The Model Framework Protocol (MCP) allows AI agents to connect to data sources, but the first version of this standard lacked serious security. In recent months, a slew of vendors have emerged to help solve the problem. Is the technology now ready for prime-time, or is it still too early to put it into production?
See also: Prompt hijacking compromises MCP-based AI workflows

There has been some progress on the core protocol side. In March, support for OAuth authentication was added, and in June, the protocol added support for third-party authentication servers like Auth0, Okta, or a company's identity management system.
The MCP standardization body also launched an official MCP registry in September to address the problem of malicious MCP servers masquerading as legitimate ones. However, significant security gaps remain. For example, authentication is optional and the systems are vulnerable to direct imports, tool poisoning, token theft, server-to-server attacks, message forgery, and more.
Companies that want to get ahead of the competition in building artificial intelligence (AI) systems must put a lot of effort into security to prevent these tools from revealing all their corporate secrets and sensitive data.
And, in recent months, vendors have stepped up their efforts. Today, major AI platforms have added security infrastructure, as have core technology providers, existing cybersecurity vendors, and a fleet of emerging players.
There are three main types of MCP server deployments, and each has its own security challenges.
See also: MCPTotal launches for secure MCP enterprise workflow management

When a company installs an internal MCP server, on infrastructure it controls, to access internal data or tools, to be used by AI agents it also controls.
First, a low-risk use case might be to allow employees to use AI agents to search non-sensitive documents or databases, such as product descriptions. A higher-risk use case might be to allow access to customer data.
Second, a company may allow its AI agents to access external data sources or tools through MCP servers. Here, a concern may be that the information the AI agents receive back may contain malicious instructions because either the server or the data source has been compromised by an attacker.
The third type of deployment is that of an internal MCP server that exposes a company’s data or tools to the outside world. Again, this could be a low-risk use case if the MCP server provides access to product descriptions or user manuals. But it could also be extremely risky if the MCP servers allow external partners to connect and place orders, submit invoices, and change their payment addresses.
What to Look for in an MCP Security Platform
Whether a company connects its own AI agents to third-party MCP servers, its own MCP servers to third-party agents, or its own servers to its own agents, there is a potential for data leakage, direct data injection, and other security threats.
This means companies should check for authorizations and permissions, implement granular access controls, and log everything, says AllCloud.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Serious vulnerability in Figma MCP allows RCE attacks

Here are some other MCP security tools that vendors offer today:
- MCP Server Detection: It is easy for company employees to download and run their own MCP servers. These servers could enhance their productivity or could become a new attack vector. Some MCP security vendors offer scanning services to help companies find all instances of shadow MCP servers in their environments.
- Runtime protection: AI agents communicate with MCP servers in plain English. This creates the potential for direct intrusions, data leaks, and other security issues. Many MCP security vendors offer tools to monitor all communications for these and similar issues.
- Authentication and access control: The core MCP protocol now supports OAuth, but that’s just the beginning. For additional security, vendors offer zero-trust and least privilege control frameworks.
- Logging and observability: Vendors can provide platforms to collect MCP logs, notify security teams about security events or policy violations, collect compliance data, or feed logs into an existing security infrastructure.
