Security & threat model
The 11th-largest theme in the research: 45 of 268 documents, 25 organizations. Decomposed into 6 topics, each with its own issues, evidence and steps.
45 documents in the theme
16 issues named
65 sourced citations
12 organizations cited
0 sourced statistics
The topics
Each opens a dossier with the same shape: what the state of it is, the issues ranked by how many independent organizations name them - or marked as our own analysis where none does - the disagreements, the numbers, and the concrete steps under each remedy.
Guardrails & the control set
Which controls exist, which are actually switched on, and what they cost to run.
The agent is only as safe as the tools it may call, and those were not reviewed 2
The control is understood, documented, and switched off where the work happens 2
Guardrails have a per-call cost that no business case carries ours
47 documents · 28 organizations · 3 issues · 8 steps
Blast radius & containment
How far a failure or a compromise can reach before something stops it.
The containment boundary is a single component nobody treats as load-bearing 2
Detection works; the reach available before it fires is the problem 2
46 documents · 28 organizations · 2 issues · 6 steps
Evidence & assurance
What demonstrates a control actually operates, to a board or a reviewer.
Nobody can list where the organization is exposed, so assurance has nothing to cover 2
The control operates and there is no evidence it operated 1
Who checks the account of what happened ours
45 documents · 28 organizations · 3 issues · 9 steps
Exploits & the attack surface
How these systems are actually attacked, and what is new about it.
An agent can be turned without any injection at all 3
The pressure on the boundary comes from the system you deployed, not an attacker 1
The route in is credentials, and the agent multiplies how many exist 1
27 documents · 16 organizations · 3 issues · 9 steps
Ownership & decision rights
Who holds each control, and who may switch a running system off.
Cyber risk is ranked in the top three and delegated out of the leadership team 1
Who may switch a working system off ours
22 documents · 16 organizations · 2 issues · 6 steps
Identity & credentials for non-human actors
What an agent is allowed to be, and what it is allowed to hold.
Agents run on one-time authentication and inherited permissions that cross boundaries 3
There is no way to revoke an agent everywhere, immediately 2
Nobody can say whose authority an agent acted under 1
18 documents · 14 organizations · 3 issues · 8 steps
Where the sources disagree
No contradictions recorded yet.
From the toolkit
Security & threat model — the implementation kit
The whole of Security & threat model, turned into something you can run. A diagnostic that tells you which of these problems you have, and an action plan with every step owned and time-boxed.
A diagnostic you can run in a room 16 questions across 6 areas, each written so a yes or no tells you whether you have that problem. No scoring model to learn.
An action plan that names who does it 46 actions, each carrying a role and a time-box, and every fix states what exists when it is done - so you can tell a fix that landed from one that was attempted.
The same actions, sorted by person An owner map, so one column goes to one person, and a sequence that says what to do first rather than leaving you to guess.
Written for your situation Three editions - listed company, private company or scale-up, and advisory - so the owner names match the room you are actually in.
Yours to use in front of a client Every word is original work. No third-party research is reproduced in it, which is what makes it safe to hand on.
16 diagnostic questions · 46 owned actions · 26 pages · one-off, updates included
Issues were named by hand after reading the documents cited under each one. Consensus counts distinct organizations, not documents, and counts only evidence a human has verified against a located passage.
Every link opens the publishing organization's own page. Summaries and characterisations are written here; no publisher prose is reproduced.