Doron Sivan, CEO & Co-Founder, MADSEC Security, SQLink Group.
Guarding Agentic AI

“I have not seen an AI agent that has directly improved an organization's security posture”

Doron Sivan, CEO & Co-Founder at MADSEC Security, joined CTech to share his thoughts on agentic AI security, and why he's still skeptical that agents themselves have made anyone more secure, even as he pushes clients to adopt them carefully. 

“I have not seen an AI agent that has directly improved an organization's security posture, aside from security products that incorporate AI-agent capabilities into their platforms,” said Doron Sivan, CEO & Co-Founder of MADSEC Security (SQLink Group), on where AI agents have actually made things better or safer.
“There is no doubt that AI agents can significantly improve many administrative and business processes, which is why we are actively promoting their use — but in a thoughtful and controlled manner,” he explained.
1 View gallery
Doron Sivan, CEO & Co-Founder, MADSEC Security, SQLink Group.
Doron Sivan, CEO & Co-Founder, MADSEC Security, SQLink Group.
Doron Sivan, CEO & Co-Founder, MADSEC Security, SQLink Group.
(Photo: Tami Bar Shalom)
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
At the moment, there is strong demand from users to develop AI agents, driven by the need to improve and accelerate processes. However, under the AI policy that Madsec also implements for its clients, every agent is reviewed and documented with the IT manager and information security manager, and must also receive approval from the organization's AI committee.
What security controls are in place versus on the roadmap?
As a cybersecurity consulting company, at Madsec we recommend aligning with the NIST AI Risk Management Framework (AI RMF 1.0). As part of this approach, we have implemented—and recommend—first identifying which AI agents and MCP servers exist within the organization and which systems they are connected to. Each agent is assigned a unique identity and is granted the appropriate permissions. The next step on the roadmap is coordination with the monitoring company providing SIEM/SOC services, in order to minimize false positives while simultaneously monitoring for anomalous activity. At the next stage, we are evaluating and recommending products designed to prevent the transmission of sensitive information. This stage also connects to the broader AI policy issue, particularly the question of who is authorized to stop an agent and how long it should take to shut down a rogue agent. From this perspective, as a cybersecurity consulting company, we are naturally at the forefront of this area.
Have you had an incident or near-miss?
AI agents generate a significant number of alerts. For example, an EDR solution may detect activity that appears suspicious, attempt to neutralize it, and alert the SOC team. From a security-incident perspective, there have been alerts, of course, but strict permission management helps minimize these situations. The greater challenge comes from external companies that sell AI agents to organizations. Here as well, maintaining a testing environment and following a hardening process currently provides a good level of protection.
What's your biggest fear about agentic AI rollout in the tech industry right now?
The biggest concern is the speed at which organizations are adopting these technologies without properly examining all the layers of security and policy described above. It is important to remember that many of the people creating agents are not developers and do not necessarily have the tools or expertise to understand which actions they took may have resulted in the creation of a dangerous agent—for example, one containing sensitive information such as keys, vulnerable code, or overly broad permissions. This becomes even more problematic when an employee leaves the organization and the company is left with an agent that has no proper documentation, oversight, or management. Even today, a great deal of information is leaking out of organizations, while security teams have too few resources to deal with the problem. That is why it is critical to follow the procedures and controls I mentioned above.