Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Agent Governance: How Enterprises Should Approach It

Governing AI agents at enterprise scale requires a fundamental change in how security, risk, and compliance teams think about AI oversight. The generative AI era focused governance on output quality: what the model says, what it produces, and whether the content meets policy standards. ‍ The agentic era demands governance of action and delegated authority: what the AI is allowed to do, what systems it can touch, and how its decisions trace back to human accountability.

TITAN AI Demo Series: Query Vendor Risk Within Claude

Your security team already lives in Claude. Now TITAN AI does too. SecurityScorecard's new Model Context Protocol (MCP) connector brings TITAN AI directly into Claude. Your team can query vendor risk, scores, and findings without leaving the tool they already use every day. No new dashboard, no extra login, just answers where the work already happens. In this episode of SecurityScorecard's Demo Tuesday series, see the TITAN AI MCP connector in action inside Claude.

The Illusion of AI Containment: Why AI Guardrails Won't Save Your Supply Chain

AI is quickly becoming one of the most useful tools available to security researchers. Its ability to analyze enormous volumes of data, identify vulnerabilities, reconstruct attacks, connect seemingly unrelated signals, and help defenders respond faster than humans could alone is incredibly beneficial.

The Vendor Assurance Confidence Gap: Why It's Widest With Your Most Critical Vendors

Vendor assurance efforts are increasing, but risk leaders don’t trust the results of that effort. In KPMG’s Global Third-Party Risk Management (TPRM) Survey, only 15% of risk leaders said they have high confidence in the data that underpins their TPRM program. Only 17% rate their data quality as excellent. Security teams are running more assessments and sending more questionnaires than ever, but fewer than one in five leaders trust what any of that produces.

The Top AI Agent Security Vendors of 2026: A Buyer's Guide

Enterprise buyers evaluating AI agent security in 2026 face a market that has fragmented into specialized categories, each solving one layer of the problem well and other layers poorly. Identity vendors govern non-human credentials. Runtime vendors constrain what agents can do at the moment of execution. Established security platforms extend their existing offerings into the agentic space. ‍

CRQ Platform Comparison for Financial Services Organizations

‍Cyber risk quantification (CRQ) has moved from optional to operational in financial services. The average cost of a data breach in the sector reaches $5.56 million, and regulatory mandates including DORA, NYDFS Part 500, and SEC cyber disclosure rules demand quantified, defensible loss exposure figures the finance function can act on. ‍

How AI-Related Security Incidents Should Be Identified and Managed

AI-related security incident detection starts with knowing what AI systems are running across the organization. Without a complete, continuously updated inventory of sanctioned, shadow, and third-party AI tools, security teams cannot detect incidents involving systems they do not know exist. From there, effective incident management requires a structured response framework that connects detection to containment, investigation, remediation, regulatory notification, and governance integration. ‍

How Accurate Are CRQ Models? Understanding Statistical Significance

Cyber risk quantification (CRQ) models are as accurate as the data and methodology behind them, and the conversation about CRQ accuracy that plays out across security and finance teams is often stuck on the wrong question. Risk is about future events that may or may not happen, and if they do, the impact will vary. ‍ Looking for certainty in a probabilistic model is a category error. The useful question is not whether a CRQ model produces the "right" number.

Building and Enforcing an AI Acceptable Use Policy

An AI acceptable use policy (AUP) is a formal set of rules that defines how employees can safely and responsibly use AI tools in the workplace. Its purpose is to encourage AI-driven productivity while protecting the organization from data leaks, intellectual property exposure, compliance violations, and the security vulnerabilities that unsanctioned AI usage introduces. Every organization deploying or permitting AI tools needs one. ‍