Calendar of Events

Loading Events

« All Events

  • This event has passed.

Webinar | MAESTRO: Threat Modelling for Agentic AI

July 21 @ 1:00 pm - 2:00 pm

The rise of Agentic AI — autonomous systems capable of perceiving their environment, making decisions, and taking actions to achieve goals — introduces a fundamentally new threat landscape that traditional security frameworks were never designed to address. When multiple AI agents interact, learn, and operate with increasing autonomy, risks like goal manipulation, agent impersonation, data poisoning, adversarial evasion, and cross-agent collusion emerge — none of which are adequately captured by frameworks such as STRIDE, PASTA, or OCTAVE.

This session introduces MAESTRO (Multi-Agent Environment, Security, Threat, Risk, and Outcome), a threat modeling framework published by the Cloud Security Alliance, designed specifically for the unique challenges of Agentic AI. MAESTRO provides a structured, layered approach built around a seven-layer reference architecture:

  • Foundation Models — adversarial examples, model stealing, backdoor attacks
  • Data Operations — data poisoning, RAG pipeline compromise, data exfiltration
  • Agent Frameworks — supply chain attacks, input validation exploits, framework evasion
  • Deployment & Infrastructure — container compromise, orchestration attacks, lateral movement
  • Evaluation & Observability — metric manipulation, detection evasion, observability data poisoning
  • Security & Compliance — security agent compromise, regulatory non-compliance, bias in AI security tools
  • Agent Ecosystem — agent impersonation, goal manipulation, marketplace manipulation, tool misuse

Beyond layer-specific threats, the session explores cross-layer attack chains — how an attacker might exploit a vulnerability in deployment infrastructure to poison training data, ultimately compromising the foundation model — and the agentic architecture patterns (single-agent, multi-agent, hierarchical, human-in-the-loop) that shape the threat surface.

WiCyS is proud to provide members the opportunity to earn CPE/CEU credits for attending WiCyS Webinars live. To earn CPE/CEU credits with the following providers, you must meet the minimum requirements:

  • GIAC/(ISC)2: attend for a minimum of 45 minutes or the entirety of the webinar
  • CompTIA: attend for a minimum of 60 minutes or the entirety of the webinar (webinar topic must relate to the certificate being renewed)

Attendees who meet the requirements can log into BrightTALK to print out their attendance certificates to submit for CPE/CEU credits.

Register for this webinar and view the recording if you are unable to join live.