YOU DO NOT COPY PROFESSIONALISM. YOU ALIGN WITH IT.
HOME / SERVICES / AI SECURITY

AI SECURITY GOVERNANCE

YOU HIRED HUNDREDS OF EMPLOYEES THIS YEAR AND INTERVIEWED NONE OF THEM

Full lifecycle security governance for agentic AI applications. NEWORDER’s adversary-aligned methodology discovers, tests, and protects autonomous AI agents across your entire environment, from build time through production runtime, ensuring every agent operates within its intended scope with the same tactical precision we bring to every engagement.

An AI agent is an insider you never interviewed. It holds your permissions, your customer data and access to the systems that move your money. It has none of your judgement, no loyalty, no fear of consequence, and no ability to tell when it is being lied to.

Your policy says the agents are governed. Your architecture diagram says they are contained. Neither statement has been tested by somebody trying to break it.

This already happened. It is not a forecast.

At NEWORDER, we deliver tactical solutions designed to think like attackers, act with precision, and produce measurable outcomes. Our services are engineered to expose hidden vulnerabilities, simulate real-world threats, and build cyber resilience at every level.

Nobody clicked anything

EchoLeak. A zero-click flaw in Microsoft 365 Copilot. A hidden instruction inside an ordinary inbound email, read by the assistant while assembling context. Tenant data left the building. Found by a third party, not by the platform vendor.

Reported January 2025. Fixed server-side May 2025.

Salesloft Drift

The model was never touched

Attackers stole OAuth and refresh tokens belonging to an AI chat agent and used them to reach connected customer systems. Fourteen companies publicly confirmed impact. The failure was token hygiene and third-party integration visibility, not model security.

August January 2025. 

GTG-1002

The attacker was the agent

Anthropic documented a state-sponsored group manipulating an AI model into functioning as an autonomous attack agent, executing 80 to 90% of tactical operations independently against roughly 30 entities. Anthropic also recorded that the model frequently overstated findings and occasionally fabricated data during those operations.

Disclosed November 2025.

AGENTIC SECURITY

SECURING THE AGENTIC ERA

AppSec teams are being asked to secure agentic applications, but how do you secure something that is non-deterministic by nature? Traditional cyber security controls were built for deterministic software with predictable inputs and outputs. Agentic AI applications are fundamentally different: they make decisions, call tools, access data, and take autonomous action. This creates security challenges at every stage of the lifecycle.

Every control you own was built for a human who might lie. Not for a machine that cannot tell it is being lied to.

At build time, teams struggle to put agentic-specific security measures in place because they lack out-of-the-box policies or custom frameworks designed specifically for AI risks and threats.

During testing, teams are unable to test agentic runtime behaviour, have no reliable way to understand what the refusal space is of the application’s model, and security assumptions are made without properly stress-testing these agentic applications against adversarial conditions.

At runtime, teams struggle to know if an agentic application is staying within its intended scope, or whether its intent has been manipulated or has quietly drifted from its original design.

The instinct is to layer on additional security measures, but policies built for traditional applications introduce serious latency and generate false positives at a rate that will break production. What is needed is something purpose-built for AI that can answer four foundational questions about your agentic environment.

THE TACTICAL FRAMEWORK

FOUR QUESTIONS YOUR AI SECURITY MUST ANSWER

01 — What agents and AI systems exist in my environment, including the ones nobody registered?

02 — What permissions, data access and identities do they carry, and can I attribute an action to a person?

03 — What can actually be exploited today, what does it cost me to fix, and in what order?

04 — How do I keep them inside scope tomorrow, and prove it to a board?

The capabilities below answer them in that order. Most organisations start at question one, because most organisations cannot yet list every agent running inside them.

THE TACTICAL OFFENSIVE AND DEFENSIVE SECURITY LOOP

We did not write this list. That is exactly why we test against it.

On 9 December 2025 the OWASP Agentic Security Initiative published a Top 10 for Agentic Applications. OWASP does not sell anything. The list was built by an open community of practitioners, it is vendor neutral, and no security firm controls it. It does not tell a South African organisation what each one means under POPIA, King V or Joint Standard 2 of 2024. That mapping did not exist, so our team built it, one risk at a time.

That makes it the rarest thing in this industry: a standard you can hold your provider to, written by nobody with something to sell you. We test against it, and against the OWASP Top 10 for LLM Applications, for exactly that reason. A standard we did not write is a standard you can audit us against.

DISCOVERY

NEWORDER connects to CI/CD pipelines to automatically discover and inventory every homegrown AI application, and integrates directly with AWS Bedrock, Google Vertex AI, Salesforce, and other cloud and third-party platforms for visibility into AI agents. Each AI system is profiled across its model, system prompt, tools, guardrails, policies, and configurations, and the inventory stays current on every change. You cannot secure what you cannot see; discovery is the non-negotiable first step.

AI SECURITY POSTURE MANAGEMENT (AI-SPM)

NEWORDER conducts a static analysis of every application’s configuration, policy coverage, and third-party dependencies and identifies any policy gaps. In addition, it maps each agentic application to its coverage of major frameworks, including NIST, OWASP, and MITRE. This gives you a clear, measurable view of your AI security posture before a single adversarial test is run, turning assumptions into evidence and compliance into a continuous output rather than a periodic exercise.

AI RED TEAMING

NEWORDER’s automated AI red teaming covers the complete kill chain from reconnaissance to exploitation. It proactively discovers exploitable vulnerabilities through automated reconnaissance and adversarial testing purpose-built for agentic applications. Static attacks draw from a 300K+ payload library with 100% MITRE and OWASP LLM and Agentic Top 10 coverage, running comprehensive sweeps of known jailbreak patterns, content moderation bypasses, and obfuscation techniques. Dynamic attacks use multi-turn and continuous probing to test how an application holds up across extended adversarial sequences, not just a single interaction. High-agency attacks deploy extremely customised, bespoke attack techniques through probing tailored specifically to the intent and design of each application.

RUNTIME PROTECTION

NEWORDER offers policy enforcement and AI threat protection at the proxy, API, or AI Gateway layer. Protection adapts as the applications evolve and as new capabilities are added. When an attack hits production, whether a jailbreak, a prompt injection, or any other AI threat, it is blocked in real time and an immediate alert is sent with full context, including what happened, which application was targeted, what the impact is, and what to do next. Key performance metrics include 98.6% threat detection accuracy, 1.4% false positive rate, sub-200ms time to detect, sub-50ms real-time blocking, and immediate mean time to respond.

OTHER SERVICES

ASI01

Which South African legal obligations a hijacked agent breaches, and what a board must be able to evidence afterwards.

ASI02

How a chained sequence of individually approved tool calls creates a Cybercrimes Act and Joint Standard 2 problem that no single permission review would have flagged.

ASI03

Why an agent action you cannot attribute to a person is a POPIA and King V accountability failure before it is ever a security failure.

ASI04

How POPIA operator obligations and the Joint Standard 2 requirement for equivalent third-party controls apply to model providers, MCP servers and agent integrations that no standard vendor questionnaire covers.

ASI05

Which South African instruments are engaged the moment an agent executes a command nobody authorised, and what a board must be able to evidence afterwards.

ASI06

Why AI agent memory poisoning breaks South African notification timelines, and what logging an organisation needs to reconstruct blast radius inside a 24 hour clock.

ASI07

Why a chain of agents instructing each other remains automated processing under POPIA section 71, and what machine-to-machine authorisation a South African board must be able to evidence.

ASI08

What a South African board must be able to evidence when a chain of agents propagates a wrong decision with no attacker present, and how the simulated incident requirement in Joint Standard 2 applies to an agent chain rather than to a network.

ASI09

The two directions of agent trust abuse, inward against staff and outward against customers, treated as one governance problem and mapped to POPIA section 71, the Cybercrimes Act and Joint Standard 2 rather than to awareness training.

ASI10

Why endpoint-resident shadow AI is invisible to the network controls most South African firms rely on, and what King V and POPIA require of a governing body for agents it never approved.

The list describes the risks. It does not tell a South African organisation what each one means under POPIA, King V or Joint Standard 2 of 2024. That mapping did not exist, so our team built it, one risk at a time.

DELIVERABLE

WHAT YOU RECEIVE

  • Proven exploitability. A working attack chain, reproduced step by step, against your agents. Not a probability, not a rating.
  • A named operator. The person who ran the test sits in front of your audit committee and walks them through what happened.
  • A remediation path. The specific control that closes each chain, ordered by what it costs you to implement.
  • A retest. Because a finding you have not re-tested is a finding you have not closed.
  • Evidence your board and your broker can use. Mapped to King V accountability and to the governance evidence insurers now ask for at renewal.
A scanA questionnaireA policy reviewA maturity score
We do not run scans.
We deploy operators.

The service line parent page.

Human operators attacking your production agents.

The paid diagnostic that produces your agent inventory.

Policy enforcement and threat protection, operated by our team.

Governance evidence timed to the renewal date.

Independent periodic assurance for the audit committee.

The framework, the ten risks and the regulatory picture.

FREQUENTLY ASKED QUESTIONS

FAQ

AI Agent Security Governance is a full lifecycle approach to securing agentic AI applications: autonomous systems that make decisions, call tools, and take action without human oversight at every step. Traditional cyber security controls were built for deterministic software and cannot address the unique risks of non-deterministic AI agents. As organisations deploy agents across customer service, internal operations, code generation, and decision support, the attack surface expands in ways legacy AppSec tools cannot see. NEWORDER’s service provides discovery, posture management, adversarial red teaming, and runtime protection in a single continuous loop, ensuring every agent behaves within its intended scope.

Traditional penetration testing targets deterministic systems with known inputs and predictable outputs. AI red teaming must account for the non-deterministic nature of large language models and agentic systems, where the same input can produce different outputs and where multi-turn conversations can gradually shift an agent’s behaviour. NEWORDER’s AI red teaming uses a 300K+ payload library, multi-turn adversarial sequences, and high-agency bespoke attacks tailored to each application’s specific intent and design. This goes far beyond static vulnerability scanning to stress-test how agents behave under sustained adversarial pressure.

Runtime protection operates at the proxy, API, or AI Gateway layer to enforce policies and block AI-specific threats in real time. This includes jailbreaks, prompt injection, content moderation bypasses, and intent manipulation. When a threat is detected, it is blocked within 50 milliseconds and a full-context alert is sent covering what happened, which application was targeted, the impact assessment, and recommended next steps. Protection adapts continuously as applications evolve and new capabilities are added, with a threat detection accuracy of 98.6% and a false positive rate of just 1.4%.

NEWORDER’s AI Agent Security Governance integrates with all major AI and agent platforms including AWS Bedrock, Google Vertex AI, OpenAI, Anthropic, Microsoft 365 Copilot, CopilotStudio, Azure AI Foundry, Salesforce, Salesforce Agentforce, ServiceNow, and Power Platform. The service also covers homegrown AI applications discovered through CI/CD pipeline integration. Deployment requires no agents, no code changes, and no source code access. Connection is typically completed in hours.

AI Agent Security Governance sits alongside and integrates with NEWORDER’s full tactical cyber security capability. Red teaming findings feed into your broader risk posture managed through our Cyber Warfare Centre. Discovery outputs align with Attack Surface Management for complete visibility across both traditional and AI assets. Runtime protection complements existing SIEM and SOC services. And executive reporting integrates with our Executive Cyber Risk Management function to ensure board-level visibility of AI-specific risks alongside your broader cyber risk programme.

Traditional vulnerability management identifies known CVEs in deterministic software. AI Security Posture Management (AI-SPM) evaluates the configuration, policy coverage, guardrail effectiveness, and framework alignment of non-deterministic agentic applications. It maps each AI application against NIST, OWASP, and MITRE frameworks and identifies gaps that traditional scanners cannot see because they were not designed to assess AI-specific risks such as prompt injection, jailbreak susceptibility, or agent drift.

Yes. Cloud AI environments are a core focus. We test across AWS Bedrock, Google Vertex AI, Azure AI services, and other cloud-native agent platforms. Cloud-hosted AI agents introduce unique risks including IAM misconfigurations for AI service accounts, over-permissioned agent roles, exposed model endpoints, and insecure tool integrations. Our methodology addresses these alongside the AI-specific risks of prompt injection, agent drift, and intent manipulation.

Yes. The service aligns with NIST AI RMF, OWASP LLM and Agentic Top 10, MITRE ATLAS, as well as broader frameworks including ISO 27001, SOC 2, PCI DSS, POPIA, and GDPR. AI-SPM maps each application’s coverage against these frameworks and identifies gaps. Full audit trails and reporting are provided for regulatory and audit evidence.

TAKE ACTION

CAN YOUR BUSINESS AFFORD TO BE HACKED?

Contact us for a no-obligation discussion about your AI roadmap.