Why Do You Trust Your AI Agent?

Threat Talks infographic

Find Threat Talks on

Your AI Agents Have Every Privilege You Do

Ten years after it shipped, NIST tore open its own Cybersecurity Framework and added a function that didn’t exist before: Govern. The original CSF was built in 2014 for critical infrastructure operators. A decade later, hospitals, school districts, and five-person startups with no CISO were running on the same framework, and NIST had to decide what to do about it.

Amy Mahn, IT Standards Advisor at NIST, and Daniel Eliot, Lead for Small Business Engagement at NIST’s Applied Cybersecurity Division, join Lieuwe Jan Koning, Co-founder and CTO at ON2IT, to explain how a multi-year public process, more than 4,000 workshop participants from 100 countries, and over 3,000 individual comments reshaped the framework used by more organizations than any other in cybersecurity.

What you’ll learn

  • A new Govern function. Cybersecurity risk now connects directly to enterprise risk and the board.
  • Technology agnostic, vendor agnostic. NIST calls this the reason CSF is so widely adopted.
  • From PDF to platform. Quick start guides and a searchable CSF 2.0 tool replace the static document.

Your cybersecurity experts

Lieuwe Jan Koning

Co-Founder and CTO
ON2IT

Rob Maas

Rob Maas

Field CTO ON2IT

Episode details

Rob’s framing for the core risk is the one to take to a leadership meeting. Humans hold “just in case” privileges, the broad access we collect to do our jobs, kept in check by judgment and the knowledge that we can be held accountable. An agent has neither. Give it an intent and it will use every privilege attached to its identity to get there, the way a worm uses access it was never meant to have, except an agent is pursuing a goal rather than running static code you can detect. The fix starts with treating agents as non-human identities: scope their privileges tightly, issue them just in time, keep them short-lived, and rotate them so a token that leaks to a cloud provider cannot be replayed forever.

From there the conversation walks the pillars. On devices, lock down the execution environment the agent runs in, a VM, a container, or serverless, so it cannot touch files it was never meant to see. On the network, identity-based segmentation does the heavy lifting: an agent working with CRM data should have no path to the financial system, and its access to API servers, MCP tooling, and marketplace skills should be denied by default and allowed only where genuinely needed. The recurring theme is that the agent is both the user and the application at once, which is why a strict allow-list of the tools and MCP servers it may call matters more than any single perimeter control.

The hard pillars are applications and data, and Rob is honest that the tooling is not there yet. Building the allow-list is difficult, enforcing it is harder, and there is no AI firewall that solves this generically today. Data is harder still, because everything in AI is data-driven: prompts, retrieval systems, and documents all flow to the model, and prompt injection means even your controls can be subverted. His cautious optimism rests on observability. Unlike a human mind, an agent’s calls can be logged and inspected, so if you capture what agents are doing, you can at least see when one goes off course.

What is missing from the classic frameworks is the agent-specific layer: behavior analytics tuned to machine speed, detection for “intention drift” when an agent strays from its original goal, and above all a human in the loop with a real kill switch for critical decisions. The closing advice is pragmatic. Embrace AI, because the alternative is falling behind, but start by getting a clear overview of every agent and MCP server in use and the access each one holds. For most organizations that visibility is now a CISO responsibility, whether or not it eventually becomes a dedicated AI officer’s job.

Threat Talks infographic

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

4 + 3 =

Christmas Hacker