Logo
Cybersecurity

AI Agents Change What Security Teams Need to Know

An AI system that recommends an action creates one kind of risk. An AI system that can execute it changes the job.

ITSEC AsiaITSEC Asia
|
Sep 18, 2026
AI Agents Change What Security Teams Need to Know

NIST is building an AI agent workflow for one of cybersecurity’s most widely used public resources.

On 17 September, its Information Technology Laboratory presented work on an agentic workflow designed to help enrich vulnerability information in the National Vulnerability Database. NIST says the project is intended to help the NVD cope with the increasing scale and complexity of disclosed vulnerabilities, and the webinar covered its architecture, implementation issues and early results.

The project illustrates a broader change.

AI is moving from producing information toward performing multi-step tasks. NIST describes AI agents as systems capable of autonomous actions that can interact with external systems and internal data.

For cybersecurity professionals, that means another layer of skills is arriving.

Security Has to Follow the Action

A conventional AI application might receive a prompt and return an answer. An agent may have access to tools, data and permissions that allow it to continue working.

That changes the questions a security professional needs to ask.

  • What systems can the agent access?
  • Which actions can it perform without approval?
  • What identity and permissions does it use?
  • How is sensitive context stored between tasks?
  • Can an untrusted input alter what the agent does next?
  • What evidence is recorded when the agent takes an action?
  • Where should a human be required to intervene?

ITU’s September workshop on secure agentic AI focused on precisely this territory. Its agenda covered security and trust challenges, risk management mechanisms, security frameworks and trustworthy evaluation methods for agentic systems.

The security boundary is no longer simply around a model. It can stretch across the entire chain of actions the model is allowed to initiate.

AI Security Needs People Who Understand Workflows

That creates an interesting workforce problem.

Someone testing an agentic system needs enough AI knowledge to understand how the agent reasons and uses context, but also familiar cybersecurity skills around identity, access control, application security, data protection, logging and testing.

They also need to think in sequences.

Suppose an agent reads an email, retrieves a document, updates an internal system and sends a response. Each individual action may be permitted. The combination can still create risk.

A useful security assessment therefore needs to examine what the agent can do across the full workflow, including what happens when instructions conflict or information from one step contaminates the next.

The red team question becomes less “Can I make the model say something strange?” and more “Can I make this system do something it shouldn’t?”

That’s a considerably more interesting afternoon.

Train Against the Workflow

Agentic AI security lends itself to practical training.

Give learners a simulated agent connected to several tools. Let them map its permissions, inspect the data it can reach and test what happens when it receives misleading instructions. Then ask them to design controls without making the system useless.

The exercise combines AI understanding with familiar cybersecurity judgment.

That kind of hands-on work fits naturally with ITSEC Cyber & AI Academy, where cybersecurity and AI skills can be practised together through scenarios that reflect how systems are actually deployed and operated.

Organizations won’t need every cybersecurity professional to become an AI researcher.

They will need people who can look at an autonomous workflow and know where to ask uncomfortable questions.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: AI Agent Enrichment Workflow at the National Vulnerability Database, 17 September 2026 · ITU: Advancing Standardization for Secure Agentic AI, 7 September 2026 · NIST: AI Agent Standards Initiative

Share this post

You may also like

Is Using a VPN Really Safe? Here’s the Reality Check.
Cybersecurity

Is Using a VPN Really Safe? Here’s the Reality Check.

INTRODUCTION Today, almost everything we do happens online, from working and studying to shopping and banking. While the internet makes life easier, it also comes with certain risks, especially when it comes to privacy and data security. Many people connect to public Wi-Fi in places like cafés, airports, or hotels without realizing that these networks may not always be secure. In some cases, attackers can monitor or intercept data that travels through these connections. This is where VPN apps become useful. A VPN app helps create a safer internet connection by protecting your data and hiding your online identity. Even if you are using an open network, a VPN can help keep your activity more private. This article will explain what a VPN app is, how it works, and why it has become an important tool for safer internet use. Source: pr.norton.com [https://pr.norton.com/blog/privacy/what-is-a-vpn?utm_], security.org [https://www.security.org/vpn/?utm_], fortinet.com [https://www.fortinet.com/resources/cyberglossary/vpn-wifi?utm_] WHAT IS A VPN APP? A VPN app is a tool that helps protect your internet connection and online activity. VPN stands for Virtual Private Network.

ITSEC AsiaITSEC Asia
|
Mar 13, 2026 6 minutes read
The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore
Cybersecurity

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

As businesses, government institutions and other organizations accelerate digital adoption, the need for cybersecurity professionals continues to grow. At the same time, the skills required to protect increasingly complex environments are changing. Cloud security, threat intelligence, security operations, penetration testing and artificial intelligence are becoming part of the modern cybersecurity skill set. The gap between available talent and the capabilities organizations actually need is becoming harder to ignore. CYBERSECURITY NEEDS ARE CHANGING FASTER THAN SKILLS The global cybersecurity workforce is facing a skills shortage alongside its broader talent challenge. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals surveyed reported at least one skills need within their teams, while 59% described those needs as critical or significant. The study also found that 88% had experienced at least one significant cybersecurity consequence because of skills shortages. For Indonesia, the implication is clear: building a cybersecurity team isn't simply about filling vacancies. Organizations need professionals who can apply their knowledge to real security problems. The skills required are also changing rapidly. The World

ITSEC AsiaITSEC Asia
|
Agt 24, 2026 5 minutes read
Data Protection and Cybersecurity Laws in the Asia-Pacific Region
Cybersecurity

Data Protection and Cybersecurity Laws in the Asia-Pacific Region

Info

Apart from sales and trade, the majority of internet users utilize it for socializing and interacting with peers online. For instance, there were 3.8 billion social media users in January 2020, which represents a 9 percent increase from the previous year. The advancements in internet and related communication technologies enable easy access to information from anywhere on the planet. For example, an online merchant operating in Thailand can offer their services to customers residing in the European Union and the United States. In order to address the dissemination of personal information, including financial, medical, and other types of personal data, worldwide through the internet, appropriate legal regulations need to be established to protect the personal data of citizens and the digital assets of organizations while working online. Following the implementation of the General Data Protection Regulation (GDPR) in the European Union (which came into effect on May 25, 2018), which governs data protection and privacy in EU countries and regulates the transfer of personal data outside the European Union and

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 11 minutes read

Receive weekly
updates on new posts

Subscribe