Episode 208: Secure Harness Engineering for Agentic AI
In episode 208 of Cybersecurity Where You Are, Sean Atkinson breaks down secure harness engineering for agentic artificial intelligence (AI). Noting the risks posed by AI agents acting without oversight, he highlights "episodes" as auditable elements that help to provide feedback, and he walks through 15 controls spread across five stages as a way to engineer an AI harness with security in mind. He also differentiates secure harness engineering from prompt engineering, guardrails, frameworks, logs, and universal wrappers for AI agents.
Here are some highlights from our episode:
- 01:23. The need for a control system in light of agent escape incidents
- 02:19. Analogy of a financial analyst to understand why separation of duties is important
- 02:57. Revolution and then evolution: How AI models have changed exponentially since 2022
- 04:54. Where secure harness engineering has a capability
- 05:42. Making decisions traceable: The need for an evidence chain to build controls effectively
- 07:15. Smartphones: A parallel for understanding the value of each new AI model
- 11:20. Engineering controls, not standard policies for all models
- 12:22. Secure harness engineering vs. prompt engineering
- 12:51. Models' evolving role: How it invites new security questions to be posed
- 15:16. AI agents without oversight: The insider persona with which defenders need to contend
- 16:02. The need for determinism and an effective diagram to build for it
- 18:22. Definition of secure harness engineering
- 19:36. Episodes and the importance of log assessment in mediating model capability
- 20:42. Reality verification: A feedback loop that gets into the concept of forensic assessment
- 21:27. Questions to ask as you get into an AI agent's evidence chain
- 22:56. Moving through intent, authority, reasoning, synthesis, decision, and enforcement
- 25:38. Side effects: What they are and how they actualize risk
- 27:16. Verification and audit: How they empower you to look at control opportunities
- 28:49. Five stages and 15 controls for secure harness engineering
- 29:47. What secure harness engineering is and is not
- 32:11. Three questions to help you get started
- 32:52. An important question for the future
Resources
- Artificial Intelligence (AI) Agents Companion Guide
- The Secure Harness: A Governance Architecture for Agentic AI
- When Agent Capability Outruns Control: Lessons from the July 2026 OpenAI and Hugging Face Incident
- Episode 202: Delineating AI Security and Cybersecurity
- Harness Engineering & Agent Orchestration
- OWASP Top 10 for Large Language Model Applications
If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.





