From Models to MCP Servers, Skills, and Plugins: Rethinking Trust in the AI Supply Chain
Blog Published: 09/29/2026
An enterprise can approve an AI model, authenticate its users, and restrict access to internal systems, yet still expose sensitive data through the components surrounding that model. In September 2025, an MCP server distributed through npm demonstrated how quickly trust can become a liabilit...
CSA Welcomes NVIDIA Open Agent Safety Platform
Blog Published: 09/28/2026
Cloud Security Alliance is building industry consensus around governance and security controls for autonomous AI. We welcome the launch of the NVIDIA Open Agent Safety Platform and NVIDIA’s commitment to making autonomous AI safer to deploy at enterprise scale. NVIDIA is bringing its e...
Cloud Security Doesn’t Have an Asset Problem. It Has a Relationship Problem.
Blog Published: 10/01/2026
Every CSPM tool can hand you a list of resources and findings. Almost none of them can tell you what happens to the rest of your environment if any one of them gets compromised. Ask most cloud security teams whether they have visibility into their environment, and they'll say yes. Th...
5 Ways AI is Changing Traditional Security Models According to Modern CISOs
Blog Published: 10/05/2026
The Reality of Securing AI in Motion Traditional security tools were built for environments defined by fixed rules and predictable workflows. But AI behavior is non-deterministic. The same prompt can produce different outcomes, and risk often emerges gradually as AI behavior adapts, ...
Post Quantum Cryptography is Not an Algorithm Upgrade
Blog Published: 10/05/2026
As organizations prepare for post quantum cryptography, I am seeing confusion in two areas. The first is around the algorithms themselves. ML KEM, ML DSA, SLH DSA, FIPS 203, 204 and 205 are often discussed as if they are interchangeable. The second is more important. Teams are starting to t...
Securing Agentic AI with Zero Trust Microsegmentation
Blog Published: 10/06/2026
AI agents select tools, invoke APIs, retrieve data, act under delegated user context, and create outbound connections at runtime. That autonomy can make them useful. It also means you need to know which agents can reach which tools, models, APIs, and data sources, and in what context. Zero...