About

BREACH INTELLIGENCE SECURITY ARCHITECTURE AI RISK

DWIGHT SAMUELS

Built the defences. Decodes the failures.

The architect behind The Architecture Brief: real breach breakdowns, practitioner frameworks, and an AI risk lens most consultancies don’t have.

Dwight Samuels, Principal Enterprise Security Architect

DWIGHTSAMUELS1.SUBSTACK.COM

I break down real breaches, before the post-mortems get sanitised, so you see exactly where the architecture failed and what it actually cost.

Career

20 years in cybersecurity, 10 in security architecture. Started hands-on: firewalls, IPS/IDS, IAM, DDoS, proxy, XDR, and SIEM. Moved into architecture running enterprise security strategy and Technical Design Authority for regulated enterprises, then into securing the estate’s newest attack surface: AI itself.

  • AI & Emerging Technology: AI enterprise integration security, GenAI and LLM governance, agentic workflow security, RAG pipeline protection, MLOps and LLMOps, AI risk governance, and regulatory resilience under the EU AI Act and ISO/IEC 42001.
  • Strategy & Governance: enterprise security strategy, operating model design, Technical Design Authority (TDA), architecture governance, security service catalogue development, investment estimation, and cross-functional leadership.
  • Architecture & Frameworks: Zero Trust and identity-centric architecture, secure-by-design methodology, built on NIST, CIS, SABSA, and TOGAF.
  • Threat Modelling & SecOps: STRIDE, MITRE ATT&CK, MITRE ATLAS, MAESTRO, vulnerability management, and NIST 800-53 alignment.
  • IAM Platforms & Protocols: Okta, SailPoint IdentityIQ, BeyondTrust, and Microsoft Entra ID, spanning conditional access, SSO (SAML, OAuth 2.0, OIDC), identity federation, and MFA architecture.
  • AI Strategy & Enablement: AI strategy and roadmap development, identifying high-value AI use cases inside the business. Building internal AI literacy and confidence at senior levels. Keynotes, workshops, and board-level briefings.

Deep practitioner work underneath all of it: encryption architecture, Thales CipherTrust Manager (CTM), Luna HSM, HYOK and BYOK key custody models, and cryptographic key management.

My background is 20 years in cybersecurity, the last 10 in enterprise security architecture, including my current role as Principal Enterprise Security Architect for a regulated enterprise, reporting into the senior leadership team (SLT). That practitioner grounding is what shapes the approach: I help senior leaders, SME owners, and teams make confident decisions about AI, without the hype, jargon, or one-size-fits-all frameworks.

Sectors served

Financial services, health, industrial, banking, consultancy, and critical national infrastructure.

What makes this different

Unsanitised Post-Mortems

Most public breach analysis is written for search traffic, not for the people who have to fix the architecture.

NHI & Ghost Credentials

An emerging risk category most programmes don’t have on their radar yet.

Agentic AI Security

Backed by practitioner credentials, not vendor marketing.

What I’m not: a vendor, a compliance box-ticker, or a generic “AI is the future” commentator.