Logo
Cybersecurity

AI Agents Change What Security Teams Need to Know

An AI system that recommends an action creates one kind of risk. An AI system that can execute it changes the job.

ITSEC AsiaITSEC Asia
|
Sep 18, 2026
AI Agents Change What Security Teams Need to Know

NIST is building an AI agent workflow for one of cybersecurity’s most widely used public resources.

On 17 September, its Information Technology Laboratory presented work on an agentic workflow designed to help enrich vulnerability information in the National Vulnerability Database. NIST says the project is intended to help the NVD cope with the increasing scale and complexity of disclosed vulnerabilities, and the webinar covered its architecture, implementation issues and early results.

The project illustrates a broader change.

AI is moving from producing information toward performing multi-step tasks. NIST describes AI agents as systems capable of autonomous actions that can interact with external systems and internal data.

For cybersecurity professionals, that means another layer of skills is arriving.

Security Has to Follow the Action

A conventional AI application might receive a prompt and return an answer. An agent may have access to tools, data and permissions that allow it to continue working.

That changes the questions a security professional needs to ask.

  • What systems can the agent access?
  • Which actions can it perform without approval?
  • What identity and permissions does it use?
  • How is sensitive context stored between tasks?
  • Can an untrusted input alter what the agent does next?
  • What evidence is recorded when the agent takes an action?
  • Where should a human be required to intervene?

ITU’s September workshop on secure agentic AI focused on precisely this territory. Its agenda covered security and trust challenges, risk management mechanisms, security frameworks and trustworthy evaluation methods for agentic systems.

The security boundary is no longer simply around a model. It can stretch across the entire chain of actions the model is allowed to initiate.

AI Security Needs People Who Understand Workflows

That creates an interesting workforce problem.

Someone testing an agentic system needs enough AI knowledge to understand how the agent reasons and uses context, but also familiar cybersecurity skills around identity, access control, application security, data protection, logging and testing.

They also need to think in sequences.

Suppose an agent reads an email, retrieves a document, updates an internal system and sends a response. Each individual action may be permitted. The combination can still create risk.

A useful security assessment therefore needs to examine what the agent can do across the full workflow, including what happens when instructions conflict or information from one step contaminates the next.

The red team question becomes less “Can I make the model say something strange?” and more “Can I make this system do something it shouldn’t?”

That’s a considerably more interesting afternoon.

Train Against the Workflow

Agentic AI security lends itself to practical training.

Give learners a simulated agent connected to several tools. Let them map its permissions, inspect the data it can reach and test what happens when it receives misleading instructions. Then ask them to design controls without making the system useless.

The exercise combines AI understanding with familiar cybersecurity judgment.

That kind of hands-on work fits naturally with ITSEC Cyber & AI Academy, where cybersecurity and AI skills can be practised together through scenarios that reflect how systems are actually deployed and operated.

Organizations won’t need every cybersecurity professional to become an AI researcher.

They will need people who can look at an autonomous workflow and know where to ask uncomfortable questions.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: AI Agent Enrichment Workflow at the National Vulnerability Database, 17 September 2026 · ITU: Advancing Standardization for Secure Agentic AI, 7 September 2026 · NIST: AI Agent Standards Initiative

Share this post

You may also like

Think Your System Is Secure? Penetration Testing Can Prove It
Cybersecurity

Think Your System Is Secure? Penetration Testing Can Prove It

INTRODUCTION Today, almost every organization relies on digital systems to run daily operations, from websites and cloud applications to payment systems and internal databases.  However, as digital infrastructure grows, so do cybersecurity risks. Attackers constantly look for vulnerabilities in applications, networks, and systems that they can exploit to gain unauthorized access or steal sensitive data (Cloudflare, 2024). Because of this growing threat landscape, organizations need ways to test their defenses before real attackers attempt to breach them. One of the most effective methods is penetration testing, often called pen testing, where cybersecurity professionals simulate attacks to identify security weaknesses before malicious actors do (IBM, 2024). In simple terms, penetration testing is authorized hacking designed to improve security rather than cause damage. Source: Cloudflare.com [https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/], ibm.com [https://www.ibm.com/think/topics/penetration-testing] WHAT IS PENETRATION TESTING? Penetration testing is a cybersecurity assessment where security experts simulate cyberattacks on systems to identify vulnerabilities that attackers could exploit. These experts that are often known as penetration testers or ethical hackers use techniques similar to real attackers, but with permission from the organization and with the goal

ITSEC AsiaITSEC Asia
|
Apr 02, 2026 6 minutes read
Cybersecurity Training Needs More Room for Failure
Cybersecurity

Cybersecurity Training Needs More Room for Failure

A cybersecurity exercise where everything goes according to plan is wonderfully reassuring. It may also be slightly suspicious. Real incidents rarely arrive with tidy instructions. An alert can look harmless until it isn’t. Evidence can contradict itself. Someone makes an assumption, spends 20 minutes following it and discovers they were looking in entirely the wrong place. That messy part of cybersecurity deserves a bigger role in how people are trained. NIST’s National Initiative for Cybersecurity Education (NICE) is putting that idea directly into its workforce discussion. Its upcoming September session on preparing students for cyber careers focuses on realism-based training, including how controlled failure can become useful workforce data rather than something educators simply mark wrong. That’s a useful distinction. A score tells you whether someone found the answer. Watching how they reached it tells you much more. A WRONG ANSWER CAN REVEAL THE REAL SKILLS GAP Imagine two SOC trainees investigating the same suspicious activity. Both eventually identify the threat. One gets there systematically. The other clicks through five theories, misses a

ITSEC AsiaITSEC Asia
|
Sep 04, 2026 3 minutes read
How IoT Devices Are Expanding the Cybersecurity Attack Surface
Cybersecurity

How IoT Devices Are Expanding the Cybersecurity Attack Surface

INTRODUCTION When people hear “IoT security, [https://itsec.asia/services/ot-ics-cybersecurity]” they often assume it’s something only IT teams need to worry about. In reality, IoT security affects everyday users, households, and businesses alike.* From smart home devices to office surveillance systems, connected devices are now part of critical daily operations. The more devices we connect, the wider the potential attack surface becomes. Here’s the part no one really talks about: Many IoT environments are deployed quickly for convenience, not necessarily designed with security as the top priority. It’s not negligence. It’s just how fast technology moves. Source: aciano.net [https://aciano.net/blog/iot-security-risks/], cio.com [https://www.cio.com/article/3990581/iot-security-challenges-and-best-practices-for-a-hyperconnected-world.html?] THE IOT LANDSCAPE NOWADAYS Security used to focus on protecting networks with firewalls and perimeter defenses. Today, attackers are shifting their focus to easier targets: user credentials, weak device authentication, misconfigured cloud dashboards, and unpatched firmware.  Today, attackers are more interested in: * User credentials * Weak device authentication * Misconfigured cloud dashboards * Unpatched firmware IoT devices often rely on cloud platforms for monitoring, analytics, and control. That means IoT security is no longer just about the

ITSEC AsiaITSEC Asia
|
Mar 06, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe