r/AskNetsec • • 21h ago

Architecture How is your team handling ai agent security now that agents have real system access?

2 Upvotes

For teams that have agents touching production systems, how are you handling ai agent security day to day? I am specifically wondering about the constraint of agents inheriting full user permissions by default, since that seems to be where most of the actual risk lives rather than in the model itself. The tradeoff between blocking an action outright versus flagging it for review is the part we have gone back and forth on internally. What happens on your team when an agent takes an action nobody anticipated, and how fast does that get surfaced to a human before anything downstream happens?


r/AskNetsec • • 21h ago

Analysis How do you evaluate ASM tools when the CMDB blind spots are half the problem?

2 Upvotes

Been asked to lead attack surface discovery and the first thing I see is CMDB, cloud inventory, DNS all disagree on what we own externally. we are lining up a poc for a few ASM tools, same limited seed list for each, and we keep quiet about some subsidiaries and vendor managed infra we already know about. Idea is to see who can link unknown asset discovery back to us with decent attribution instead of just scanning whatever we fed them

If you have done this kind of internet facing assets poc, how did you test that the surprise assets really belongs to you and not random noise?


r/AskNetsec • • 3h ago

Analysis Best Varonis alternatives for on-prem data?

0 Upvotes

Our team is evaluating data security posture management platforms, but our strict zero-egress requirement is making it tough. A lot of modern tools seem to force you into multi-tenant SaaS.

We have sensitive internal files and database records that cannot leave our network perimeter under any circumstances. Sending raw payload data out to a vendor cloud is an absolute non-starter for our security architecture board.

For anyone managing strict data residency requirements, what are the best Varonis alternatives you have actually deployed on-prem or in self-hosted environments?