AI Security · Runtime · Supply Chain

Postura de segurança das tecnologias de IA

Avaliação dos quinze vetores de ataque de IA, dos nove controles de runtime governance, da descoberta contínua de AI-SPM e da exposição da cadeia de suprimentos de modelos, MCPs e agentes.

Cobertura AI Security

21%

15 vetores avaliados

Cobertura Runtime

32%

9 controles de runtime

Exposição cibernética máx.

10/10

Tecnologias com privilégio excessivo

11

controle ausente

Lacunas — AI Security (OWASP Top 10 LLM / SANS)

Cobertura do controle no portfólio, do menor para o maior.

Indirect Prompt Injection (0/16)0%
Agent Takeover (0/16)0%
Lateral Movement (0/16)0%
RAG Poisoning (1/16)6%
Hallucination (2/16)13%
Data Exfiltration (2/16)13%
Adversarial Attacks (2/16)13%
Privilege Escalation (2/16)13%
Model Poisoning (3/16)19%
Supply Chain Attack (3/16)19%
Prompt Injection (4/16)25%
Excessive Permissions (5/16)31%
Jailbreak (7/16)44%
Secrets Exposure (8/16)50%
Data Leakage (11/16)69%

Lacunas — AI Runtime Governance

Cobertura do controle no portfólio, do menor para o maior.

Runtime Platform Risk (0/16)0%
Runtime Resilience (1/16)6%
Runtime Enforcement (1/16)6%
Runtime Segregation (3/16)19%
Runtime Policy Controls (3/16)19%
Runtime Observability (4/16)25%
Runtime Security (7/16)44%
Runtime Monitoring (13/16)81%
Runtime Logging (15/16)94%

Exposição de segurança por tecnologia

TecnologiaExp. segurançaSecurity ctrl.Runtime ctrl.Supply chainPrioridade
Agentes autônomos de back-office10.07%11%7.0Auditoria imediata
MCP Gateway corporativo9.513%22%9.0Próximo ciclo
Microsoft 365 Copilot9.027%33%4.0Monitoramento contínuo
Azure OpenAI Service8.033%44%7.0Próximo ciclo
GitHub Copilot / Cursor8.020%22%8.0Monitoramento contínuo
Glean (AI Search corporativa)8.013%22%6.0Monitoramento contínuo
ServiceNow AI Agents8.013%22%7.0Monitoramento contínuo
ChatGPT Enterprise8.020%11%6.0Monitoramento contínuo
UiPath / Automation Anywhere Agentic8.013%33%7.0Próximo ciclo
Amazon Bedrock7.027%56%8.0Monitoramento contínuo
Salesforce Agentforce7.020%33%6.0Monitoramento contínuo
Google Gemini / Vertex AI7.020%33%7.0Monitoramento contínuo
AI Security Posture (Palo Alto / CrowdStrike)7.040%44%6.0Observação
Copiloto de crédito (motor de decisão)6.527%44%6.0Próximo ciclo
Databricks Mosaic AI6.027%56%6.0Monitoramento contínuo
AI Observability (Arize / LangSmith)6.013%33%5.0Observação

Context Engineering

Risco médio do domínio6.7/10
  • Context Management
  • Context Lineage
  • Context Security
  • Context Classification
  • Context Leakage
  • Context Poisoning
  • Retrieval Context Quality

AI-SPM

Risco médio do domínio6.6/10
  • Model Discovery
  • Agent Discovery
  • MCP Discovery
  • Attack Surface Mapping
  • Vulnerability Identification
  • Security Drift
  • Exposure Mapping

AI Supply Chain

Risco médio do domínio6.6/10
  • Open Source Models
  • Marketplace Models
  • Third Party Providers
  • External Dependencies
  • External APIs
  • MCP Marketplaces
  • Agent Marketplaces

Agentes autônomos de back-office

Fornecedores e dependências: LangGraph · MCP marketplace público · APIs transacionais internas

Vetores de ataque cobertos

1/15 · 7%
  • Prompt Injection
  • Indirect Prompt Injection
  • Jailbreak
  • Hallucination
  • Data Leakage
  • Data Exfiltration
  • RAG Poisoning
  • Model Poisoning
  • Adversarial Attacks
  • Supply Chain Attack
  • Secrets Exposure
  • Excessive Permissions
  • Agent Takeover
  • Privilege Escalation
  • Lateral Movement

Runtime governance

1/9 · 11%
  • Runtime Security
  • Runtime Observability
  • Runtime Resilience
  • Runtime Monitoring
  • Runtime Logging
  • Runtime Segregation
  • Runtime Enforcement
  • Runtime Policy Controls
  • Runtime Platform Risk

MCP Gateway corporativo

Fornecedores e dependências: MCP registries públicos · Servidores MCP de terceiros · Conectores comunitários

Vetores de ataque cobertos

2/15 · 13%
  • Prompt Injection
  • Indirect Prompt Injection
  • Jailbreak
  • Hallucination
  • Data Leakage
  • Data Exfiltration
  • RAG Poisoning
  • Model Poisoning
  • Adversarial Attacks
  • Supply Chain Attack
  • Secrets Exposure
  • Excessive Permissions
  • Agent Takeover
  • Privilege Escalation
  • Lateral Movement

Runtime governance

2/9 · 22%
  • Runtime Security
  • Runtime Observability
  • Runtime Resilience
  • Runtime Monitoring
  • Runtime Logging
  • Runtime Segregation
  • Runtime Enforcement
  • Runtime Policy Controls
  • Runtime Platform Risk

Microsoft 365 Copilot

Fornecedores e dependências: OpenAI (via Azure) · Microsoft Graph · Marketplace de agentes

Vetores de ataque cobertos

4/15 · 27%
  • Prompt Injection
  • Indirect Prompt Injection
  • Jailbreak
  • Hallucination
  • Data Leakage
  • Data Exfiltration
  • RAG Poisoning
  • Model Poisoning
  • Adversarial Attacks
  • Supply Chain Attack
  • Secrets Exposure
  • Excessive Permissions
  • Agent Takeover
  • Privilege Escalation
  • Lateral Movement

Runtime governance

3/9 · 33%
  • Runtime Security
  • Runtime Observability
  • Runtime Resilience
  • Runtime Monitoring
  • Runtime Logging
  • Runtime Segregation
  • Runtime Enforcement
  • Runtime Policy Controls
  • Runtime Platform Risk