authors
Nikhil Balaraman
Nikhil Balaraman articles and resources from Pomerium.

Topic archive
More from Nikhil Balaraman

Data-Layer Proxy vs Context-Aware Proxy: Which Do You Need?
Two proxy architectures secure AI agent access, and they solve different problems. How data-layer and context-aware proxies differ, and when you need each.

MCP Governance: What the OWASP Framework Requires, and Where Enforcement Has to Live
The OWASP MCP Governance & Risk Framework v1.0 sets tiers, hard gates, and audit rules for AI agents. Here's what it requires and how to enforce it at runtime.

Identity Was Built for Humans Logging In. Agentic AI Ripped Up That Assumption.
Non-human identities outnumber people 45-to-1. Learn why agentic AI redefines the identity attack surface and how Pomerium enforces Zero Trust for AI agents.

Your IAM Was Built for People. Your Biggest Identity Problem Isn't People Anymore.
Every enterprise identity program was designed around a simple assumption: the thing logging in is a person. A person with a password, an MFA device, a predictable workday, and a manager who approves their access.

Agents Have Boundary Issues. Your Infrastructure Shouldn't.
Why the five isolation boundaries in agent security research all point to the same conclusion: enforcement has to live outside the model.

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."
.png.CaqDtkk2.webp)
IAM for Agentic AI: 6 Platforms Compared | Pomerium
Compare Pomerium, Aembit, Astrix, Token Security, Oasis, and Britive for securing AI agents and workload identities. See which platform fits your stack.
.png.jT38w0LS.webp)
Understanding Anthropic's Zero Trust for AI Agents Guide
Most writing about AI agent security stops at the scary part: agents can be prompt-injected, they hold credentials, they act near production. True, and not very useful. However, the implementation half of Anthropic's Zero Trust for AI Agents guide is more interesting because it stops describing the problem and starts grading the solutions. It lays out exactly which controls count as table stakes, which are enterprise-grade, and which are reserved for the highest-stakes environments.
.png.CLojiDYH.webp)
Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust
The Register reported today that CVE-2026-0257 , an authentication bypass in Palo Alto's GlobalProtect, has moved from a quiet medium-severity advisory to confirmed exploitation in the wild. Rapid7 traced successful attacks back to at least May 17 and reproduced the technique themselves. The flaw now sits in CISA's Known Exploited Vulnerabilities catalog with a same-day patch deadline for federal agencies.
.png.BOyLwQ5r.webp)
When the Web Becomes the Attacker: AI Agent Traps and the Case for Identity-Aware Access
As autonomous AI agents fan out across the open web to read pages, call tools, and drive workflows on our behalf, the web itself becomes the attack surface. The adversary no longer needs to compromise the model, the endpoint, or the user. They only need to shape the information the agent sees. The DeepMind team calls this new class of adversarial content AI Agent Traps , and their paper is the first systematic taxonomy of them.
.png.D1dxPUm2.webp)
Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026
The explosive growth of agentic AI has created a new security frontier. As large language models (LLMs) gain the ability to call external tools—through the Model Context Protocol (MCP)—organizations face an urgent question: How do you control what tools an agent can access, what parameters it can pass, and how do you audit its actions?
.png.DqqhEqND.webp)
Why Identity-Aware Access is the Missing Layer in Agentic Security
A new VentureBeat analysis from this week lands on a truth that every enterprise security team already feels in their gut: most AI agents are a credential exfiltration waiting to happen. The monolithic agent pattern — where reasoning, execution, credential storage, and tool access all share the same process — creates a threat surface that conventional security tooling wasn't designed to close.
.png.C8TvzZ8b.webp)
MCP Server Security Risks: What Development Teams Need to Know in 2026
MCP servers give AI agents direct access to your internal systems—databases, APIs, file systems—through a standardized protocol. That's powerful for building agentic workflows, but it also creates attack vectors that traditional security tools weren't designed to handle. Gartner predicts 25% of enterprise breaches by 2028 will trace back to AI agent abuse.

The AIUC-1 Compliance Checklist: 5 Layers Every Enterprise Needs Before Deploying AI Agents
A quick-reference checklist for AIUC-1 compliance. Five layers, 28 controls, one page. Print it, pin it, pass the audit.

What Is an Agentic Gateway? Definition, Architecture, and Why It's Different from an API Gateway
Discover what agentic gateways are, how they secure autonomous AI agents with tool-level authorization and session-aware policy enforcement, and why API gateways fall short.
.png.CAHbD12i.webp)
The AIUC-1 Compliance Stack: The Architecture Auditors Are Actually Looking For
Most enterprises will fail AIUC-1 before the audit starts. Here’s the five-layer compliance architecture — built around a central control plane — that covers every domain.
.png.CbQUPgiG.webp)
Midmarket Security Teams Deserve Better Than Enterprise Hand-Me-Downs
New research shows 42% of midmarket security teams are stretched thin while enterprise tools don't fit. Here's why a zero trust reverse proxy, like Pomerium, changes the equation.

What Made McKinsey's AI Platform Easy to Hack? And How to Fix it.
Enterprise AI assistants are quickly becoming the front door to internal systems .

Complete Guide: Zero Trust for Air-Gapped Networks
Air-gapped networks are supposed to be impenetrable. No internet connection, no remote attacks. That's the theory at least. But isolation alone doesn't stop the threats that walk through the front door: compromised USB drives, malicious insiders, and supply chain attacks that arrive pre-installed on new hardware.

MCP Security: Why MCP Is an Authorization Crisis
A developer asks an internal AI assistant to summarize a customer support ticket and check whether a refund has already been issued. The agent retrieves the ticket, queries a billing API, updates the CRM, and returns a clean summary. Everything works exactly as designed.

Secure Internal Access to Grafana, Argo, GitLab, and Prometheus Without a VPN
Securing internal tools without a VPN is no longer a fringe idea—it’s becoming the default for modern Kubernetes platforms.

From NGINX to Pomerium: A Practical Migration Guide for Internal Kubernetes Applications
Migrating from NGINX Ingress to Pomerium does not require a disruptive rewrite. Most teams adopt Pomerium incrementally, starting with internal services where the security and operational gains are immediate. An initial objective can be to decouple routing from access control for internal services.

Privilege Access Is the Past. Per Request Authorization Is the Future.
For twenty years, cybersecurity has organized itself around a single idea:

AI Is Your Biggest Security Risk
IBM’s Cost of a Data Breach Report 2025 delivers a surprising headline: for the first time in five years, the global average cost of a data breach has declined, dropping to $4.44M . The reason? Faster detection and containment, driven largely by security automation and AI.

10 Kubernetes Security Tools DevOps Teams Should Be Using in 2026
Kubernetes clusters are dynamic, distributed, and often ephemeral—which makes them difficult to secure with traditional tools. Firewalls and network segmentation protect the perimeter , but they cannot see inside the cluster or answer whether a request is authorized.
.png.C3SYIPl6.webp)
Why Kubernetes Ingress Needs an Identity Layer
Kubernetes ingress controllers are excellent at one thing: moving encrypted traffic to the right service. But encryption alone does not equal security.

Replacing Ingress-NGINX: A Modern Approach to Secure Kubernetes Access
For years, NGINX Ingress has been the default answer to a simple question: How do I get traffic into my Kubernetes cluster? It excels at Layer-7 routing, TLS termination, and traffic shaping, and for many workloads it remains a solid choice. But as Kubernetes has moved beyond hosting public-facing services and into powering internal platforms , the limitations of traditional ingress have become increasingly apparent.

Announcing Pomerium v0.31
The latest release of Pomerium v0.31 focuses on reliability and simplicity. Check out the release notes here .

Smarter Health Checks for Zero-Downtime Deployments
The latest Pomerium release introduces fine-grained and context-aware health checks for Kubernetes, AWS ECS, and systemd . These checks confirm that your routing and policy-enforcement layers are fully ready before handling traffic, giving operators reliable zero-downtime upgrades.

The Human Factor in Security: Lessons from the CyberArk Employee Risk Survey
In their comprehensive book Network Security: Private Communication in a Public World , Kaufmann, Perlman, and Speciner wryly observed,

How Pomerium Supports FedRAMP Compliance
Recently, we’ve had a lot of conversations with folks regarding whether or not Pomerium has achieved FedRAMP. We wanted to take some time to point out that while FedRAMP doesn’t apply to self-hosted software like Pomerium Core or Enterprise, there are actually specific parts of NIST SP 800-53 and FedRAMP compliance requirements that Pomerium can help you achieve.
Taking Back Zero Trust: Bank Policy Institute (BPI) provides a fairly reasoned take on Zero Trust
Bad actors in a Financial Institution’s network should be assumed.
