Agentic AI Security · MAESTRO · OWASP · MITRE ATLAS

A pentest finds bugs. A threat model finds design flaws.

Your agents plan, remember and act. They hold credentials and call tools your last pentest never scoped. I threat-model your multi-agent architecture with CSA MAESTRO, the OWASP Top 10 for Agentic Applications and MITRE ATLAS, then map every finding to the EU AI Act and NIS2. Fixed price. Independent. No tool to sell.

Book a free 30-min Idea Call →
The Attack Surface Nobody Scoped

Every agent is a non-human identity with keys, permissions and an attack surface.

Agentic systems break the assumptions AppSec reviews are built on. The prompt is an input channel. The tool call is a privilege boundary. The memory is a persistence layer. Goal hijacking, tool misuse, memory poisoning and cross-agent escalation do not show up in a scanner and rarely in a classic pentest.

The incidents are no longer hypothetical. EchoLeak (CVE-2025-32711) exfiltrated data from Microsoft 365 Copilot without a single click. OWASP shipped a dedicated Top 10 for Agentic Applications in December 2025 because the LLM Top 10 no longer covered what agents do. If your agents run in production, this is your current exposure.

The scanner finds what you built wrong. The threat model finds what you designed wrong, before an attacker does.
Concrete Deliverables

What you walk away with.

Methodology you can cite in your next audit. Findings your engineers can ship.

Threat Model of Your Agent Architecture

Scenario-driven attack trees across every agent, tool, memory and orchestration layer. Built along MAESTRO's seven layers, mapped to OWASP ASI01 to ASI10 and MITRE ATLAS techniques.

Non-Human Identity and Permission Review

Which agent holds which credential, which tool grants which privilege, and where scoped identities replace shared API keys.

Report with Remediation Roadmap

Prioritized fixes scored by effort and impact, from quick wins in the system prompt to architectural changes in the orchestration layer.

EU AI Act and NIS2 Mapping

Each finding tied to the regulatory requirement it serves, so the security work counts twice: hardening and compliance evidence.

Optional Continuous Retainer

Re-assessment per release, an updated threat model as you ship new agents, and a standing security contact for your team. EUR 1,500 to 3,000 per month.

Core Assessment

Agentic AI Security Assessment

€12,000 to €18,000 · 2 to 4 weeks · remote or on-site

Priced by the complexity of your agent architecture. Includes discovery, threat modeling, EU AI Act and NIS2 mapping, the written report with remediation roadmap, and the executive read-out. Optional continuous retainer from €1,500 to €3,000 per month.

Book a free Idea Call to scope it
How It Runs

From architecture to a hardened system in three stages.

A focused engagement, typically 2 to 4 weeks from kick-off to read-out.

Stage 1

Architecture Discovery

We map agents, tools, data flows, memory and trust boundaries. Nothing gets modeled that we have not first understood.

Stage 2

Threat Modeling

Attack trees per scenario, worked along MAESTRO's seven layers and checked against OWASP Agentic and MITRE ATLAS.

Stage 3

Roadmap and Read-out

Findings become a prioritized remediation roadmap, walked through with your engineers and your leadership.

Track Record

I build multi-agent systems. And I take them apart.

The assessment comes from the builder's side, not from an audit checklist. This is work I show on stage and run in production.

Talk · AWS Community Day Istanbul 2026

Your Agent Is Your New Layer 8

Why autonomous agents behave like a new human layer in your organisation: with all the security consequences that brings.

Session · AWS Community Day Istanbul 2026

Securing Agent Identity

How agents get their own identities, scoped permissions and auditable access instead of shared API keys.

Live build · AWS Community Day Athens 2026

A multi-agent crew, built on stage

A multi-agent film crew shown live: specialised agents planning, producing and reviewing against real constraints.

Enterprise work

Multi-agent deep dives

Technical deep dives on hybrid multi-agent architecture and platform engineering for enterprise teams, plus hands-on Amazon Bedrock AgentCore workshops.

The Green Light

Up to 100% AWS funded.

As an AWS Community Hero, I navigate the funding process with you, from application to approval. Eligibility is assessed in the first 30 minutes, not added as an afterthought at the end.

PoC Funding

Up to €10,000

Covers prototype development. Deliverables engineered to meet funding requirements.

Migration Funding

Up to €400,000

For larger cloud transformation projects. Multi-phase plan structuring and end-to-end application support.

Questions Buyers Ask

Answers, in writing.

Threat modeling, red teaming or a pentest: which one does my agent architecture need?

In that order. A threat model finds the design flaws and tells you where red teaming and pentesting are worth the money. Running a pentest against an unreviewed agent architecture tests the walls of a house with no locks.

What is MAESTRO threat modeling?

MAESTRO is the Cloud Security Alliance's threat-modeling framework for agentic AI: seven layers from foundation model to agent ecosystem. It is the most complete lens for multi-agent systems available today, and the assessment applies it end to end.

What is the OWASP Top 10 for Agentic Applications?

The OWASP GenAI Security Project's ranking of agentic risks, released in December 2025: from ASI01 Agent Goal Hijack to ASI10 Rogue Agents. The report maps every finding to these IDs so your team can track them in familiar terms.

Which stacks do you assess?

Amazon Bedrock and AgentCore, CrewAI, LangGraph and LangChain, plus custom orchestration. I build on these stacks myself. The assessment does not depend on any specific vendor.

What does an agentic AI security assessment cost?

EUR 12,000 to 18,000 fixed, depending on the complexity of the architecture. The continuous retainer runs EUR 1,500 to 3,000 per month. Both prices are on this page on purpose: comparable engagements are quoted at USD 35,000 and up.

Your agent holds credentials. So it holds rights

FREE DECK

Agent Security Check

An autonomous agent holds credentials, calls tools and touches systems. This is where the findings pile up.

  • The attack paths
  • Two regulations with deadlines
  • A placement map
  • Two worksheets

37 pages. Large type, one idea per page, sources on every page. Double opt-in: you confirm by email first. Unsubscribe with one click.

Linda Mohamed
Your consultant

Linda Mohamed

AWS Community HeroIndependent ConsultantBedrock · CrewAI · LangGraphEN & DE delivery

An independent practice for organisations that want their AI agents assessed by the person who builds them. AWS Community Hero, speaker at AWS Community Days in Istanbul and Athens 2026, and builder of production multi-agent systems on Amazon Bedrock, CrewAI and LangGraph. Based in Vienna, Austria. Remote or on-site, English or German.

Book a free 30-min Idea Call →
Architecture

Where agents cross boundaries.

Findings cluster in the same places: identities, tool permissions and what reaches the model. The review follows the OWASP Top 10 for Agentic Applications[7], MITRE ATLAS[8] and MAESTRO[9].

Agent deployment on AWS: one IAM role per agent, secrets in Secrets Manager, weights encrypted at rest, logs in CloudWatch.
What a threat model looks at: every agent has its own identity and role, secrets live outside the code, model weights are encrypted, and every call leaves a log. The example is a reference project from my lecture.Source: Linda Mohamed, lecture “Von Managed zu Hybrid: KI-Architekturen”, Hochschule Burgenland, 2026
Data boundary on a managed model: application, private data and retrieval stay in your environment; only permitted context crosses to the model endpoint.
The boundary question behind most findings: which context, tools and data may cross to the model, and who decided that.Source: Linda Mohamed, lecture “Von Managed zu Hybrid: KI-Architekturen”, Hochschule Burgenland, 2026
AWS services

The AWS services behind this work.

The AWS controls that come up in almost every agent review. Each name links to the official documentation.

AWS Identity and Access Management (IAM)

Who and what may call which service. For agents: one narrow role per agent.

AWS CloudTrail

Records every API call in the account, the audit trail for what an agent actually did.

Amazon Bedrock Guardrails

Filters for topics, harmful content and personal data on the way into and out of the model.

Amazon Bedrock AgentCore

Runtime, memory, identity and tool gateway for AI agents built with any framework, such as Strands or CrewAI.

Amazon CloudWatch

Logs, metrics and alarms. For AI systems: latency, errors and cost per call.

Amazon Bedrock

Managed access to foundation models from several providers through one API. You choose the model and write the prompt; AWS runs the model.

Book directly

Book it right here.

All prices are net. Companies outside Austria pay no VAT and can book directly by card. Companies in Austria, please choose “Pay by invoice”: 20% VAT is added there.

Agentic AI Security Assessment

€12,000net

A focused engagement, typically 2 to 4 weeks from kick-off to executive read-out.

Buy now →Pay by invoice

Security Assessment Extended

€15,000net

The same assessment for a larger scope. Not sure which size fits? Book the free call first.

Buy now →Pay by invoice

Security Assessment Complex

€18,000net

For complex agent landscapes. We confirm the scope in the free call.

Buy now →Pay by invoice

Security Retainer Essential

€1,500net / month

Re-assessment as you ship new agents, compliance monitoring and an updated threat model on record.

Buy now →Pay by invoice

Security Retainer Standard

€2,250net / month

The Essential retainer with more capacity per month.

Buy now →Pay by invoice
Start Here

Begin with a 30-minute Idea Call.

Before the assessment, we have a short conversation to confirm fit. No commitment. No slides. The same opening conversation that precedes every paid engagement.

  • Confirm the scope of your agent architecture
  • Check where the EU AI Act and NIS2 apply to you
  • Decide whether the one-time assessment or the retainer fits best
  • Get the intake brief and a calendar slot
Book the Idea Call

Only a quick question? Book 15 minutes

Typically respond within one business day. Vienna, Austria · serving clients across the EU · [email protected]