Session

MCP Servers Are a New Attack Surface: How to Securely Build and Use Them

Model Context Protocol (MCP) is only as secure as the server you build it on. In under two years, it has become the standard integration layer connecting AI agents to enterprise systems, databases, source code, and production APIs. However, an agent crosses a trust boundary on every tool call and resource fetch, and the protocol leaves the server to decide what is allowed. If the server does not enforce those boundaries, nothing else will.

Grounded in real-world incidents and contributions to the OWASP GenAI Security Project, this practitioner-focused talk provides an actionable builder’s guide to securing MCP architectures.

We address both sides of the trust boundary, how to build secure MCP servers and how to vet third-party ones:
⚬ Architecture & Attack Surface: Why choosing the smallest deployment model (stdio vs. HTTP) and building focused, task-shaped tools drastically reduces prompt injection and tool-poisoning risks.
⚬ Builder's Defense Triad: Practical implementation of input validation, policy enforcement, and process containment.
⚬ Consumer Vetting Checklist: Essential checks to sandbox, isolate, and monitor third-party MCP servers before connecting them to your models.

Attendees will leave with a clear mental model of MCP trust boundaries and a concrete set of guardrails to apply on Monday morning.

Delivered at BSides Las Vegas 2026 to an engaged audience of security engineers and AI practitioners. The session is practical and vendor-neutral, drawing on my experience as a security engineer and contributor to the OWASP GenAI Security Project guidance on third-party MCP usage.

Saquib Saifee

Security Engineer @ IBM, CISSP, eCPPT

Raleigh, North Carolina, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top