Security1 publisher2 min readPublished
Brockman tells security teams to give an agent approved access to their highest-priority systems
OpenAI president Greg Brockman told security leaders to point a coding agent at live codebases and infrastructure configurations. The most detailed published objection leans on a readiness study its own author's firm ran.
The Watch · Security desk

What happened
- OpenAI president Greg Brockman published a blog post on the state of cybersecurity after several high-profile incidents involving models built by OpenAI, Anthropic and Meta.
- He told security teams to start with Codex, the Codex Security plugin or a comparable tool, give it approved access to codebases and infrastructure configurations, and begin on their highest-priority systems.
- A SimSpace study found almost 80% of polled security leaders had high confidence in their agentic cybersecurity capabilities, while comparable teams tested in the firm's proving grounds scored 30% on defensive readiness.
- An SC Media Perspectives column calls the approved-access advice a major security risk that makes it more likely the defensive tooling itself creates previously unknown vulnerabilities.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Any CSO who acts on the post owns a scope decision the post does not make: which repositories and configuration stores the agent can reach, and whether it can write to them.
- exposure An agent holding infrastructure configuration access sits inside the systems it is assessing, so its errors land in production instead of a lab environment.
- contradiction The strongest number arguing against the advice was produced by the same firm whose simulation product the column recommends in its place. Anyone citing that number in a board paper should ask for the methodology first.
- cost On Villanustre's reading, budget raised to defend against model-enabled attacks flows back to the vendor whose models feature in the incidents that prompted the advice.
The phrase that decides the risk is "approved access", and the post leaves its scope to the team doing the deploying [4]. Brockman also told security leaders to run assessments against actual systems as soon as possible [2]. Put the two instructions together and they point at production. The SC Media column reads them that way, and argues the result raises the chance the defensive tooling introduces vulnerabilities that were not there before [5].
The two SimSpace figures are about 50 points apart [9], and they measure two different things. One comes from security leaders answering a survey about their own confidence [6]; the other from teams tested in SimSpace's AI proving grounds, matched to the survey group on maturity [7]. The column does not describe how the readiness score is calculated.
The column also says that score improves as teams run frequent agentic security simulations [8], and it rejects Brockman's tabletop suggestion outright, on the grounds that no tabletop scenario can prepare a team for a real breach and that there is no substitute for highly realistic simulation [11]. The report supplying the numbers is the author's own firm's: the text reads "As we identified in SimSpace's State of Agentic Cybersecurity report" [10]. The number and the recommended remedy come from one vendor.
The one named objection from outside is narrower, and it is about incentives. "Although I agree in general with Mr. Brockman's recommendations, this is a problem that OpenAI helped create in the first place," said Flavio Villanustre, CISO at LexisNexis Risk Solutions Group [13]. Villanustre added that "the recommendation seems to be for users to now pay more to OpenAI" as they use AI to defend themselves [14].
The material does not include a case file. The argument against agentic access to production is about likelihood, and the column's own threat ranking puts human beings and conventional social engineering, phishing included, ahead of frontier models for many organizations [12]. On executive buy-in, the column and the post agree: leadership has to understand and support the specific initiative [16].
Neither the post nor the column specifies the scope. Anyone piloting this sets it: which repositories the agent can read, which configuration stores, whether it can write, and who signs the approval that the word "approved" is standing in for. Standard practice is to prove unfamiliar tooling on systems whose failure is survivable, and the post asks for the opposite order: "Do not wait for a company-wide rollout to start with your highest-priority systems" [4].
What to watch
- Any scope guidance from OpenAI on what "approved access" means for the Codex Security plugin, including read versus write.
- A disclosed case of an agentic defensive tool changing production configuration or introducing a vulnerability.
- SimSpace publishing the methodology behind the 30% readiness score, or a before-and-after run on the same teams it surveyed.