Skip to main content

Securing Agentic Systems

by David Matousek

Book 1 covers building agentic systems. This one covers securing them: the threat model, the posture framework, and the governance that holds under real production load. Chapters publish weekly in The Agentic Shift and land here as they go live.

Part 1 The Threat Model

  • Defense-in-Depth for Agentic Systems

    Layered Security for AI That Actually Works

    Coming soon
  • Know Your Agent - The Type Taxonomy

    Why \"Agent\" Is Doing Too Much Work as a Category

    Coming soon
  • Context as Attack Surface

    Injection, Pollution, and Exfiltration

    Coming soon
  • Shift Left, To the Agent

    Security as Agent Orchestration, Not Pipeline

    Coming soon
  • AI Reasoning as a Security Mechanism

    One Capability, Three Altitudes

    Coming soon
  • Governance as Security

    Governing the Agentic Stack, Layer by Layer

    Coming soon
  • Securing the Inheritance Chain

    How Unsafe Patterns Propagate Through Spawn Trees

    Coming soon

Part 2 The Agentic Security Posture

  • The Agentic Security Posture Framework

    Seven Posture Domains for Securing AI Agents

    Coming soon
  • Agent Identity Posture

    Who Is This Agent?

    Coming soon
  • Agent Input Posture

    What Can Influence This Agent?

    Coming soon
  • Agent Data & Context Posture

    What Does This Agent Remember and Trust?

    Coming soon
  • Agent Tool & API Posture

    What Can This Agent Touch?

    Coming soon
  • Agent Communication Posture

    How Do Agents Talk to Each Other?

    Coming soon
  • Agent Runtime Posture

    Where Does This Agent Run?

    Coming soon
  • Agent Governance Posture

    Can You See What This Agent Is Doing?

    Coming soon

Part 3 The DevSecOps Transformation

  • When the Pipeline Loses Its Authority

    The Governance Crisis of Shifting Security Left

    Coming soon
  • Rebuilding Governance for the Agentic Era

    Attestation, Compliance Evidence, and the New Trust Model

    Coming soon

Part 4 The AI-Native Pipeline

  • The AI-Native Pipeline

    The Reference Architecture

    Coming soon
  • Securing Discover

    Risk Classification and the Attack-Surface Map

    Coming soon
  • Securing Define

    Intent Is a Security Artifact

    Coming soon
  • Securing Plan

    Threat-Model the Design

    Coming soon
  • Securing Build

    The Reasoning Scan Joins the Floor

    Coming soon
  • Securing Deliver

    Evidence at the Gate, Not a Review Board

    Coming soon
  • Securing Document

    The Evidence Every Turn Leaves Behind

    Coming soon
  • The Execution Layer

    Governed at the Edge, Outside the Loop

    Coming soon

Part 5 Governance in Practice

  • Beyond Coding Agents - Governance Across Domains

    When \"Commit\" Means Something Different

    Coming soon
  • Agent Security Posture in the Enterprise

    From Framework to Practice

    Coming soon
  • Conclusion - Security Is Not a Feature

    TBD

    Coming soon