# Fire Mountain Labs > Humans that know AI. We help organizations deploy AI that survives attackers, auditors, and regulators. AI red teaming, risk assessment, governance, and training. Fire Mountain Labs is a Service-Disabled Veteran-Owned Small Business helping organizations deploy AI that survives attackers, auditors, and regulators. ## Services - [AI Red Teaming & Failure Mode Analysis](https://firemountainlabs.com/our-services/ai-safety-security/): Adversarial testing of your AI systems mapped to MITRE ATLAS, plus structured analysis of the failures that happen with no attacker at all. - [AI Risk Assessment](https://firemountainlabs.com/our-services/ai-risk-assessment/): Evaluating AI systems for security, regulatory, and operational risk, with findings mapped to NIST AI RMF and ranked by likelihood and business impact. - [AI Enterprise Readiness Assessment](https://firemountainlabs.com/our-services/ai-enterprise-readiness/): Where you actually stand, scored against the MITRE AI Maturity Model, with a plan you can fund and execute. - [AI Governance](https://firemountainlabs.com/our-services/ai-governance/): AI policy development, regulatory compliance assessment, and AI incident response. Governance aligned to the EU AI Act, NIST AI RMF, and ISO/IEC 42001. - [ISO/IEC 42001 Audit](https://firemountainlabs.com/our-services/iso-42001-audit/): ISO/IEC 42001 audit services led by PECB-certified lead auditors: readiness (pre-audit) assessment, internal audit, and certification audit support. - [AI Lifecycle Engineering](https://firemountainlabs.com/our-services/ai-lifecycle-engineering/): Security, privacy, and resilience built into the AI system from the first requirement: lifecycle engineering on the CRISP-ML(Q) framework. - [Secure Design Review](https://firemountainlabs.com/our-services/secure-design-review/): Assessment of an AI system already in flight against secure-by-design principles: threat modeling, privacy and data protection, resilience, and traceability. - [Training & Workshops](https://firemountainlabs.com/our-services/live-workshops/): Half-day and full-day AI security workshops, conference talks, and partner enablement, tailored to your systems, your sector, and your regulatory exposure. ## Resources - [Blog](https://firemountainlabs.com/resources/blog/): Writing from Fire Mountain Labs on AI security, governance, and assurance. - [Publications](https://firemountainlabs.com/resources/publications/): Selected publications by founders Chris M. Ward and Josh Harguess on adversarial machine learning, AI security and offensive security for AI systems. - [Speaking](https://firemountainlabs.com/resources/speaking/): Fire Mountain Labs conference talks, including BSides San Diego, a NATO research symposium, BSides Las Vegas and the Cloud Security Alliance. - [Slides](https://firemountainlabs.com/resources/slides/): Slide decks from Fire Mountain Labs talks and workshops, written up in full with the deck attached. - [Podcasts & Digital Media](https://firemountainlabs.com/resources/podcasts-digital-media/): Fire Mountain Labs video and interview appearances, including the AI Maturity Series and a Help Net Security video on adopting AI-driven security tools. ## Blog posts - [BSides San Diego 2026: Breaking the Black Box](https://firemountainlabs.com/resources/blog/b-sides-san-diego-2026-breaking-the-black-box/): A BSides San Diego 2026 session on the AI governance frameworks that matter: NIST AI RMF, the EU AI Act, ISO 42001, GDPR and MITRE's AI Maturity Model. - [2025: The Year of the Spark](https://firemountainlabs.com/resources/blog/2025-the-year-of-the-spark/): A look back at our first year: research at the NATO IST-210 symposium, CAMLIS, BSides Las Vegas and SPIE DCS, and where we take it next. - [Beyond the Firewall: The Three Pillars of Offensive AI Security](https://firemountainlabs.com/resources/blog/beyond-the-firewall-the-three-pillars-of-offensive-ai-security/): AI fails in ways firewalls cannot see: data poisoning, model theft, prompt injection. The three layers of a deliberate offensive AI security strategy. - [Adversarial Threat Vectors and Risk Mitigation for RAG](https://firemountainlabs.com/resources/blog/adversarial-threat-vectors-and-risk-mitigation-for-rag/): Our research on how attackers exploit every stage of a RAG pipeline, from poisoned vector stores to leaked prompts, and the controls that stop them. - [Is AI Security a Distraction?](https://firemountainlabs.com/resources/blog/is-ai-security-a-distraction/): The industry is racing to bolt security onto AI systems that were never designed to be safe. Securing an unsafe system is the wrong place to start. - [AI Safety Scores](https://firemountainlabs.com/resources/blog/ai-safety-scores/): An independent Future of Life Institute assessment graded leading AI companies on safety, and no vendor scored above a C. The vendor's risk becomes yours. ## Company - [About](https://firemountainlabs.com/about/): Fire Mountain Labs is a Service-Disabled Veteran-Owned Small Business helping organizations deploy AI that survives attackers, auditors, and regulators. - [Chris M. Ward](https://firemountainlabs.com/leadership/ceo-chris-m-ward/): Chris M. Ward is CEO of Fire Mountain Labs: U.S. Navy veteran, PECB-certified ISO/IEC 42001 Lead Auditor, coauthor of 26 publications in AI and AI security. - [Dr. Josh Harguess](https://firemountainlabs.com/leadership/cto-dr-josh-harguess/): Dr. Josh Harguess is CTO of Fire Mountain Labs: Ph.D., UT Austin, ISO/IEC 42001 Lead Auditor, former MITRE AI Red Team lead, 70+ publications and 6 patents. - [Contact Us](https://firemountainlabs.com/contact-us/): Get in touch with Fire Mountain Labs about AI red teaming, risk and maturity assessment, governance, ISO/IEC 42001 audit, and training. - [Cookies](https://firemountainlabs.com/cookies/): What Fire Mountain Labs collects when you visit this site: the one analytics tool we use, the cookies it sets, and how to turn it off.