THE NEW PERIMETER · AI AGENT SECURITY

The new perimeter is the agent.

The network boundary dissolved years ago. In the agentic enterprise your perimeter is wherever an agent can read, decide, act, or leak. IMS maps it, tests it, and closes it.

07Attack surfaces
2 WKAssessment cycle
BOARDReady output
PERIMETER MONITOR● LIVE
AGENTCONTROL POINT
S-01InstructionPrompts · policy · tool descriptions

▼ HOW IT FAILS

Untrusted content becomes instruction.

    ▲ WHAT CLOSES IT

    Trust boundaries on every input; tool descriptions reviewed as code.

    IMS ASSESSES

    Instruction-surface review + injection test battery.

    HOVER A SURFACE →
    // CORE THESIS

    Your AI perimeter is wherever an agent can read, decide, act, or leak.

    Prompt injection is not a model problem. It is a delegation problem.
    MCP turns language into authority.
    If your agent can touch production, your board owns the risk.
    // THE SEVEN SURFACES

    The New Perimeter framework

    Seven behavioral surfaces define where an agent can be attacked. We map, test, and close each one.

    OPEN THE ATLAS →
    // PERIMETER DIAGNOSTIC

    Map your AI perimeter in 3 minutes.

    An operational diagnostic, not a marketing quiz. Toggle what your agents actually do.

    INPUT // AGENT CAPABILITIES7 SIGNALS
    // PROOF ARTIFACTS

    Evidence, not adjectives.

    Every engagement produces board-visible artifacts. Sample outputs from the assessment.

    AI RISK HEATMAPASSESSMENT-2026-Q2
    LIKELYIMPACTCONTROLNET
    LOWELEVATEDCRITICAL
    POSTURE REPORTCONFIDENTIAL
    62/100PERIMETER MATURITY

    Findings 23Critical 4Roadmap items 11

    RED-TEAM FINDINGCRITICAL

    FINDING RT-014 · surface S-04 TOOL› Indirect injection in a retrieved PDF chained the support agent's refund tool.› Text-to-action: untrusted content → live financial transaction. No human gate.+ CONTROL: scope tool to read-only; approval gate > $0; provenance tag on retrieval.

    MCP & TOOLING AUDIT14 SERVERS
    MCP SERVERSCOPEEXPOSEDRISKgithub-mcprepo:writepublicCRITdb-queryread/writevpcHIGHstripe-toolschargesinternalCRITsearch-ragreadvpcMED

    “We deployed 11 production agents in two quarters and inventoried none. Four can move money or write to customer systems without a human gate. This is unmanaged delegation — and it is the committee's risk to own.”— EXCERPT, IMS EXECUTIVE BRIEFING

    // ASSESSMENT MISSION PLAN

    Six service lines. One perimeter.

    SVC-01 ALL

    AI Security Posture Assessment

    Two-week perimeter map across all seven surfaces. The primary engagement.

    SVC-02 S-01–07

    Enterprise Agent Security Architecture

    Reference architecture for agents that can be deployed without unmanaged delegation.

    SVC-03 S-01·04·06

    AI Red Teaming

    Adversarial testing of injection, tool abuse, and text-to-action escalation.

    SVC-04 S-02·07

    AI Governance, Risk & Compliance

    Board-ready risk language, agent inventory, and fiduciary framing.

    SVC-05 S-04

    MCP & Tooling Security Audit

    Inventory, scope review, and gating for every MCP server and tool action.

    SVC-06 ALL

    Board / Executive AI Risk Briefing

    A private briefing environment for CISOs, boards, audit committees, and GCs.

    // MAP. TEST. CLOSE.

    Map your agent perimeter before you deploy more AI.

    Every enterprise needs an agent inventory before it needs another AI policy. Start with a two-week posture assessment.

    Request AI Security Posture AssessmentExplore the framework