
Unlocking the Secrets of Enterprise Agentic Security
Let’s dive into the fascinating world of enterprise agentic security. Visa’s president of technology, Rajat Taneja, recently shared how Anthropic’s Mythos was aimed at Visa’s payment network, uncovering minor weaknesses and open-sourcing the harness that controlled the hunt for vulnerabilities.
Many enterprises struggle to achieve the same level of engineering depth needed to address security issues effectively. Shockingly, over half of enterprises have experienced a security incident or near-miss. While 65% enforce agent permissions at runtime, only 18% isolate their highest-risk agents, and a mere 8% combine enforcement with isolation.
Relying solely on provider-native controls for agentic security further widens the gap. Research has shown that 92% of enterprises default to using hyperscalers and AI platform providers as their primary security layer.
Discrepancy Between Satisfaction and Incident Data
The research reveals an interesting trend where enterprises tend to rate familiar tools higher, even if they have failed in the past. Surprisingly, enterprises that have experienced security incidents rate their tools higher than those that haven’t.
Furthermore, the data shows that enterprises are quick to trust tools that prevent breaches, even if they have never been tested in action. This rush to trust new tools that identify and prevent breaches highlights the evolving landscape of agentic security.
It’s essential to recognize the importance of identity and isolation as complementary strategies rather than substitutes. Enterprises must focus on building a robust, layered security approach to effectively combat agentic AI-based attacks.
Provider Lock-in and Future Plans
Provider-native platforms have become increasingly popular, with a significant majority of enterprises naming them as their primary security layer. However, despite high satisfaction levels, a majority of enterprises plan to replace their tools within the next year.
Interestingly, organizations closest to security threats are the least confident about their capabilities. The data suggests a growing need for a more comprehensive approach to agentic security.
Conclusion
Enterprise agentic security is a complex and evolving field that requires a strategic and proactive approach. By understanding the key trends and challenges highlighted in the research, enterprises can better prepare themselves to tackle the growing threats in the digital landscape.
