Portfolio

John Mackenzie

AI Systems, Cyber Risk, And The Training To Run Them Safely.

Australian AI and cybersecurity specialist. I advise boards, train teams, and build the tools I recommend. Every build is public so you can check the work before you hire me.

John Mackenzie

My Ventures

Products I Build And Run

01

BlackSnow Intelligence

You Get Screened Out Before Anyone Calls You.

Reads your website the way procurement teams and their AI do: privacy policy, data protection agreement, and sub-processor list. Free, no account.

02

CyberTown

Cyber Judgment, Trained Through Real Decisions.

Role-based cybersecurity training built on realistic decision scenarios, with dashboards and evidence exports for governance.

03

AIEOS

The Governed AI Software Production Environment.

Direct an AI workforce across accounts and providers. Work is split into accountable items, independently reviewed, and nothing reaches Done without evidence.

04

AIwatx

Measured, Not Modelled.

Measures AI token use on your own machine, applies a published method, and proves the saving against your own baseline. Early access, no public site yet.

05

LLM Vault

Govern Every AI Interaction. Prove Every Decision.

The governed layer between an organisation and every model, agent, and coding tool it uses: classification, policy gating, routing, review, and tamper-evident evidence.

06

Business Intelligence Hub

The AI-Enabled Operating System For Leaders.

Map your company, run a governed AI team, and keep every action traced and human-approved. Built for 50 to 250 employee EU companies.

Research

Research Papers

Abstract Cyber Cube governance model showing cyber risk as a dynamic organisational configuration.
Paper 01

Cyber Cube Theory and the Failure of Cyber Governance

Cyber Cube Theory reframes serious cyber incidents as organisational governance failures, not just technical failures. It examines how board oversight, executive management, control reality, assurance quality, privacy, AI, suppliers, and evidence combine to shape cyber defensibility.

Digital boardroom evidence challenge model for cyber defensibility and proportional proof.
Paper 02

Advocatus: Institutionalising Evidentiary Governance in Cyber Defensibility

Advocatus introduces a board-level challenge architecture for cyber defensibility. It examines how high-consequence cyber claims should be tested through structured dissent, proportional proof, evidence quality, and traceable governance decisions.

Black Snow internal audit concept showing hidden catastrophic cyber risk inside a compliant environment.
Paper 03

Black Snow–Informed Internal Audit

Black Snow–Informed Internal Audit examines why compliant organisations still fail. It reframes internal audit around catastrophic cyber risk, weak signals, sequencing, culture, resource allocation, assurance distortion, and structural proximity to severe cyber harm.

Cyber Butterfly Effect concept showing small tolerated cyber weakness propagating through organisational systems.
Paper 04

The Cyber Butterfly Effect

The Cyber Butterfly Effect explains how small tolerated weaknesses can move through an organisation’s cyber DNA and eventually create disproportionate harm. It focuses on micro-causation, hidden weakness, supplier opacity, behavioural adaptation, and assurance failure.

Sequence Matters concept showing different cyber intervention orders creating different organisational risk outcomes.
Paper 05

Sequence Matters: Non-Commutative Operators in Organisational Cyber Risk

Sequence Matters argues that the order of cyber interventions changes the risk outcome. It examines how controls act on technical, behavioural, and symbolic organisational states, making cybersecurity sequencing a first-class governance variable.

General Theory of Organisational Cyber Risk showing cyber survivability boundaries and defensibility under stress.
Paper 06

A General Theory of Organisational Cyber Risk

A General Theory of Organisational Cyber Risk reframes cyber risk as a survivability problem in a tail-dominant environment. It challenges expected-loss thinking, compliance proxies, averaging, and weak board-level assumptions about cyber defensibility.

Start With One Task

A free 30-minute assessment. You leave with the task named and a one-page next step.

Book The Free Assessment