As AI agents gain direct access to enterprise systems through Model Context Protocol, security leaders must treat MCP servers as a new class of unmanaged identity risk before they become the next shadow IT problem.
CISOs have spent the last two years building governance around shadow AI like acceptable-use policies, prompt-level DLP and approved model lists. AI governance was the obvious choice because 65% of employees are now using AI at work and 43% share sensitive information with these tools without their employer’s knowledge. Every control CISOs focused on was a response to this behaviour. Model Context Protocol is breaking this assumption because MCP servers let AI agents connect straight into enterprise systems without anyone typing into an LLM window.
MCP is the protocol organisations use to wire agents into databases, ticketing systems, code repositories and internal APIs. It sits underneath most agentic AI deployments in production today and yet only 8.5% of MCP servers use OAuth, with the rest running on static secrets or no authentication at all. What this means is that shadow AI governance policies aren’t reaching the access AI agents hold through MCP.
MCP access creates new risk
The access that AI agents have to MCP servers creates a new category of risk where the server itself becomes a non-human identity, with its own credentials and its own reach into enterprise systems. In most cases, there’s no owner and without one, no one checks what a server can see. This is probably why 15% of registered MCP servers publish no source code at all. A security team would not be able to verify what a server does with its access even if someone asked.
Researchers found over 42,000 exposed AI agent instances and more than 1,000 of them were running on unauthenticated MCP servers that leaked API keys, Slack credentials and chat histories onto the internet. Seven CVEs have hit MCP implementations in the past year, including a critical code execution flaw, revealing that no one owns the server so no one notices what it does until something breaks.
Security teams need to take ownership of this, starting with discovery at every endpoint, inspecting configuration files directly rather than watching a single central server. This ensures inventory of every installation including ones that aren’t managed centrally.
Once visible, MCP servers need the same scrutiny as any other identity. Log what its credentials actually touch, install mechanisms for approval at the host application before the tool executes, and include the server into the same non-human identity graph used for cloud accounts and API keys. This matters because an MCP server sitting in its own silo tells security teams nothing about how it connects to everything else.
“MCP servers are rapidly becoming the new shadow IT of the AI era, holding privileged access to critical systems without the governance, visibility, or accountability that CISOs expect from traditional identities.”
– Ben Mudie, Field CTO APJ, Tenable
Why exposure management matters here
An agent with access to private data, exposure to untrusted content and the ability to act on external systems is exactly the kind of toxic trilogy threat actors look to exploit. Tool descriptions travel to the model as part of its context, which gives an attacker a place to hide instructions inside a description field that a person probably doesn’t read but the model follows.
On its own, a hidden instruction doesn’t matter much but it needs a distribution channel and unofficial marketplaces offer it. One popular skill marketplace had roughly 1 in 5 listings turning out to be malicious, with no review step between publishing and installing. Combine that together and organisations get a poisoned description, a marketplace with no vetting and a server no one really owns.
It is important to prioritise risk because a poisoned description matters only if the AI agent reading it holds credentials, secrets or something worth stealing. An audited server matters only if it sits on a path to sensitive data. Most cybersecurity platforms aren’t built to map such combinations and offer the right context, but exposure management platforms do exactly that.
Exposure management extends the same contextual understanding for AI deployments by scoring an interaction based on its severity and business criticality. This gives teams the ability to plug the high-risk exposure first. A CISO working with a finite remediation budget needs vulnerability priority ratings because treating every MCP as equally urgent won’t guarantee that the right exposures are plugged first. Prioritisation turns MCP from a blind spot to a governed part of the AI programme.
With exposure management, CISOs can answer the three important questions: What AI is running? What can it reach? What is leaving the organisation through it? Answering those questions for chatbots and copilots while leaving MCP servers out of scope defeats the purpose, because it excludes the fastest-growing part of the agentic AI stack from the program.
MCP will keep expanding because it makes agentic AI useful and CISOs can’t really put that on hold. The real choice is expanding governance. CISOs who make that choice will extend exposure management to MCP the same way they already approach cloud and identity, with continuous discovery, context mapping and monitoring rather than periodic reviews. The ones that don’t will be left reacting to incidents instead of getting ahead of them.
Bio
Ben Mudie, Field CTO, Asia Pacific and Japan at Tenable
As Field CTO for APJ, Ben Mudie serves as a strategic advisor to global enterprises, operating at the intersection of customer advocacy, strategic advisory and technical expertise to help organisations understand and manage the modern attack surface.
He focuses on helping organisations close the “exposure gap” by leveraging unified platforms to gain context over their risk. His practitioner-first approach ensures that his strategic advice is always grounded in technical reality.
An engineer at heart, Ben has spent 20 years in the regional technology sector, with a deep focus on Exposure Management. He is a strong advocate for helping global organisations spot the vulnerabilities and hidden attack paths in their IT, cloud and AI environments.
Based in Sydney, Australia, Ben is a frequent contributor to the Asia Pacific security community and a speaker at cybersecurity conferences.
