Session
From OWASP Theory to Enterprise Controls: Mapping the Agentic Top 10 to Deployable Controls.
The OWASP Top 10 for LLM Applications and the emerging Agentic Security risks have given the industry a shared vocabulary. But vocabulary doesn't ship security controls. Most organizations read the list, nod, and then have no idea what to deploy on Monday morning.
This session bridges the gap between OWASP's risk taxonomy and deployable enterprise security controls. For each major agentic risk , tool poisoning, excessive agency, confused deputy attacks, indirect prompt injection , the talk maps specific, implementable controls drawn from real enterprise deployments. Not theoretical mitigations. Actual architecture patterns, policy configurations, and detection rules.
The session includes a head-to-head security comparison of Claude Code vs. Cursor mapped against the OWASP Agentic Top 10, showing how different AI coding agent architectures create different attack surfaces and require different control strategies.
Key Learnings
• Translating OWASP Agentic Top 10 risks into specific, deployable enterprise security controls
• Architecture-level differences in AI coding agent security: Claude Code vs. Cursor attack surface comparison
• Implementing detection rules for tool poisoning and confused deputy attacks in production
• Building a threat model for multi-agent systems that goes beyond single-agent prompt injection
• A reusable mapping framework your team can apply to evaluate any AI agent deployment
Aakash Abhay Yadav
Managing CyberSecurity GRC | OWASP AI Exchange Author
San Francisco, California, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top