical exploration of Agentic AI, autonomous organizations, AI governance and the cybersecurity architecture required when digital agents begin acting as part of the workforce.

Agentic AIAutonomous OrganizationsAI SecurityAI GovernanceZero Trust
Order the bookSecure checkout via PayPal.

Payment is processed by PayPal. For order questions, contact gm@swisscyberai.org.

Cybersecurity

The Three Laws of Cybersecurity

A principles-based approach to cyber resilience

A framework for simplifying cybersecurity thinking and focusing leadership attention on the conditions that determine whether an organization can prevent, withstand and recover from cyber attacks.

CybersecurityResilienceLeadershipRisk
Visit the SCAI Shop
Speaking & Executive Discussions

Topics built for boards, CISOs and technology leaders.

Speaking themes focus on the strategic decisions created by AI-driven security, autonomous systems and the need to operate at machine speed.

01

The Last Human Workforce

How AI agents evolve into digital workforces and what autonomous organizations mean for leadership, governance and cyber risk.

02

Cybersecurity at Machine Speed

Why detection is no longer enough — and why organizations need measurable automated containment and recovery.

03

Securing Agentic AI

Identity, tools, permissions, memory, orchestration and Zero Trust for autonomous AI agents.

04

AI Governance Without Killing Innovation

How executives can create guardrails that preserve speed and experimentation while keeping accountability intact.

05

From Cyber Controls to Automated Resilience

Using the Automated Resilience Index as a way to discuss security performance in operational rather than purely compliance terms.

06

The Vanishing Human

What happens to responsibility, control and trust when more enterprise decisions are delegated to autonomous systems?

Platforms & Ecosystem

Where the work connects.

Research, professional dialogue, publishing and community-building come together across several complementary platforms.

Swiss Cyber AI Organization

Independent Swiss organization for cybersecurity, artificial intelligence, research and education.

Explore SCAI →
Swiss Cyber AI Conference

Executive-level exchange on cybersecurity, AI, risk, resilience and responsible technology.

Conference website →
LinkedIn

Ongoing commentary on cybersecurity, Agentic AI, resilience, governance and executive security leadership.

Connect on LinkedIn →
Connect

Cybersecurity is becoming an AI-speed discipline.

If you are working on Agentic AI, autonomous systems, cybersecurity resilience, AI governance or the future operating model of the enterprise, connect through SCAI or LinkedIn.