No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Saturday, May 9, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

Many Critical Problems for CISOs in Agentic AI Security

by TheAdviserMagazine
10 months ago
in Market Analysis
Reading Time: 5 mins read
A A
Many Critical Problems for CISOs in Agentic AI Security
Share on FacebookShare on TwitterShare on LInkedIn


A2A and MCP: What They Are

The emerging agentic AI market is experiencing its infrastructure inflection point. Enterprise builders are already getting exhausted by the prospect of hard-coding all of the tools and data an agent needs to use. This hard coding creates fragile systems that can be challenging to make secure and flexible.  Today we are seeing communication and interoperability standards emerge at two foundational layers: intra-agent with the Model Context Protocol (MCP) and inter-agent with Agent-to-Agent (A2A) protocols.

MCP controls how agents manage and share structured memory, task state, and environmental assumptions across sessions and models. A2A protocols specify the rules for inter-agent communication, including negotiation, delegation, and task synchronization. Though MCP and A2A can enable enterprise agent interoperability, they also create new vulnerabilities and challenges in security, performance, and governance.

What They Aren’t

Knowing what A2A and MCP are is just as important to clarify what these protocols aren’t. Some security pros have misinterpreted these each of these protocols to be:

A control plane
A policy engine

These protocols don’t orchestrate agents, they enable interoperation. Think of A2A like RPC or Kafka in a microservices architecture it’s a transport and serialization layer, not a scheduler or a source of truth.

Similarly, MCP isn’t a governance layer. It’s more like a distributed cache or a shared memory abstraction, akin to how systems like Apache Ignite or Memcached provide fast, ephemeral access to state, but don’t enforce business logic or access policy.

If you treat MCP like a control plane, you’ll end up with brittle coupling and security blind spots. One common joke that already exists is that the “S” in MCP stands for security. Hat tip to our colleague Carlos Casanova for the title based on his comment that MCP should stand for “Many Critical Problems.”

The real control plane for agents (when one exists) will likely emerge as a higher-order construct. It will be layered on top of these protocols, with its own lifecycle, observability, and trust models.

As Always, Security Forces Tradeoffs

Security is never free. Security taxes performance, flexibility, and (sometimes) reliability. The same is true for agentic architectures. Modifying the output of an LLM to meet a new security standard might result in significantly higher token use because of a prompt change. In A2A systems, introducing authentication and authorization mirrors adding TLS to microservices. You gain confidentiality and trust at the expense of latency and overhead related to certificate management.

MCP faces similar constraints. Imagine it as a distributed cache or shared state layer used by agents to store and retrieve context. If that context must be signed, versioned, and verified for integrity then suddenly, this resembles a blockchain-light architecture. You gain tamper resistance, but you pay in throughput and latency. Stale or poisoned context can propagate errors across the agent mesh unless strong validation and rollback mechanisms exist.

In scenarios where two agents operate within separate execution environments and collaborate on a task without a shared trust anchor or federated identity, they typically need to 1) negotiate credentials, 2) validate scopes, and 3) establish secure channels. This process is similar to service mesh architectures such as Istio, in which mutual TLS (mTLS) secures communication between pods but introduces additional complexity for routing, observability, and debugging.

MCP Security Flaws Identified

The Model Context Protocol (MCP) is rapidly becoming a standard and critical layer in agentic systems but it’s also emerging as a surface for exploitation. Several CVE’s discovered recently showcase this. In addition,  Trend Micro discovered 492 and Knostic.AI found over 1800 MCP servers exposed to the internet, reminding security leaders of unsecured S3 buckets in AWS in the not so distant past.

Because MCP governs how agents share and retrieve context, it becomes a prime target for context poisoning, impersonation, and unauthorized inference. If an agent can inject misleading or malicious context into the shared memory, it can manipulate downstream behavior similar to how poisoned DNS entries or corrupted configuration maps can destabilize distributed systems.

Worse, many current MCP implementations lack strong guarantees around context provenance. Without cryptographic signatures or verifiable lineage, agents have no way to determine whether a piece of context is authentic, recent, or relevant. This is the equivalent of a distributed system relying on unsigned messages in a gossip protocol. Fast, but far too trusting.

And because MCP often operates beneath the application layer, these flaws are hard to detect and even harder to remediate. There’s no 1) centralized audit trail, 2) no rollback mechanism, and 3) no standard for revocation. In effect, we’re building shared memory for autonomous systems without the isolation or integrity guarantees we take for granted in container orchestration or distributed databases.

Static Security Models Don’t Fit The Needs Of Ephemeral Autonomous Agents

Securing agentic systems will require a redesign of 1) trust 2) identity, and 3) control.  It requires dynamic trust that enables temporary, scoped identities, context-aware permissions, and cryptographically verifiable provenance. Some potential approaches include:

Agentic AI should use just-in-time credentials with clear constraints on use, duration, and scope that are easy to issue, revoke, and fully auditable.
Agentic AI should use root-cause analysis across agentic supply chains including distributed tracing on actions, decisions, and reasoning.

In Agentic Systems Failure Isn’t A Crash…It’s A Cascade

One agent misinterprets context, another acts on flawed assumptions, and a third amplifies the error. By the time a human notices, the trail is cold. That’s why we need a new kind of root cause analysis (RCA) that’s designed for autonomous, distributed decisions.

The system must include full traceability for every agent interaction. Not just the WHAT, but the WHY and HOW. Each decision could carry a cryptographic breadcrumb: a signed reference to the context it used, the agent that provided it, and the logic path it followed.

The Securing Agents And Agentic Gold Rush: Picks And Shovels

Every emerging technology has its infrastructure moment. For the cloud era it was containers, observability, and CI/CD pipelines. For this instance of the AI era, it’s GPUs, vector databases, and fine-tuning frameworks. For agentic systems, the next frontier isn’t just smarter agents, it’s the tooling that makes them secure, testable, and trustworthy.

This is the “picks-and-shovels” phase of the agent economy. The real opportunity lies in building the scaffolding: agent debuggers, context validators, permission brokers, simulation environments, and trust observability layers.

Performance and Capability: Why Testing Comes First

To understand agentic systems, we have to test and trust them (and their supply chains). And that testing must possess the same characteristics of agentic systems. So testing will need the following characteristics: 1) relentless 2) systematic and 3) scalability.

Examples of testing include:

Benchmarking context fidelity
Measuring decision latency
Stress-testing permission boundaries

Making Good Choices Now Sets Us Up For The Future

We’re standing at the edge of a new human hybrid computing paradigm. Agents will do more than execute code. They will make decisions, collaborate, and evolve. The protocols, tests, and security measures we design today will shape how these agents interact, how they’re trusted, and how they’re held accountable.

With that in mind, we need to make a trust a first-class primitive for AI Agents and Agentic AI.

Let’s Connect

Forrester clients who have questions implementing or securing AI agents and Agentic AI can request an inquiry or guidance session with either of us.

See Jeff and Rowan at Technology & Innovation Summit, taking place in Austin, TX from November 2-5 and at Security & Risk Summit, taking place from November 5-7.



Source link

Tags: agenticCISOsCriticalproblemsSecurity
ShareTweetShare
Previous Post

JPMorgan Clients Could Get Crypto-Backed Loans By 2026

Next Post

Israeli institutional investors bet on Teva

Related Posts

edit post
Amazon Opens Its Supply Chain Empire To All — But Is It A Fit For Your Business?

Amazon Opens Its Supply Chain Empire To All — But Is It A Fit For Your Business?

by TheAdviserMagazine
May 8, 2026
0

Amazon’s AWS Playbook: Now Applied To Supply Chain Logistics Per ShipMatrix, in 2025, Amazon surpassed the US Postal Service, FedEx,...

edit post
3 Defensive Dividend Stocks to Weather Market Uncertainty

3 Defensive Dividend Stocks to Weather Market Uncertainty

by TheAdviserMagazine
May 8, 2026
0

Amid renewed market turbulence, investors are turning to time-tested defensive names. These three stocks offer resilient dividends and essential products....

edit post
Extreme Connect 2026: Momentum Depends On Platform ONE And AI

Extreme Connect 2026: Momentum Depends On Platform ONE And AI

by TheAdviserMagazine
May 8, 2026
0

Platform ONE changed the tone at Extreme Connect. The energy felt real — less marketing noise, more actual momentum —...

edit post
What Is POS Data Scrubbing? The Essential Guide for Channel Managers

What Is POS Data Scrubbing? The Essential Guide for Channel Managers

by TheAdviserMagazine
May 8, 2026
0

The global POS software market is projected to reach $32.1 billion in 2026, yet many channel managers are still drowning...

edit post
NFP Preview: Can the US Jobs Market Stay Afloat?

NFP Preview: Can the US Jobs Market Stay Afloat?

by TheAdviserMagazine
May 8, 2026
0

Leading indicators signal a potentially above-consensus read, with headline job growth projected in the 110–150K range — well above the 65K consensus....

edit post
AI Is Everywhere In GTM. Customer Value Isn’t.

AI Is Everywhere In GTM. Customer Value Isn’t.

by TheAdviserMagazine
May 7, 2026
0

At this year’s B2B Summit, one thing was clear: The ground has shifted for go-to-market teams. Leaders know they need...

Next Post
edit post
Israeli institutional investors bet on Teva

Israeli institutional investors bet on Teva

edit post
How I Stopped Wasting Hours Hunting For Real Estate Leads

How I Stopped Wasting Hours Hunting For Real Estate Leads

  • Trending
  • Comments
  • Latest
edit post
Gavin Newsom issues ‘final warning’ amid California’s dire housing crisis — what’s at stake for millions of residents

Gavin Newsom issues ‘final warning’ amid California’s dire housing crisis — what’s at stake for millions of residents

May 3, 2026
edit post
Florida Warning: With Senior SNAP Benefits Averaging 8/Month, Thousands Risk Losing Assistance in 2026

Florida Warning: With Senior SNAP Benefits Averaging $188/Month, Thousands Risk Losing Assistance in 2026

April 27, 2026
edit post
Minnesota Wealth Tax | Intangible Personal Property Tax

Minnesota Wealth Tax | Intangible Personal Property Tax

May 6, 2026
edit post
10 Cheapest High Dividend Stocks With P/E Ratios Under 10

10 Cheapest High Dividend Stocks With P/E Ratios Under 10

April 13, 2026
edit post
Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

April 29, 2026
edit post
NYC Mayor Mamdani knocked Ken Griffin in pied-a-terre tax promo. His firm calls the move ‘shameful’

NYC Mayor Mamdani knocked Ken Griffin in pied-a-terre tax promo. His firm calls the move ‘shameful’

April 23, 2026
edit post
Chime MyPay Cash Advance: 2026 Review

Chime MyPay Cash Advance: 2026 Review

0
edit post
Joyful Health Raises M to Recover the 5B Providers Lose Each Year to Denied and Underpaid Claims – AlleyWatch

Joyful Health Raises $17M to Recover the $125B Providers Lose Each Year to Denied and Underpaid Claims – AlleyWatch

0
edit post
Rhode Island High-Earner Surtax Would Hurt Small Businesses

Rhode Island High-Earner Surtax Would Hurt Small Businesses

0
edit post
Jim Farley Has Promised Cheaper Fords. Here’s What That Means for Investors.

Jim Farley Has Promised Cheaper Fords. Here’s What That Means for Investors.

0
edit post
More Retirees Over 60 Are Being Hit With Unexpected Business Fees

More Retirees Over 60 Are Being Hit With Unexpected Business Fees

0
edit post
Links 5/9/2026 | naked capitalism

Links 5/9/2026 | naked capitalism

0
edit post
Jim Farley Has Promised Cheaper Fords. Here’s What That Means for Investors.

Jim Farley Has Promised Cheaper Fords. Here’s What That Means for Investors.

May 9, 2026
edit post
Sydney Huang Warns AI Bot Collusion Could Spread Before Regulators Respond

Sydney Huang Warns AI Bot Collusion Could Spread Before Regulators Respond

May 9, 2026
edit post
Links 5/9/2026 | naked capitalism

Links 5/9/2026 | naked capitalism

May 9, 2026
edit post
F&O Talk: Nifty bulls indecisive but opportunities in broader markets. Sudeep Shah’s strategy on Voltas, Tejas and 4 more stocks

F&O Talk: Nifty bulls indecisive but opportunities in broader markets. Sudeep Shah’s strategy on Voltas, Tejas and 4 more stocks

May 9, 2026
edit post
Alx Oncology outlines interim ASPEN-09 data from ~80 patients by mid-2027 as CD47-high cohort shows 22-month median PFS (NASDAQ:ALXO)

Alx Oncology outlines interim ASPEN-09 data from ~80 patients by mid-2027 as CD47-high cohort shows 22-month median PFS (NASDAQ:ALXO)

May 9, 2026
edit post
Why GameStop’s bid for eBay echoes one of the worst business deals of all time

Why GameStop’s bid for eBay echoes one of the worst business deals of all time

May 9, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Jim Farley Has Promised Cheaper Fords. Here’s What That Means for Investors.
  • Sydney Huang Warns AI Bot Collusion Could Spread Before Regulators Respond
  • Links 5/9/2026 | naked capitalism
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.