security controls

Threat Modeling AI Applications

The post explains how to adapt threat modeling for AI systems, which differ from traditional software in that they produce probabilistic outputs, follow instructions, and have expanded attack surfaces. It recommends explicitly defining what assets the system must protect, understanding real usage patterns, and identifying risks such as prompt injection, misuse of tools, data integrity failures, and harmful outputs. It concludes that AI threat modeling requires structured analysis early in design to assess likelihood and impact and inform architectural mitigations. 

https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/

Detecting and Mitigating Common Agent Misconfigurations

The article emphasizes the need to detect and mitigate common agent misconfigurations to enhance security. Agents are increasingly integrated into business workflows, but misconfigurations pose risks, including unauthorized access, data leaks, and unmonitored legacy systems. Key mitigation strategies involve using Copilot Studio for authentication, implementing data policies, conducting regular audits on dormant connections, and restricting actions based on user roles. Overall, effective management and monitoring of agents are crucial for maintaining a secure operational environment.

https://www.microsoft.com/en-us/security/blog/2026/02/12/copilot-studio-agent-security-top-10-risks-detect-prevent/

Rising Identity Complexity: How CISOs Can Prevent It From Becoming an Attacker’s Roadmap

The identity surface has expanded dramatically, encompassing employees, contractors, machines, and cloud workloads, making identity management a critical security concern. IAM has evolved from an administrative utility to a proactive defense layer, integrating with security operations to detect and respond to identity-based threats. A threat-aware IAM strategy focuses on continuous posture assessment, attack path analysis, and automated mitigation to protect against credential misuse and privilege escalation.

https://thenewstack.io/ciso-identity-complexity-strategy/

AI Is Spreading Faster Than Companies Can Secure It, CISO Survey Finds

AI adoption is outpacing security measures, per a Pentera survey of 300 U.S. CISOs. Key findings: 67% lack visibility into AI usage, 44% report lagging AI security, and major challenges include expertise shortages and reliance on outdated security controls. Despite funding for AI security, it lacks dedicated budgets, highlighting significant gaps in securing evolving AI systems amidst complex IT environments.

https://www.prnewswire.com/il/news-releases/ai-is-spreading-faster-than-companies-can-secure-it-ciso-survey-finds-302691361.html

Data Minimization Is Still an Underrated Security Control

Data minimization is an underrated security control that reduces the volume of sensitive data, thereby decreasing the impact of breaches and improving security operations. Despite organizations claiming to practice data minimization, the sheer volume of data often outpaces governance capabilities, thereby increasing risk. To effectively implement data minimization, organizations must challenge the “speculative” analytics mindset, audit data propagation, and automate retention processes.

https://www.databreachtoday.com/blogs/data-minimization-still-underrated-security-control-p-4049

Is Microsoft 365 a Compliant EDRMS?

Microsoft 365 can be used as an EDRMS if it complies with the Managing Digital Records in Systems Standard and the Minimum Recordkeeping Metadata Requirements Standard. Agencies must ensure information assets are protected, metadata is created, and information is accessible for the required duration. If M365 cannot be configured to meet these standards, integration with an EDRMS or saving information assets in an EDRMS is recommended.

https://archives.sa.gov.au/managing-information/Information-management/storing-information-assets/-is-microsoft-365-a-compliant-edrmsbusiness-system

The Hidden Cybersecurity Cost Of ‘Just-In-Case’ Decisions

Organizations often accept risks unknowingly through “just-in-case” decisions, granting data access and keeping permissions active to avoid disruption. These decisions, while seemingly responsible, accumulate over time and create a larger attack surface, increasing the risk of security incidents. To mitigate this, organizations should implement practices like removing dormant accounts, setting expiration dates for temporary access, and treating access reviews as risk assessments.

https://www.forbes.com/councils/forbestechcouncil/2026/02/04/the-hidden-cybersecurity-cost-of-just-in-case-decisions/

75% of Organisations Have Gaps in Core Security Controls, Research Finds

75% of organizations lack core security controls, with insufficient MFA, endpoint detection, and policy management. This results in overlapping exposures and significant risk, as seen in recent research by Nagomi Security. Misconfigurations are rapidly increasing exposure, and vulnerabilities are not the only concern. While vulnerability management is strong, identity and endpoint controls lag, leaving many assets unprotected. Progress should focus on eliminating high-impact exposure conditions rather than siloed metrics.

https://www.itsecurityguru.org/2026/01/29/75-of-organisations-have-gaps-in-core-security-controls-research-finds/

Аgentic AI Security Measures Based on the OWASP ASI Top 10

The OWASP Foundation released a playbook outlining the top 10 risks of deploying autonomous AI agents, including goal hijacking, tool misuse, and privilege abuse. These risks arise from the agents’ ability to make decisions and process data without human oversight. Mitigation strategies include enforcing least autonomy and privilege, using short-lived credentials, and requiring human confirmation for critical actions.

https://www.kaspersky.com/blog/top-agentic-ai-risks-2026/55184/

Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents

AI agents boost productivity by automating tasks, but their rapid deployment complicates accountability, creating security risks. They bypass traditional access models, accumulating broad permissions without clear ownership. Three types of agents exist: personal (user-owned, low risk), third-party (vendor-owned, moderate risk), and organizational (shared, high risk). Organizations must rethink risk management, establish clear ownership, and map user-agent interactions to avoid authorization bypass problems. Unmanaged AI agents represent significant risks due to their autonomous nature and unclear responsibilities.

https://thehackernews.com/2026/01/who-approved-this-agent-rethinking.html

Scroll to Top