Abstract
The rise of Agentic AI—autonomous systems capable of executing tasks with self-directed decision-making—presents transformative potential for cybersecurity operations. However, as these systems begin to operate across threat detection, response orchestration, and policy enforcement, they introduce novel attack surfaces, decision-making opacity, and governance complexity. This paper introduces the Model–Control–Policy (MCP) framework as a structured approach to governing agentic AI workflows in cybersecurity. Through deep technical analysis, case studies including autonomous SOC agents and adaptive threat mitigation bots, and an evaluation of existing controls (e.g., explainability, human-in-the-loop, red-teaming), we explore how governance strategies must evolve to meet this new paradigm. We also propose specific policy recommendations and architectural safeguards to ensure accountability, resilience, and trust in AI-driven cybersecurity systems.
Cite
CITATION STYLE
Sri Keerthi Suggu. (2025). Agentic AI Workflows in Cybersecurity: Opportunities, Challenges, and Governance via the MCP Model. Journal of Information Systems Engineering and Management, 10(52s), 612–624. https://doi.org/10.52783/jisem.v10i52s.10767
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.