General Information

What is the mission of Kinfolk LLC? Our mission is to empower small and mid-sized organizations with actionable risk insights to identify, assess, and mitigate cyber threats. We focus on simplifying cybersecurity risk so you can focus on growing your business.

Who leads the Kinfolk team? The firm was founded by Piyali Das, a cyber risk leader with two decades of experience driving enterprise-wide technology and cyber risk initiatives. Piyali holds an MS in Information Technology and Cybersecurity and maintains several industry-leading credentials, including CRISC, CCSK, CCAK, and PMP.

AI Security Risk & Compliance

Do you provide risk assessments for Artificial Intelligence (AI) and Machine Learning (ML)? Yes. Emerging technologies introduce unique vulnerabilities, and ignoring AI risk can leave your organization exposed. We specialize in proactive AI security and innovation, leveraging a background in defining cutting-edge Risk Assessment Frameworks specifically for AI/ML environments.

What is “Shadow AI,” and why is it a significant risk for our business? “Shadow AI” occurs when employees use unauthorized public AI tools (like public chatbots or image generators) to assist with their daily tasks without IT or security approval. The primary danger is data leakage: pasting sensitive company data, proprietary source code, or confidential customer information into public AI models often means that data is absorbed into the vendor’s training model, making it retrievable by outsiders and violating privacy compliance.

How do you evaluate AI vendors during a risk assessment? When vetting third-party AI solutions, we move past generic software checklists to evaluate how the AI operates. Our assessments focus on three core areas:

  1. Data Governance & Privacy: Where is your data stored, who owns the outputs, and is your data being used to train the vendor’s public models?
  2. Model Security: How does the vendor protect against specialized AI vulnerabilities like prompt injection, data poisoning, and model inversion?
  3. Algorithmic Bias & Transparency: Does the tool provide clear documentation on its decision-making parameters to prevent discriminatory or inaccurate outputs?

What is the purpose of an AI Acceptable Use Policy, and do we need one? Yes, every organization using digital tools needs one today. An AI Acceptable Use Policy establishes clear boundaries for your employees regarding which AI tools are approved, what types of data are strictly prohibited from being inputted, and how AI-generated outputs must be human-verified for accuracy before use. We provide ready-to-deploy policies to help you establish these guidelines immediately.

Can you help us build a repeatable framework for managing AI risks? Absolutely. Grounded in enterprise risk framework innovation, we provide businesses with a structured approach to mapping out AI discovery models, assessing exposure paths, and scaling an AI governance program. This ensures your team can confidently adopt secure, agentic, and automated AI technologies at machine speed without adding permanent headcount or breaking your operational workflows.

What is “Agentic AI,” and how does it change our risk profile? Traditional AI typically generates content (text or images) when prompted, but Agentic AI is designed to take autonomous actions—such as accessing your email, managing calendars, or interacting with other business applications—to complete complex tasks. This shift from “generative” to “agentic” means that a single security oversight could allow an AI agent to perform unauthorized actions across your entire digital ecosystem.

How do you secure AI agents that have “Read/Write” access to our systems? Securing autonomous agents requires moving beyond simple data privacy to a “Least Privilege” model for AI. We help you establish technical guardrails that limit exactly what an AI agent can see and do, ensuring it only has the minimum access necessary to perform its specific task. We also focus on monitoring “agent-to-agent” communications to prevent one compromised tool from triggering a chain reaction of security failures.

What are the specific risks of “Prompt Injection” in automated AI workflows? In an agentic environment, a “prompt injection” attack occurs when a malicious actor provides an input that tricks the AI into ignoring its original instructions. For example, if an AI agent is processing customer emails, a hidden command in an incoming message could trick the agent into forwarding sensitive files to an external address. We help you implement validation and filtering layers to prevent your AI from being “hijacked” by malicious external prompts.

Do we need a different risk assessment for AI agents compared to standard software? Yes. While standard software is predictable, AI agents can be non-deterministic, meaning they may solve the same problem in different ways each time. Our specialized assessments focus on “Output Integrity” and “Human-in-the-loop” (HITL) checkpoints, ensuring that while the AI operates at machine speed, a human still has the final say on high-stakes actions.

What compliance frameworks or certifications can you help our organization achieve? We have extensive, hands-on experience establishing robust risk programs and preparing organizations for rigorous audits. We provide audit-ready compliance framework support for:

  • ISO 27001
  • SOC2 Type 2
  • NIST
  • PCI-DSS
  • SOX

Third-Party & Supply Chain Risk

Do you offer vendor, third-party, or supply chain risk assessments? Yes. Your security is only as strong as the weakest link in your vendor ecosystem, and unprotected critical data often slips through third-party gaps. Backed by deep enterprise experience managing third-party risk at organizations like Capital One, we help you evaluate, monitor, and mitigate the risks posed by your vendors, software providers, and supply chain partners to ensure your data stays secure.

Here are some excellent additions to your FAQ draft based on your June 1, 2026, Weekly Kinfolk Newsletter article regarding supply chain intrusions and vendor vulnerabilities.

Why are attackers targeting our third-party vendors instead of our internal network? As small and mid-sized businesses tighten their internal defenses (like enforcing MFA and securing endpoints), attackers adapt. Instead of attempting to break through your front door, they look for supply chain intrusions—slipping through the less-secure “back window” of smaller, trusted vendors who already have authorized access to your data or systems.

If a vendor loses our data, who is held responsible? From a Governance, Risk, and Compliance (GRC) perspective, you cannot outsource your legal and ethical responsibilities. Under modern compliance frameworks like ISO 27001 and SOC 2, if a third-party vendor suffers a breach that compromises your client information, your business faces the regulatory fallout, reputational damage, and potential legal liabilities.

What key questions should we ask vendors before signing a contract? When performing a vendor sanity check, your organization should mandate three non-negotiable questions:

  1. “Can you provide your latest SOC 2 Type II report, ISO 27001 certification, or a documented security assessment?” (Do not accept verbal assurances; insist on independent validation).
  2. “How is our data isolated from your other clients, and what encryption standards are used at rest and in transit?”
  3. “What is your formal notification timeline if you experience a security incident?” (Your contract should explicitly require notification within 24 to 72 hours so your internal team can take protective action).

How does Kinfolk help us establish business continuity during a vendor outage? Operational downtime is a massive risk if a critical Software-as-a-Service (SaaS) provider or IT help desk goes down. We help your business design concrete business continuity plans so you know exactly how your organization will function if a vital third-party tool vanishes overnight.

Note: For the original reference file mentioned earlier, these concepts align directly with the foundational goals outlined in “Mason SBDC Copy V2 of Introducing Kinfolk v2 – Google Slides.pdf” to address gaps in resources and protect critical data across all business operational boundaries.

Working With Us

How is Kinfolk different from other cybersecurity firms? We offer a business-first approach that avoids unnecessary technical jargon and reactive “quick fixes”. We focus on long-term security roadmaps, business-focused risk assessments, and executive-ready reporting, giving you startup-level agility backed by senior enterprise expertise.

What kind of engagement models do you offer? We offer flexible, right-sized ways to work with your organization:

  • Ongoing Subscription Model: Ongoing, tiered pricing plans designed specifically to scale with small and medium businesses.
  • Fixed-Fee Security Risk Assessments: A comprehensive, tailored evaluation of your organization’s specific threat landscape.
  • Security Compliance Readiness Projects: Flexible support designed to adapt and evolve as your regulatory requirements grow.

Are your services insured? Yes. All service engagements are fully backed by Kinfolk business insurance, providing comprehensive coverage for professional liability and Errors and Omissions (E&O) risks.

Get In Touch

How can we get started?

We make it simple to kickstart your security journey. You can reach out to us directly or schedule a consultation online:

Click on the Logo to go back to Home Page