Three guides tackle enterprise AI security

Three guides tackle enterprise AI security

Three new guides aim to secure fast-changing enterprise AI systems. They apply the CIS Controls to LLMs, AI agents, and MCP environments with practical recommendations for enterprise teams.


The AI LLM Companion Guide covers prompts, context handling, and the exposure of sensitive information. The AI Agent Companion Guide focuses on tool execution, governed autonomy, and access to enterprise systems. The MCP Companion Guide addresses secure tool access, non-human identities, and auditable interactions across the protocol layer.

Curtis Dukes, Executive Vice President and General Manager of Security Best Practices at CIS, said: “These guides reflect a shared effort to bring clarity to an area where organisations are seeking direction. By combining our collective expertise, we translated the CIS Controls into concrete steps that help teams secure AI systems across the model, agent, and protocol layers.”

The organisations said the guides are aimed at risks including data leakage, unbounded agent autonomy, credential misuse, and unsafe tool execution. Astrix contributed work around AI agents, MCP servers, and non-human identities, while Cequence focused on application, data, and API security. Jonathan Sander, Field CTO of Astrix Security, said: “AI agents introduce a new operational surface that organisations must understand before they scale.” Shreyans Mehta, CTO and Co-Founder of Cequence Security, said the partnership had created guidance that helps organisations enable “agentic AI safely”. More information is available here.



  • Franchise law call follows Vodafone dispute

    Franchise law call follows Vodafone dispute

    Franchise protections are facing renewed scrutiny after Adrian Howe’s death. His family is calling for Adrian’s law after concerns over risk in brand-led franchise agreements.


  • Chinese EV imports test mandate

    Chinese EV imports test mandate

    Chinese EV imports are testing the UK’s transition strategy. Stellantis has warned that the ZEV mandate is creating commercial strain as lower-cost rivals gain ground.


  • EU sanctions push crypto compliance further offshore

    EU sanctions push crypto compliance further offshore

    Europe’s latest Russia package extends sanctions deeper into crypto markets. HTX has been identified among platforms affected by new EU restrictions, as Brussels widens scrutiny of digital assets, offshore channels, and sanctions evasion.