Threat model · AI and agent systems

AI Threat Atlas

Two views of the same problem. The scale shows how bad an outcome is and who it hits. The map shows where the breach happens. Every breach point links to the levels it feeds, and every level links back to its breach points.

Risk levels and who they hit

Seven levels, ordered by how many people are hurt and how hard the damage is to reverse. Select a step for its detail.

Levels 1 to 3 · We negate

Known causes, known controls. A good assessment and fix closes most of the exposure.

Levels 4 to 5 · We contain

Intent is involved. Prevention is partial, so limits, detection and recovery matter as much.

Levels 6 to 7 · We harden and escalate

Bigger than one client. Our job is resilience, early warning and getting the right authorities involved.

Attack surface

An AI system drawn as a data-flow diagram, with 36 numbered breach points. Dashed red marks what is outside your control. Filter by layer or by risk level, or play a full attack.

Show layer
Risk level
Play an attack

Select any numbered marker for how the attack works, a real case, and the defences. On a small screen, scroll the map sideways.

Each level in detail

Situations, what stops them, a benchmark case, and when to escalate. Select a numbered breach point to open it.

Breach point register

All 36 points from the map, grouped by layer. Codes such as LLM01 refer to the OWASP Top 10 for LLM Applications, 2025 edition.

Scoring a finding

Severity alone doesn't set priority. Multiply the level by how easy the attack is to reach. Every finding on the map gets one number.

12–21

Fix now. Stop the affected feature or remove the permission until it is fixed.

6–11

Fix this quarter. Owner and date assigned, retested when done.

1–5

Schedule. Track it and review at the next retest.

Any finding at level 6 or 7 goes to the executive team and the board regardless of its score. Low likelihood does not make a catastrophic outcome a routine ticket.

Where our role stops

At levels 6 and 7 no private firm negates the threat alone. We do not test whether a model will produce weapons or mass-casualty content; that work belongs to the model developers and government evaluators. What we do is make sure a client's agents cannot be used as a route into systems that matter, that someone notices quickly if they are, and that the client knows who to call: CISA and the FBI in the United States, plus the sector regulator.

Certifications and learning pathway

A two-year sequence for a founder who builds with AI and is new to security. Each stage has something to learn, something to prove, and somewhere to practise in public.

1
Months 0 to 3

Foundations

Speak the frameworks and understand every point on the map.

Learn
  • OWASP Top 10 for LLM Applications and for Agentic Applications
  • MITRE ATLAS case studies
  • NIST AI Risk Management Framework
  • PortSwigger Web Security Academy, including its LLM attack labs (free)
  • Hands-on secure coding labs such as SecureFlag
Prove
  • Nothing yet. Optional: CompTIA Security+ if you want general security basics on paper
Practise
  • Lakera's Gandalf prompt-injection game
  • Gray Swan Arena challenges
  • Break your own test agents with garak, PyRIT and promptfoo
2
Months 3 to 9

Hands-on AI security

Be able to run the technical part of an assessment alongside a contract tester.

Learn
  • Agent, MCP and RAG attack techniques: map points 3, 7, 13 and 17 to 26
  • Writing a finding: evidence, level, score, fix
Prove
  • CAISP, the first credential to get
  • CMCPSE for MCP, since MCP is where we lead
Practise
  • AI bug bounties, such as Anthropic's programme on HackerOne
  • Publish one piece of original research with real findings
3
Months 6 to 12

Governance and advisory

Be credible with the CTO, general counsel and auditor, who often hold the budget.

Learn
  • ISO/IEC 42001 and how audits work
  • Customer security questionnaires and what evidence satisfies them
  • Sector rules for your first clients
Prove
  • AIGP, the governance credential with no prerequisites
  • Optional: ISO/IEC 42001 Lead Implementer, CompTIA SecAI+
Practise
  • Contribute to the OWASP GenAI Security Project
  • First talk at a BSides event
4
Months 12 to 24

Depth and team

Put senior, recognised credentials on the team, mostly through hires and advisers.

Learn
  • Offensive security depth for whoever leads testing
  • Incident response for agents
Prove
  • OSAI for the technical lead
  • CISSP or CISM, then AAISM for a senior hire or adviser
  • SANS courses once the company can pay
Practise
  • DEF CON AI Village and larger conference talks
  • Annual benchmark report from our own assessment data
CredentialTypeCostNeedsCovers on the mapVerdict
CAISPPractical DevSecOpsHands-on exam: 5 challenges in 6 hours plus a report$1,099Basic Linux. No ML or deep security backgroundCore, tools, data, build. Maps to OWASP, ATLAS, NIST, ISO 42001Start here
CMCPSEPractical DevSecOpsMCP security specialist$699Not statedTools layer: points 17 to 20Add in stage 2
AIGPIAPPGovernance, multiple choiceCheck IAPPNone publishedGovernance around every level; no hands-on testingGet in year 1
ISO/IEC 42001 Lead ImplementerPECB and other training bodiesManagement-system course and examVariesNone formalSupports the vendor trust pack offerIf rung 3 sells
CompTIA SecAI+Launched February 2026Multiple choice, vendor neutral£218 UK voucherRecommended: Security+ and 2+ years in securitySecuring AI systems, AI governanceOptional
CompTIA Security+General security foundationAbout $425NoneClassic security: points 2, 4, 28, 33Optional
OSAI (AI-300)OffSec24-hour proctored red-team exam$1,749+OSCP-level skills recommendedOffensive testing across the whole mapFor the technical lead
AAISMISACAAI security management$459 / $599Active CISM or CISSPSecurity leadership for AI riskFor a senior hire
SANS SEC545GenAI and LLM application securityInstructor-led course$8,260Security fundamentalsCore and tools layersLater, company-paid

What the firm itself needs

SOC 2 Type II

Enterprise clients ask for it and acquirers require it. Start in year one; the audit period takes months.

Insurance and contracts

Technology errors and omissions, cyber and general liability cover, plus written authorisation and rules of engagement for every test.

Named expertise

Two or three security advisers and contract testers whose credentials stand behind the work until the team has its own.

Certificates support credibility; they do not create it. The research found no evidence that buyers or acquirers weigh any of these credentials, and found that peer recommendations and original research move them most. A completion certificate from a training platform is learning, not a credential. Prices were checked in October 2026, mostly from third-party pages, and CAISP, CMCPSE and OSAI figures come from Practical DevSecOps, which sells two of them. Confirm with each provider before paying.

Company roadmap

Six workstreams across three years. Revenue figures are planning targets worked out from the price bands in the research, not benchmarks from comparable firms.

Days 1 to 90Prove demandMonths 3 to 12Prove the methodYear 2Make it recurringYear 3Make it transferable
Method and tooling
  • Assessment playbook v1 built on the 36 points and 7 levels
  • Test lab: sample agents, MCP servers and a RAG app to attack
  • Report template with level, score, evidence, fix
  • Map v2 with a maintained incident feed
  • Crosswalk to OWASP, NIST AI RMF and ISO/IEC 42001
  • Scripted runs of garak, PyRIT and promptfoo per breach point
  • Automated 36-point test suite and report generator
  • Agent and MCP inventory tool for client environments
  • Re-baseline on every major model release
  • Annual benchmark report from our own assessment data
  • Decide whether the tooling stands alone as licensed software
Offers and revenue
  • 25 discovery calls with mid-market SaaS and AI vendors
  • 2 paid mapping sprints
  • 1 full assessment sold
  • 8 to 12 paid assessments
  • 3 to 4 subscriptions
  • About $250K to $400K
  • Subscription is the default follow-on
  • Vendor trust pack live
  • Subcontract work through integrators
  • About $1M to $1.5M
  • Multi-year subscriptions on assignable contracts
  • Optional self-serve tier of the tooling
  • About $2M to $3M, with $0.5M to $1M operating profit
Team
  • 2 to 3 named security advisers on small equity grants
  • 1 contract red-teamer on call
  • Test a possible security co-founder on one joint project
  • Bench of 3 to 4 contract testers
  • 2 senior non-founder deliverers hired
  • Founder off routine delivery
  • Second-line leadership in delivery and sales
  • Business runs through a six-month founder absence
Credibility
  • Founder active on scored challenge venues
  • Atlas shared with advisers for critique
  • CAISP and AIGP earned
  • First original research report
  • 2 referenceable case studies
  • 1 accepted talk
  • Course or workshop built on the playbook
  • Partner status with one or two platforms and an auditor referral channel
  • Benchmark report becomes the flagship
  • Major conference talk
Company readiness
  • Entity, bank, bookkeeping
  • E&O, cyber and general liability cover
  • Master agreement, authorisation letter, rules of engagement
  • SOC 2 started
  • Client data handling and retention policy enforced
  • Contractor IP assignment on every agreement
  • SOC 2 Type II report
  • Books split recurring, project and software revenue
  • Reviewed accrual financials
  • Data room kept current
Exit readiness
  • Every contract assignable from the first one
  • Track recurring share and client concentration monthly
  • 50%+ recurring
  • No client above 20% of revenue
  • 60%+ recurring
  • Conversations open with compliance, testing and integrator buyers
Gate to passFive buyers will pay $15K or more, and a credible security practitioner puts their name on the work.Clients renew, and at least a third of assessments convert to a subscription.Delivery quality holds when the founder is not on the engagement.A buyer's diligence finds recurring, transferable revenue.

If the first gate fails on the second test, stop and rethink. Without a credible security practitioner attached, this is a media business about AI security, which is a smaller and different company.

Offer ladder
Public atlas and incident feedFree
Mapping sprint$5K–$10K · 1 week
Agent and MCP assessment$15K–$40K · 2–3 weeks
Vendor trust pack$10K–$40K
Continuous assurance$4K–$12K a month

The last rung is the business. Every assessment proposal includes the subscription as the default next step. The mapping sprint price is our own estimate; the others come from published price bands.

Scorecard: what a buyer of the company will check
MeasureEnd of year 1End of year 2End of year 3Why it matters
Recurring share of revenue25%+50%+60%+Worth two to four turns of valuation multiple
Largest client's shareUnder 35%Under 20%Under 20%Buyers reprice above about 20%
Active subscriptions3 to 46 to 813 to 19Derived from the revenue targets at about $8K a month
Delivery done without the founder20%60%90%Founder dependence is the most common deal killer
ComplianceSOC 2 startedSOC 2 Type IIMaintainedEnterprise clients and acquirers both require it
Original research published1 report2 reportsAnnual benchmarkResearch has the strongest influence on security buyers

All targets are our planning figures.

Operating rules

How we work, from the first engagement. These protect clients, protect us, and are what make the company worth buying.

Authorisation first
  • No testing without a signed authorisation, a written scope and rules of engagement
  • The founder does not lead offensive testing of client production systems until a senior security practitioner is on the team
  • Stop and call the client the moment a test touches something out of scope
Evidence standard
  • Every finding carries proof it can be reproduced, a level, a score, a fix and a retest result
  • Every public claim has a source. No incident goes on the atlas unchecked
  • We report what we could not test as plainly as what we did
Client data
  • Collect the least data the test needs; encrypt it; delete it on a fixed schedule
  • No client data in consumer AI tools, ever
  • Our own agents are assessed against the atlas every quarter
Independence
  • Vendor neutral. No referral fee from a product vendor without telling the client
  • We never certify our own remediation work as an independent audit
  • Auditors are referral partners; we sell readiness and testing
Disclosure and escalation
  • Flaws found in third-party products go to the vendor first, with a 90-day default before publication
  • Level 6 or 7 findings reach the client's executives the same day
  • Any threat to life or public safety goes to the authorities. We do not test weapons content
Built to transfer
  • Annual, assignable contracts by default
  • Playbooks and tooling belong to the company; every contractor signs IP assignment
  • Anything done twice gets written into the playbook
Where we stay ahead
Re-test on every model release
  • Major models change every six to eight weeks, and each change can reopen a closed finding. A standing test suite that re-runs on release is the reason a subscription exists
Agents testing agents
  • Use AI agents to run the repeatable parts of an assessment, with a human reviewing every finding. This is where our AI-building skill is an advantage over traditional testers
Inventory before testing
  • Most clients cannot list their own agents, MCP servers and tokens. A tool that produces that list in days is the fastest way into an account
Our own incident data
  • A maintained, sourced incident feed tied to the 36 points. Data we collect ourselves is what an acquirer cannot copy
Agent incident response
  • Playbooks and rehearsals for a hijacked agent: how to stop it, what it could reach, how to recover. Few firms offer this yet
Findings people can read
  • Reports a CTO, lawyer or board member understands at a glance. Visual explanation is a real edge in a field known for unreadable reports
Risk register
RiskWhat it looks likeOur response
Platform absorptionAutomated testing becomes a free feature of tools clients already ownSell judgement, independence and governance on top of free tooling; never depend on one tool
CredibilityPolished material with thin technical depth, which buyers already penaliseNamed advisers, contract testers, verified findings, public track record
Thin services marginsProject work that earns little after contractor costsFixed-fee offers, automation of repeat work, subscription as the default
Client concentrationOne consulting relationship supplies most of the revenueTrack monthly; cap any client at 20% by year two
LiabilityA test damages a client system, or a missed flaw is later exploitedAuthorisation and scope on paper, insurance, liability caps in the master agreement
A dated atlasThe 36 points stop matching how systems are attackedQuarterly review of the points against the incident feed

A learning order

  1. Start with point 7. Understand why a model can't separate instructions from data. Everything else in AI security follows from that one fact.
  2. Then points 3, 13 and 17. Untrusted content in, a channel out, and too much power in the middle. Play the "Zero-click email leak" chain until each step is obvious.
  3. Then the tool layer, 17 to 24. This is where MCP and agents live and where the field is moving fastest.
  4. Then the data plane, 25 to 29. Retrieval and permissions are the most common real-world enterprise finding.
  5. Then the build plane, 30 to 35. Supply chain is slower to exploit and harder to detect.
  6. Last, classic security. Points 2, 4, 28 and 33 are ordinary application and cloud security. They still account for many AI incidents.

Frameworks to know