STEADY · Pane 04

Security

Can we let AI see and act without leaking, escalating, or being hijacked?

Insight

  • Overshare hotspots, sensitivity label coverage, agent permissions, Conditional Access posture
  • Prompt and agent incident patterns

Action

  • Harden the data foundation before broad Copilot; apply least privilege for makers
  • Extend incident response runbooks to AI misuse and agent misbehaviour

Owner

CISO

Illustrative signals

  • Sites remediated
  • % labelled content
  • Privileged agent count
  • AI-related incidents

Standards bridges

  • ISO 27001
  • SOC 2
  • Microsoft secure Copilot foundation
  • SANS AI Security Maturity
  • MITRE ATLAS

Pane 04 sits in the STEADY arc.

Use this page as the canonical definition for Insight and Action. Signals are illustrative.