Conference Description
Key Takeaways
- Focused on securing Model Context Protocol (MCP) implementations in enterprise AI agent deployments
- Addresses emerging attack vectors including prompt injection, tool poisoning, and agent privilege escalation
- Features guidance from OWASP contributors and active security researchers
- Designed for security architects, AI security engineers, and application security teams
- Includes the launch of a practical guide for securing MCP-enabled systems
Introduction
The Securing the Model Context Protocol Summit brings together security professionals tasked with evaluating and defending AI agent deployments in enterprise environments. As organisations accelerate their adoption of agentic AI systems capable of accessing enterprise data, invoking tools, and executing actions across business infrastructure, the Model Context Protocol has emerged as a foundational layer enabling these capabilities. This summit addresses the security implications that accompany MCP’s growing prevalence, offering practitioners the frameworks and controls necessary to manage associated risks.
Understanding the Model Context Protocol Security Landscape
The Model Context Protocol provides a standardised mechanism for AI agents to interact with external tools, data sources, and enterprise systems. While this interoperability accelerates agent capabilities and simplifies integration, it simultaneously introduces attack surfaces that traditional application security models were not designed to address. Security teams now face the challenge of evaluating risks that span the boundaries between AI models, enterprise infrastructure, and third-party services.
The summit examines several critical threat categories that have emerged alongside MCP adoption. Prompt injection attacks remain a persistent concern, where malicious inputs attempt to manipulate agent behaviour. Tool poisoning represents a newer vector in which compromised or malicious tools are introduced into an agent’s available capabilities. Agent privilege escalation occurs when AI systems acquire access beyond their intended scope, potentially through chained tool invocations or exploited trust relationships.
Additional concerns include data leakage through agent interactions, the inherent trust placed in third-party MCP servers, runtime manipulation of agent behaviour, and supply-chain compromise affecting MCP components. Each of these vectors requires distinct assessment methodologies and defensive controls.
OWASP Guidance and Practical Frameworks
The summit features contributions from OWASP members and security researchers who are actively developing secure adoption patterns for MCP implementations. Presentations include the OWASP Secure MCP Blueprint, which provides architectural guidance for organisations deploying MCP-enabled systems, and the OWASP Top 10 for MCPs, a classification of the most significant risks facing these deployments.
Practical demonstrations include the Damn Vulnerable MCP Server, an intentionally vulnerable implementation designed for security training and testing, alongside MCP-Scanner Threat Discovery, which addresses the identification of vulnerabilities in existing deployments. These resources offer security teams hands-on tools for both education and operational assessment.
Enterprise Architecture and Governance Considerations
Beyond individual vulnerabilities, the summit addresses the broader architectural and governance challenges that accompany enterprise-scale AI agent deployments. Sessions cover risk assessment approaches tailored to MCP implementations, security controls appropriate for production environments, and governance frameworks for organisations scaling their use of AI agents across multiple business functions.
The event also marks the launch of Securing the Model Context Protocol: Defend agentic AI systems from supply chain, runtime, and code execution threats, a practical guide intended to support organisations implementing MCP-enabled systems.
Who Should Attend
The summit is designed for professionals responsible for the security of AI systems within their organisations. This includes security architects evaluating MCP adoption, AI security engineers implementing defensive controls, application security teams assessing agent integrations, security leaders developing governance policies, platform security teams managing infrastructure, and cloud security professionals addressing deployment risks in distributed environments.
Attendees will leave with actionable guidance on the security implications of MCP-enabled architectures, common attack paths targeting agentic AI systems, and the controls necessary to defend enterprise deployments against emerging threats.

