惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

K
Kaspersky official blog
云风的 BLOG
云风的 BLOG
IT之家
IT之家
T
The Blog of Author Tim Ferriss
C
Check Point Blog
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
F
Fortinet All Blogs
D
DataBreaches.Net
The Register - Security
The Register - Security
L
LINUX DO - 最新话题
W
WeLiveSecurity
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V2EX - 技术
V2EX - 技术
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
小众软件
小众软件
F
Full Disclosure
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
I
InfoQ
S
Secure Thoughts
TaoSecurity Blog
TaoSecurity Blog
MyScale Blog
MyScale Blog
AI
AI
Recent Announcements
Recent Announcements
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Hugging Face - Blog
Hugging Face - Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
C
CXSECURITY Database RSS Feed - CXSecurity.com
V
Vulnerabilities – Threatpost
NISL@THU
NISL@THU
SecWiki News
SecWiki News
Cisco Talos Blog
Cisco Talos Blog
H
Heimdal Security Blog
Y
Y Combinator Blog
N
News | PayPal Newsroom
P
Privacy International News Feed
美团技术团队
Attack and Defense Labs
Attack and Defense Labs
D
Docker
PCI Perspectives
PCI Perspectives
Webroot Blog
Webroot Blog
A
About on SuperTechFans
A
Arctic Wolf
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
MongoDB | Blog
MongoDB | Blog
T
Threat Research - Cisco Blogs

Security @ Cisco Blogs

Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
Extending Zero Trust Across the Agentic AI Workflow
Prabhat Singh · 2026-06-03 · via Security @ Cisco Blogs

Earlier this year, Cisco outlined our vision for Zero Trust for the agentic workforce. At its core is a simple principle: trust should not be established once and assumed indefinitely. As agents interact with models, tools, applications, and data, their activity must be continuously evaluated.

Putting that principle into practice requires controls that can follow agents as they work. Consider a coding agent like Claude Code or Codex. To complete a single task, it may call an LLM for reasoning, connect with MCP tools to read Jira and push to GitHub, hit SaaS APIs for data, and browse the web for additional context. It does all this autonomously, at machine speed, carrying whatever credentials it was handed at startup.

Why existing controls fall short

Traditional Zero Trust controls authenticate a user and grant access to a resource. Once access is granted, we rely on humans to exercise judgment or machines to follow pre-defined rules. An agent is neither a user nor a deterministic machine. It is a process that reasons, decides, and acts – with broad scope, exponential scale, and no human judgment.

As a result, access control is no longer enough. A coding agent may be authorized to connect to GitHub, Jira, and an approved set of models. The real question is not whether it can connect to those systems, but what actions it takes across them as it works toward a goal. Reading a repository, creating a pull request, modifying a production configuration, or accessing sensitive data may all carry different levels of risk.

This is the shift from access control to action control. Organizations need to evaluate agent activity not just when access is granted, but throughout the workflow itself. That is the agent security challenge—and it is categorically different from the problems Zero Trust was originally designed to solve.

From Access Control to Action Control

Cisco Secure Access is evolving to help make that shift with Agent Gateway—new functionality that extends policy enforcement across agent interaction with LLMs, MCP servers, SaaS APIs, and web destinations. To move from access control to action control, Agent Gateway will help answer five questions before a request is allowed to proceed:

  • Who is the agent? Cisco uses Duo to identify the Codex, Claude Code, or LangChain agent itself – not just the laptop it runs on.
  • What is it trying to access? Agent Gateway will map requests to a named resource group: an approved model set, a group of MCP tools, a set of SaaS APIs, or a web category.
  • Is this action allowed? Policy will decide whether the request is permitted, observed, or blocked. A “fetch” from the GitHub repo is allowed; a “create_file” to the same repo can be denied.
  • Which credential should be used? Tokens, OAuth grants, and API keys will live in Cisco’s vault. The agent never touches them. Agent Gateway will inject the right credential server-side per method and path.
  • What happened? Every decision – agent identity, resource touched, policy verdict, credential reference, route taken—will land in one audit event.
Cisco AI gateway pks image
Figure: Cisco Secure Access Agent Gateway applies consistent policy across agent interactions

What makes Cisco’s approach different

Many approaches to agent security introduce a second access stack that enterprises adopt alongside their existing SSE and identity infrastructure. Cisco’s approach is different: if you already run Secure Client, Secure Access, and Duo, you already have the enforcement surface. With Agent Gateway, Cisco extends these capabilities into the agentic workflow. No agent code changes. No new management portal. No second identity system.

  • Agent identity via Duo Non-Human Identity (NHI). Duo will identify the agent process itself using Duo identity, extending naturally from user MFA to agent and non-human identities. No separate identity service required. In MCP environments, Duo and Secure Access work together to enable fine-grained tool-level authorization, so organizations can govern which tools an agent is allowed to invoke, not just which MCP servers an agent can access.
  • Shared policy across the workflow. Agents operate across models, MCP tools, APIs, and web activity—not within a single control plane. With Agent Gateway, Cisco will apply a common policy framework across those environments, helping organizations govern approved models, MCP tools, enterprise APIs, and web destinations.
  • Server-side credential injection. Keys and tokens live in Cisco’s vault. The agent never touches them. Agent Gateway will inject the right credential server-side per method and path. This separates agent authorization from credential possession, allowing agents to perform approved actions without access to the underlying credentials. This closes a class of exfiltration risk that no proxy-only solution addresses.

What this means in practice

Consider an enterprise deploying hundreds of coding agents across software development. Each agent may be authorized to use approved LLMs, access Jira through MCP tools, retrieve source code from GitHub, consult internal documentation, and interact with selected enterprise APIs. On paper, that sounds straightforward. In practice, those agents may perform thousands of actions every day across dozens of systems.

Traditional access controls can answer whether an agent is allowed to connect to GitHub. They struggle to show whether a particular action was appropriate once the agent got there. Even basic audit questions require stitching evidence from LLM provider logs, MCP server logs, GitHub audit trails, and whatever the agent’s orchestration framework happens to capture.

With Agent Gateway and Duo, every agent has a named identity tied to its owner and business purpose. Every GitHub interaction shows which method was called, whether it was allowed, and which vault reference provided the token. When a model provider has an outage, requests can automatically fail over to another approved model within the same policy framework. Observation mode can identify unusual patterns—such as a burst of write requests to a normally read-only API—and surface them as policy recommendations.

The value is not another dashboard. It is a single control loop for agent identity, action, credential, policy, and outcome.

Some products or features described may be in various stages of development and offered on a when-and-if available basis. Cisco reserves the right to change delivery timelines and will have no liability for any delays or failures to deliver.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram