ServiceNow Webinar | Threat Modeling Agentic AI Systems

ServiceNow Webinar | Threat Modeling Agentic AI Systems

🎙 Sukana Sukawasi 👥 3K 📅 December 2, 2025 ⏱ 59 min 👁 445 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

threat modelingagentic AIAI securityprompt injectionMAESTRO

Summary

The webinar, presented by Sukana Sukawasi, a Senior Staff Product Security Engineer at ServiceNow, offers a comprehensive introduction to threat modeling for agentic AI systems. It begins with an overview of the AI threat landscape, categorizing threats into development-time, use-time, and runtime phases, referencing the OWASP AI Exchange. Key attacks such as prompt injection, evasion, membership inference, model inversion, and model extraction are explained with examples. The presentation then distinguishes traditional AI from agentic AI, highlighting the autonomous, goal-oriented nature of the latter. It describes single-agent and multi-agent architectures, using a ServiceNow incident resolution example. The core of the webinar introduces the MAESTRO Threat Modeling Framework, designed specifically for agentic environments, addressing shortcomings of existing frameworks. The speaker outlines the four questions of threat modeling (understand system, identify threats, plan mitigations, validate) and emphasizes the importance of early integration into the SDLC. The session concludes with a brief demo (if time permits) and a Q&A. The webinar is practical, aimed at security professionals, and provides actionable insights for securing agentic AI deployments.

172 words

Critical Evaluation

Value of the Information & Strength of the Argument

The webinar provides valuable insights into the emerging field of agentic AI security. It offers a clear taxonomy of AI-specific threats and explains them with relatable examples, making complex concepts accessible. The introduction of the MAESTRO framework is a significant contribution, as it addresses the limitations of existing threat modeling approaches for agentic systems. The argumentation is coherent and well-structured, building from foundational concepts to the proposed framework. However, the presentation is largely based on the speaker’s expertise and industry experience, with limited empirical evidence or case studies. The framework is introduced but not deeply validated, and the webinar has a promotional undertone for ServiceNow’s solutions. Overall, the content is informative and practical, but the lack of rigorous scientific validation and the reliance on anecdotal examples temper its strength.

Scientific Rigor, Source Quality, Title Accuracy

The webinar demonstrates a reasonable level of scientific rigor. It references the OWASP AI Exchange, a recognized industry resource, and builds on established threat modeling principles (e.g., Adam Shostack’s four questions). The speaker’s background in security engineering adds credibility. However, the presentation is primarily an expert opinion piece, and the MAESTRO framework is not compared with existing frameworks in a systematic way. The title accurately reflects the content, and the webinar stays on topic. The description provides a link to the WiCyS BrightTALK channel for further webinars, but no specific sources are cited in the description. The Q&A session was not included in the transcript, so public comments are not analyzed.

255 words

Title / Content Match

The title accurately reflects the content: the webinar focuses on threat modeling for agentic AI systems, covering threats, architecture, and a new framework.

Quality & Reliability

7/10

The webinar provides a structured overview of AI security threats and introduces a new threat modeling framework (MAESTRO) by an experienced security engineer. While it is largely based on expert opinion and industry experience, it references established concepts (OWASP AI Exchange) and offers practical guidance. The lack of peer-reviewed sources and the promotional nature of the webinar slightly reduce the score.

Key Moments

Cited Sources

Concurring Sources

  • OWASP AI Exchange — The webinar references OWASP AI Exchange for categorizing AI threats, which aligns with the presented threat landscape.

Contribution & Novelties

The webinar contributes to the field by introducing the MAESTRO Threat Modeling Framework, specifically designed for agentic AI systems. It addresses the shortcomings of existing frameworks, which often fail to account for the autonomous, multi-agent nature of these systems. The presentation provides a structured approach to identifying and mitigating threats in agentic environments, filling a gap in current security practices. The practical examples and architecture breakdowns offer actionable insights for security professionals.

Pour aller plus loin :

  • OWASP AI Exchange — The OWASP AI Exchange provides a comprehensive taxonomy of AI threats, referenced in the webinar.
  • Threat Modeling: Designing for Security — Adam Shostack’s book on threat modeling, which introduces the four-question framework mentioned in the webinar.
  • NIST AI Risk Management Framework — A framework for managing AI risks, relevant to the broader context of AI security.
  • MITRE ATLAS — A knowledge base of adversary tactics and techniques for AI systems, useful for threat modeling.
  • Prompt Injection Attacks — OWASP page on prompt injection, a key threat discussed in the webinar.

171 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the webinar's comprehensive coverage. The technical level is moderate, suitable for a broad security audience. The overall reliability is solid, given the expert background of the presenter, though the promotional nature slightly lowers the score.

Reliability 7/10