
Maria Singh
Vice President, The AI Collective; Founder, AISecurityLab.ai
Maria is a cybersecurity and AI strategy leader, Vice President of The AI Collective and founder of AISecurityLab.ai, who at T-Mobile helped cut critical vulnerabilities by 90% across more than 75,000 endpoints. Our posts together cover the security assumptions under AI programmes that are ageing fastest, from the cryptography AI systems rely on to how organisations decide which vulnerabilities to leave open.
About Maria
Maria Singh is Vice President of The AI Collective, where she oversees more than 42 chapters across Southeast Asia, India and East Asia, including Taiwan, South Korea and Japan. She previously led the region as APAC Regional Director, and she appoints chapter leads, approves new chapters and secures the partnerships that fund regional programmes. She also founded AISecurityLab.ai, Asterchat.ai and QaiTX, which advise smaller firms on AI strategy, cyber resilience and governance, and she has advised SMEs on AI adoption and workforce readiness through the Singapore AI Association's AI Discovery Clinics.
At T-Mobile she covered vulnerability and risk management for 75,000 laptops and more than 1,000 servers. Working with the IT Endpoint Engineering team, she helped reduce critical vulnerabilities by 90%. She wrote Python scripts to find devices missing from vulnerability scans and to flag missing patches, and coordinated risk-ranked remediation through Tenable and ServiceNow. At EnterpriseKC and the Heartland Cyber Range she led cybersecurity content strategy and lab development aligned to the NIST NICE workforce roles.
Her current research is on AI assurance for smaller firms: a Master's capstone building a screening approach for the SAIA AI Discovery Clinic, and an SME AI Policy Builder that turns a firm's answers into a baseline AI policy and staff guide. She is the author of Red Queen Cipher (2026), a book on AI and quantum security, and writes Red Queen Signal on cybersecurity, AI risk and post-quantum readiness. She is based between Singapore and Kansas City.
- Expertise
- Vulnerability prioritisation · Remediation coordination · AI workflow security · Prompt injection and OWASP LLM risks · Human oversight · AI governance (NIST AI RMF, NIST CSF) · Post-quantum readiness · Risk communication · Python scripting
- Certifications
- GIAC Security Essentials (GSEC); CompTIA Security+; Certified ScrumMaster; Marketing Strategy Certificate, Cornell University; Management Accelerator, McKinsey; Business Leadership Certificate, University of Washington Bothell
- Board service
- Founding member, OASec Conference (2026); board member, ISACA Kansas City Chapter (2025 to 2026); past president, Women in Security Kansas City; board, Kansas City AI Club (2025); mentor, Women in CyberSecurity (WiCyS); cybersecurity advisor, Brilliancy Quantum Brands; volunteer, OWASP Singapore (2026); participant, R Street post-quantum cryptography policy working group (2026)
- Speaking
- DEF CON Singapore (2026), agent security and trust boundaries; AIMX Singapore (2026), fireside on guardrails for AI adoption; SecureWorld Kansas City (2025), speaker on cybersecurity workforce development and moderator of a panel on AI in cybersecurity
- Recognition
- OCA Corporate Achievement Award (2022), for professional achievement and service to Asian American communities

Red Queen Cipher
Winning the Eternal Arms Race in Quantum AI Security
Red Queen Cipher looks at what happens to security when AI and quantum computing advance together, and why static defences stop holding once attackers automate and computing power keeps rising. Maria sets out the practical responses: post-quantum migration planning, cryptographic agility, stronger governance, secure-by-design engineering and adaptive approaches to AI risk. Her argument is that organisations need to start building that resilience now, before the threat arrives.
Get the book on Amazon →Articles with Maria

The Vulnerability Didn't Change. The Attacker Did.
Most organisations defer some patches and record the decision as an accepted risk. Those decisions assumed that turning a patch into a working exploit took skill and weeks. Anthropic's 2026 evaluations show a model doing it in under an hour for about $2,000 per exploit, and its September threat report describes criminals running exploit research around the clock. Here is how to rewrite the risk register.
Read article →
What Quantum Computing Means for the Encryption Behind Your AI
No quantum computer can break today's public-key encryption yet, but the estimates of what it would take fell twentyfold in a year, and Google now targets 2029 for its own migration. AI systems rest on the same RSA and elliptic-curve cryptography: the links that carry training data, the signatures that vouch for models and the tokens that identify agents. Here is what breaks, what does not, and what boards should do now.
Read article →
