Security & threat model

The 11th-largest theme in the research: 45 of 268 documents, 25 organizations. Decomposed into 6 topics, each with its own issues, evidence and steps.

45documents in the theme
16issues named
66sourced citations
12organizations cited
0sourced statistics

The topics

Each opens a dossier with the same shape: what the state of it is, the issues ranked by how many independent organizations name them - or marked as our own analysis where none does - the disagreements, the numbers, and the concrete steps under each remedy.

Guardrails & the control set

Which controls exist, which are actually switched on, and what they cost to run.

  • The agent is only as safe as the tools it may call, and those were not reviewed 2
  • The control is understood, documented, and switched off where the work happens 2
  • Guardrails have a per-call cost that no business case carries ours

47 documents · 28 organizations · 3 issues · 8 steps

Blast radius & containment

How far a failure or a compromise can reach before something stops it.

  • The containment boundary is a single component nobody treats as load-bearing 2
  • Detection works; the reach available before it fires is the problem 2

46 documents · 28 organizations · 2 issues · 6 steps

Evidence & assurance

What demonstrates a control actually operates, to a board or a reviewer.

  • Nobody can list where the organization is exposed, so assurance has nothing to cover 2
  • The control operates and there is no evidence it operated 1
  • Who checks the account of what happened ours

45 documents · 28 organizations · 3 issues · 9 steps

Exploits & the attack surface

How these systems are actually attacked, and what is new about it.

  • An agent can be turned without any injection at all 3
  • The pressure on the boundary comes from the system you deployed, not an attacker 1
  • The route in is credentials, and the agent multiplies how many exist 1

27 documents · 16 organizations · 3 issues · 9 steps

Ownership & decision rights

Who holds each control, and who may switch a running system off.

  • Cyber risk is ranked in the top three and delegated out of the leadership team 1
  • Who may switch a working system off ours

22 documents · 16 organizations · 2 issues · 6 steps

Identity & credentials for non-human actors

What an agent is allowed to be, and what it is allowed to hold.

  • Agents run on one-time authentication and inherited permissions that cross boundaries 3
  • There is no way to revoke an agent everywhere, immediately 2
  • Nobody can say whose authority an agent acted under 1

18 documents · 14 organizations · 3 issues · 8 steps

Where the sources disagree

No contradictions recorded yet.