HOME / SERVICES / AI SECURITY
AI SECURITY GOVERNANCE
YOU HIRED HUNDREDS OF EMPLOYEES THIS YEAR AND INTERVIEWED NONE OF THEM
Full lifecycle security governance for agentic AI applications. NEWORDER’s adversary-aligned methodology discovers, tests, and protects autonomous AI agents across your entire environment, from build time through production runtime, ensuring every agent operates within its intended scope with the same tactical precision we bring to every engagement.
An AI agent is an insider you never interviewed. It holds your permissions, your customer data and access to the systems that move your money. It has none of your judgement, no loyalty, no fear of consequence, and no ability to tell when it is being lied to.
Your policy says the agents are governed. Your architecture diagram says they are contained. Neither statement has been tested by somebody trying to break it.
This already happened. It is not a forecast.
Nobody clicked anything
EchoLeak. A zero-click flaw in Microsoft 365 Copilot. A hidden instruction inside an ordinary inbound email, read by the assistant while assembling context. Tenant data left the building. Found by a third party, not by the platform vendor.
Reported January 2025. Fixed server-side May 2025.
Salesloft Drift
The model was never touched
Attackers stole OAuth and refresh tokens belonging to an AI chat agent and used them to reach connected customer systems. Fourteen companies publicly confirmed impact. The failure was token hygiene and third-party integration visibility, not model security.
August January 2025.
GTG-1002
The attacker was the agent
Anthropic documented a state-sponsored group manipulating an AI model into functioning as an autonomous attack agent, executing 80 to 90% of tactical operations independently against roughly 30 entities. Anthropic also recorded that the model frequently overstated findings and occasionally fabricated data during those operations.
Disclosed November 2025.
AGENTIC SECURITY
SECURING THE AGENTIC ERA
AppSec teams are being asked to secure agentic applications, but how do you secure something that is non-deterministic by nature? Traditional cyber security controls were built for deterministic software with predictable inputs and outputs. Agentic AI applications are fundamentally different: they make decisions, call tools, access data, and take autonomous action. This creates security challenges at every stage of the lifecycle.
Every control you own was built for a human who might lie. Not for a machine that cannot tell it is being lied to.
At build time, teams struggle to put agentic-specific security measures in place because they lack out-of-the-box policies or custom frameworks designed specifically for AI risks and threats.
During testing, teams are unable to test agentic runtime behaviour, have no reliable way to understand what the refusal space is of the application’s model, and security assumptions are made without properly stress-testing these agentic applications against adversarial conditions.
At runtime, teams struggle to know if an agentic application is staying within its intended scope, or whether its intent has been manipulated or has quietly drifted from its original design.
The instinct is to layer on additional security measures, but policies built for traditional applications introduce serious latency and generate false positives at a rate that will break production. What is needed is something purpose-built for AI that can answer four foundational questions about your agentic environment.
THE TACTICAL FRAMEWORK
FOUR QUESTIONS YOUR AI SECURITY MUST ANSWER
01 — What agents and AI systems exist in my environment, including the ones nobody registered?
02 — What permissions, data access and identities do they carry, and can I attribute an action to a person?
03 — What can actually be exploited today, what does it cost me to fix, and in what order?
04 — How do I keep them inside scope tomorrow, and prove it to a board?
The capabilities below answer them in that order. Most organisations start at question one, because most organisations cannot yet list every agent running inside them.
THE TACTICAL OFFENSIVE AND DEFENSIVE SECURITY LOOP
- Most AI security is bought in two disconnected halves. Somebody tests once and produces a report. Somebody else deploys guardrails tuned to a vendor default. The report ages, the guardrails drift, and nothing connects the two. We run them as one loop, and the loop is the reason the controls stay relevant.
- Red Team, offence. Proactively discover weaknesses in your models, agents and applications through adversarial simulation. Prompt injection, multi-turn attacks, agent logic corruption, tool chain exploitation, identity abuse and reconnaissance. The output is a working attack chain, reproduced step by step.
- Blue Team, defence. Ensure guardrails, policies and runtime protections prevent, detect and respond to AI-specific threats in real time. Guardrail conformance, runtime posture management, policy enforcement, anomaly detection and trust boundary alerting, with an audit trail built so an action can be attributed and reconstructed.
- Purple Team, continuous fusion. Feed adversarial findings directly into defensive controls, policy updates and guardrail improvements. Closed-loop remediation, guardrail patching, red and blue alert correlation, policy update mapping and CI integration hooks. Every chain the red team proves becomes a rule the defence enforces, and every rule is tested again at the next engagement.
- Yellow Team, secure build. The upstream half. Secure architecture, secure code review and pipeline hardening, so the same class of finding stops being written into the next release.
We did not write this list. That is exactly why we test against it.
On 9 December 2025 the OWASP Agentic Security Initiative published a Top 10 for Agentic Applications. OWASP does not sell anything. The list was built by an open community of practitioners, it is vendor neutral, and no security firm controls it. It does not tell a South African organisation what each one means under POPIA, King V or Joint Standard 2 of 2024. That mapping did not exist, so our team built it, one risk at a time.
That makes it the rarest thing in this industry: a standard you can hold your provider to, written by nobody with something to sell you. We test against it, and against the OWASP Top 10 for LLM Applications, for exactly that reason. A standard we did not write is a standard you can audit us against.
DISCOVERY
NEWORDER connects to CI/CD pipelines to automatically discover and inventory every homegrown AI application, and integrates directly with AWS Bedrock, Google Vertex AI, Salesforce, and other cloud and third-party platforms for visibility into AI agents. Each AI system is profiled across its model, system prompt, tools, guardrails, policies, and configurations, and the inventory stays current on every change. You cannot secure what you cannot see; discovery is the non-negotiable first step.
AI SECURITY POSTURE MANAGEMENT (AI-SPM)
NEWORDER conducts a static analysis of every application’s configuration, policy coverage, and third-party dependencies and identifies any policy gaps. In addition, it maps each agentic application to its coverage of major frameworks, including NIST, OWASP, and MITRE. This gives you a clear, measurable view of your AI security posture before a single adversarial test is run, turning assumptions into evidence and compliance into a continuous output rather than a periodic exercise.
AI RED TEAMING
NEWORDER’s automated AI red teaming covers the complete kill chain from reconnaissance to exploitation. It proactively discovers exploitable vulnerabilities through automated reconnaissance and adversarial testing purpose-built for agentic applications. Static attacks draw from a 300K+ payload library with 100% MITRE and OWASP LLM and Agentic Top 10 coverage, running comprehensive sweeps of known jailbreak patterns, content moderation bypasses, and obfuscation techniques. Dynamic attacks use multi-turn and continuous probing to test how an application holds up across extended adversarial sequences, not just a single interaction. High-agency attacks deploy extremely customised, bespoke attack techniques through probing tailored specifically to the intent and design of each application.
RUNTIME PROTECTION
NEWORDER offers policy enforcement and AI threat protection at the proxy, API, or AI Gateway layer. Protection adapts as the applications evolve and as new capabilities are added. When an attack hits production, whether a jailbreak, a prompt injection, or any other AI threat, it is blocked in real time and an immediate alert is sent with full context, including what happened, which application was targeted, what the impact is, and what to do next. Key performance metrics include 98.6% threat detection accuracy, 1.4% false positive rate, sub-200ms time to detect, sub-50ms real-time blocking, and immediate mean time to respond.
OTHER SERVICES
ASI01
Which South African legal obligations a hijacked agent breaches, and what a board must be able to evidence afterwards.
ASI02
How a chained sequence of individually approved tool calls creates a Cybercrimes Act and Joint Standard 2 problem that no single permission review would have flagged.
ASI03
Why an agent action you cannot attribute to a person is a POPIA and King V accountability failure before it is ever a security failure.
ASI04
How POPIA operator obligations and the Joint Standard 2 requirement for equivalent third-party controls apply to model providers, MCP servers and agent integrations that no standard vendor questionnaire covers.
ASI05
Which South African instruments are engaged the moment an agent executes a command nobody authorised, and what a board must be able to evidence afterwards.
ASI06
Why AI agent memory poisoning breaks South African notification timelines, and what logging an organisation needs to reconstruct blast radius inside a 24 hour clock.
ASI07
Why a chain of agents instructing each other remains automated processing under POPIA section 71, and what machine-to-machine authorisation a South African board must be able to evidence.
ASI08
What a South African board must be able to evidence when a chain of agents propagates a wrong decision with no attacker present, and how the simulated incident requirement in Joint Standard 2 applies to an agent chain rather than to a network.
ASI09
The two directions of agent trust abuse, inward against staff and outward against customers, treated as one governance problem and mapped to POPIA section 71, the Cybercrimes Act and Joint Standard 2 rather than to awareness training.
ASI10
Why endpoint-resident shadow AI is invisible to the network controls most South African firms rely on, and what King V and POPIA require of a governing body for agents it never approved.
The list describes the risks. It does not tell a South African organisation what each one means under POPIA, King V or Joint Standard 2 of 2024. That mapping did not exist, so our team built it, one risk at a time.
DELIVERABLE
WHAT YOU RECEIVE
- Proven exploitability. A working attack chain, reproduced step by step, against your agents. Not a probability, not a rating.
- A named operator. The person who ran the test sits in front of your audit committee and walks them through what happened.
- A remediation path. The specific control that closes each chain, ordered by what it costs you to implement.
- A retest. Because a finding you have not re-tested is a finding you have not closed.
- Evidence your board and your broker can use. Mapped to King V accountability and to the governance evidence insurers now ask for at renewal.
We deploy operators.
The service line parent page.
Human operators attacking your production agents.
The paid diagnostic that produces your agent inventory.
Policy enforcement and threat protection, operated by our team.
Governance evidence timed to the renewal date.
Independent periodic assurance for the audit committee.
The framework, the ten risks and the regulatory picture.
FREQUENTLY ASKED QUESTIONS
FAQ
What is AI Agent Security Governance and why does my organisation need it?
AI Agent Security Governance is a full lifecycle approach to securing agentic AI applications: autonomous systems that make decisions, call tools, and take action without human oversight at every step. Traditional cyber security controls were built for deterministic software and cannot address the unique risks of non-deterministic AI agents. As organisations deploy agents across customer service, internal operations, code generation, and decision support, the attack surface expands in ways legacy AppSec tools cannot see. NEWORDER’s service provides discovery, posture management, adversarial red teaming, and runtime protection in a single continuous loop, ensuring every agent behaves within its intended scope.
How does AI red teaming differ from traditional penetration testing?
Traditional penetration testing targets deterministic systems with known inputs and predictable outputs. AI red teaming must account for the non-deterministic nature of large language models and agentic systems, where the same input can produce different outputs and where multi-turn conversations can gradually shift an agent’s behaviour. NEWORDER’s AI red teaming uses a 300K+ payload library, multi-turn adversarial sequences, and high-agency bespoke attacks tailored to each application’s specific intent and design. This goes far beyond static vulnerability scanning to stress-test how agents behave under sustained adversarial pressure.
What does runtime protection cover and how does it work?
Runtime protection operates at the proxy, API, or AI Gateway layer to enforce policies and block AI-specific threats in real time. This includes jailbreaks, prompt injection, content moderation bypasses, and intent manipulation. When a threat is detected, it is blocked within 50 milliseconds and a full-context alert is sent covering what happened, which application was targeted, the impact assessment, and recommended next steps. Protection adapts continuously as applications evolve and new capabilities are added, with a threat detection accuracy of 98.6% and a false positive rate of just 1.4%.
Which AI platforms and frameworks are supported?
NEWORDER’s AI Agent Security Governance integrates with all major AI and agent platforms including AWS Bedrock, Google Vertex AI, OpenAI, Anthropic, Microsoft 365 Copilot, CopilotStudio, Azure AI Foundry, Salesforce, Salesforce Agentforce, ServiceNow, and Power Platform. The service also covers homegrown AI applications discovered through CI/CD pipeline integration. Deployment requires no agents, no code changes, and no source code access. Connection is typically completed in hours.
How does this service integrate with NEWORDER's existing cyber security offerings?
AI Agent Security Governance sits alongside and integrates with NEWORDER’s full tactical cyber security capability. Red teaming findings feed into your broader risk posture managed through our Cyber Warfare Centre. Discovery outputs align with Attack Surface Management for complete visibility across both traditional and AI assets. Runtime protection complements existing SIEM and SOC services. And executive reporting integrates with our Executive Cyber Risk Management function to ensure board-level visibility of AI-specific risks alongside your broader cyber risk programme.
What is the difference between AI-SPM and traditional vulnerability management?
Traditional vulnerability management identifies known CVEs in deterministic software. AI Security Posture Management (AI-SPM) evaluates the configuration, policy coverage, guardrail effectiveness, and framework alignment of non-deterministic agentic applications. It maps each AI application against NIST, OWASP, and MITRE frameworks and identifies gaps that traditional scanners cannot see because they were not designed to assess AI-specific risks such as prompt injection, jailbreak susceptibility, or agent drift.
Does NEWORDER test cloud-hosted AI agents?
Yes. Cloud AI environments are a core focus. We test across AWS Bedrock, Google Vertex AI, Azure AI services, and other cloud-native agent platforms. Cloud-hosted AI agents introduce unique risks including IAM misconfigurations for AI service accounts, over-permissioned agent roles, exposed model endpoints, and insecure tool integrations. Our methodology addresses these alongside the AI-specific risks of prompt injection, agent drift, and intent manipulation.
Can AI Agent Security Governance support our compliance requirements?
Yes. The service aligns with NIST AI RMF, OWASP LLM and Agentic Top 10, MITRE ATLAS, as well as broader frameworks including ISO 27001, SOC 2, PCI DSS, POPIA, and GDPR. AI-SPM maps each application’s coverage against these frameworks and identifies gaps. Full audit trails and reporting are provided for regulatory and audit evidence.
TAKE ACTION
CAN YOUR BUSINESS AFFORD TO BE HACKED?
Contact us for a no-obligation discussion about your AI roadmap.