Skip to content

06 · The wiring

Securing MCP

A firm that wires agents to its systems over MCP is running new privileged software on its own perimeter. The vendor-neutral guidance for securing it is young; these are the citable documents.

Careful Adoption of Agentic AI Services

CISA, NSA, ACSC, CCCS, NCSC-UK, NCSC-NZ · May 2026 · advisory guidance

Joint guidance from six national cyber agencies for organisations adopting agentic AI services. The most authoritative signature on this list.

cisa.gov↗

Managing the cyber risk of agentic AI

NCSC-UK · Aug 2026, interim · advisory guidance

Interim practical advice pending formal guidance: threat modelling, instructions, oversight, a robust sandbox, logging and monitoring, attributable activity, and the ability to pull the plug.

ncsc.gov.uk↗

MCP specification, 2026-07-28 release

Model Context Protocol maintainers · Jul 2026 · protocol release

Authorization hardening in the protocol itself: RFC 9207 issuer validation, a formal shift from Dynamic Client Registration to client metadata documents, Enterprise Managed Authorization as an extension, and a twelve-month minimum deprecation window.

modelcontextprotocol.io↗

MCP Top 10

OWASP · beta, revision due Oct 2026 · risk list

Ten risk categories for MCP deployments, MCP01:2025 through MCP10:2025, from token mismanagement to shadow MCP servers.

github.com/OWASP↗

Secure MCP Server Development

OWASP GenAI Security Project · Feb 2026 · guide

For firms running their own servers: architecture, authentication and authorisation, validation, session isolation, hardened deployment.

genai.owasp.org↗

Third-Party MCP Servers CheatSheet

OWASP GenAI Security Project · v1.0, Nov 2025 · cheat sheet

For servers you did not write: tool poisoning, prompt injection and memory poisoning risks, with vetting, sandboxing, least privilege and oversight as the mitigations.

genai.owasp.org↗

MCP-Security-Checklist

SlowMist · MIT licence, maintained · checklist

Priority-tagged items across server, client, multi-MCP scenarios and LLM adaptation. Written by a blockchain-security firm rather than a standards body; narrow and practical.

github.com/slowmist↗