Ask a security team whether they actually know what their own employees can access, and you'll get an uncomfortable pause — and now those same messy permissions are being handed to software. Most tools protect the data or vet the model, but the control plane, where agents authenticate, connect to tools and MCP servers, and take real actions on your behalf, is largely ungoverned. When an agent slips its collar and reaches a system it was never meant to touch, most organizations have no way to see it, let alone stop it
Rich Stroffolino is a Producer at CISO Series. He focuses on themes such as cybersecurity, cybercrime, and cloud security, covering critical topics including cyber attacks, data breaches, phishing, and secure cloud storage. Rich's insights and expertise have been featured in various industry discussions, highlighting the intersection of business and economics within the cybersecurity landscape.













