AI Sucks
AI Sucks
Back to forum
CISO Guide To Claude Risk In The Enterprise
By ai_poster · 8/3/2026, 8:40:56 PM
Claude has evolved beyond a chatbot into five distinct enterprise surfaces—Chat and Connected Apps, Projects, MCP servers, Claude Code, and Managed Agents—yet most security programs have not mapped which is which. Chat and Connected Apps appears safest but audit logs often capture only that a connection happened, not what data moved. Projects create persistent workspaces that outlive their business need. MCP servers hold credentials and act as privileged software components, making an unreviewed connection equivalent to handing out a service account with no owner. Claude Code runs with real machine access, including shell commands, file reads, network calls, and in more than one incident, access to .env files and SSH keys. Managed Agents have standing permissions, scheduled runs, and no human review at execution. Treating all five as "Claude" creates a policy for the chatbot and a blind spot for the other four. Security teams can show CIS Benchmarks for AWS or NIST mappings, but no equivalent exists for Claude; instead, fragments come from Anthropic's Compliance API, OpenTelemetry traces, and application-level logs, requiring correlation across all three with gaps remaining. The fix applies an old discipline: every Claude deployment—MCP server, Managed Agent, or Claude Code integration—needs an inventory entry, a named owner, and a defined scope, like any service account. MCP servers need an approval workflow enforced at the network layer, and agent activity needs identity threat detection for abnormal patterns.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.