TL;DR: MCP is turning AI agent connectivity into an identity problem, with over 1,000 servers live by early 2025 and thousands more appearing across the ecosystem according to Lasso Security. The real issue is that existing IAM and monitoring models were built for stable, reviewable identities, not fast-moving agents that can reach sensitive tools and data.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Why MCP Agents Are the Next Cyber Battleground”.
By the numbers:
- By early 2025, over 1,000 MCP servers were live.
- By early 2025, more than 10K community-deployed MCP servers were live.
Key questions
Q: How should security teams govern MCP servers used by AI coding assistants?
A: Treat MCP servers as privileged trust boundaries, not simple data sources.
Q: Why do MCP-based agents create more risk than ordinary API integrations?
A: Because the agent is choosing actions, chaining tools, and preserving context across steps.
Q: What are the signs that MCP governance is failing?
A: Common signs include agents reaching systems outside their intended workflow, incomplete audit trails for tool use, and data retrieval that cannot be tied back to a clear business purpose.
Practitioner guidance
- Inventory every MCP-connected agent Build a complete register of MCP clients, servers, tools and owners so no agent reaches production without an accountable identity record.
- Scope tool access per agent Separate read, write and administrative actions for each agent and each tool, then remove any default broad permissions that are not explicitly justified.
- Require logging for model-tool interactions Capture agent requests, tool invocations and downstream actions in a searchable audit trail that security teams can review and correlate.
Bottom line: MCP turns AI agent connectivity into an identity governance problem because each tool connection creates a new access boundary.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
MCP is turning agent connectivity into an identity governance problem, not just an integration problem. The article shows that once agents can reach tools and data through a standard protocol, the security question shifts from whether the system connects to whether the resulting non-human identities are visible, bounded, and attributable. That is a familiar NHI pattern, but MCP accelerates it across more systems at once. Practitioners should read MCP adoption as an expansion of identity surface area, not a feature upgrade.
A few things that frame the scale:
- 53% of MCP servers expose credentials through hard-coded values in configuration files, according to The State of MCP Server Security 2025.
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone.
A question worth separating out:
Q: How do security teams decide whether an MCP agent has too much access?
A: A useful test is whether the agent can read data, trigger actions, and move across systems with one broad entitlement. If those capabilities are bundled, the access is too wide. Teams should separate those functions, then confirm that each permission is necessary, traceable, and removable without breaking unrelated workflows.
👉 Read our full editorial: MCP agents are expanding the identity attack surface for enterprises
Identity sprawl is the real MCP risk, not protocol novelty: MCP matters because it converts every agent connection into a new identity boundary that has to be authenticated, authorised and observed. The article shows that the control problem is no longer limited to human accounts or classic service accounts. Practitioners should treat each MCP relationship as a governed identity lifecycle, not a convenience layer.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: What should organisations do when agent access grows faster than review processes?
A: They should move control points closer to provisioning and runtime oversight, because periodic review cannot keep up with rapidly multiplying agents. That means agent inventory, explicit authorisation, telemetry and revocation need to be built into the operating model before scale turns into shadow access.
👉 Read our full editorial: MCP agents are expanding the identity attack surface for enterprises