Security1 distinct publisher3 min readPublished
Versa field CISO Prasad Tharippala says in-house inference buys control and data residency, but security has to be built rather than assumed. For a team with 90 days and no money, he puts agent inventory and blast-radius work first.
The Watch · Security desk

security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
build
SSE in Go breaks twice before your handler runs: an illegal header, then a 30-second timeout1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
build
Rate limit your MCP servers, because a retrying agent turns one error into a billing incident1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
The sequencing has a mechanical reason behind it. Tharippala's test list runs to nine classes of agent attack, then adds seven more, which is sixteen distinct things to exercise before production [15][16][17]. Sixteen classes against an agent population nobody has enumerated produces findings without owners, which is why inventory sits first and blast radius reduction second in his ranking [13]. He does not allocate days; split evenly, three workstreams across 90 days is 30 days each [19]. Permission scoping also pays earlier than the test does, because narrowing what a compromised agent can reach lowers the value of a successful injection whether or not you have yet proved the injection works [14].
The ring around the model is where the money goes. He counts twelve operational items, including GPU infrastructure, power and cooling, capacity planning, orchestration, audit evidence and ongoing optimization [5][6]. Licensing and compliance review is the line he says rarely makes the budget at all: open weights are not unrestricted, many licenses carry usage restrictions, and the EU AI Act adds obligations for larger models [7]. That review recurs, because every model or adapter update needs re-validation [8].
Utilization is the other number that moves. Poor workload management leaves idle GPU capacity or unpredictable performance during demand spikes, and the levers he names are scheduling, quotas, batching, caching, model routing and demand forecasting, with quantization and multi-tenant GPU sharing changing the economics further [11]. That work is operational, not security work, and it draws on the same people security needs. The skill set he describes spans platform engineering, MLOps, GPU and Kubernetes expertise, site reliability, AI security and red-teaming, identity and data governance [9]. Where an organization assumes its existing infrastructure or security team can absorb the load, he reports significant delays and, in some cases, projects that never deliver the expected business value [10].
Read the source with its position in view. This is one interview, Tharippala is a field CISO at a vendor [1], and his stated conclusion is that build versus buy is the wrong axis, with a hybrid split between in-house workloads and managed services often the practical answer [12]. The part that stands independent of that position is the responsibility transfer: six duties move to whoever runs the weights, and none of them arrive staffed [3][4]. The threshold itself is missing from the material available here. The interview is summarized as covering what counts as a failing result and five questions buyers should ask agent platforms [18]. Without those, the acceptance gate on any red-team engagement is yours to draft, which is another argument for spending the first thirty days counting agents rather than buying tooling.
Ranked by verification strength, evidence, and original report placement.
Self-hosting shifts responsibility for hardening, patching, access control, monitoring, model evaluation and incident response onto the organization running the model.
He says the real operational cost comes from everything around the model: GPU infrastructure, networking, storage, power and cooling, capacity planning, orchestration, model updates, monitoring, security controls, data governance, audit evidence and ongoing optimization.
Licensing and compliance review rarely makes it into the budget; open weight does not mean unrestricted, many open weight licenses carry usage restrictions, and regulations like the EU AI Act add obligations for larger models.
Every model or adapter update needs re-validation, so licensing and compliance review is an ongoing cost rather than a one-time exercise.
Organizations often assume existing infrastructure or security teams can absorb the work; operating inference reliably at scale is a different discipline, which can lead to significant delays and in some cases projects that never deliver the expected business value.
GPUs are expensive and poor workload management can cause significant idle capacity or unpredictable performance during demand spikes; scheduling, quotas, batching, caching, model routing and demand forecasting help, and quantization and multi-tenant GPU sharing can make a real difference.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One named practitioner, nothing checked
Every load-carrying statement traces to the same interview, and the counted lists that give the story its shape are tallies of one man's sentences. It is on-the-record and internally coherent — Tharippala is named, his role is named, and his test list points at OWASP's agentic guidance and MITRE ATLAS — but there is no artifact, no measurement and no second voice. The strongest items are the ones that need no verification because they are logical rather than empirical: self-hosting does not confer security, and re-validation recurs with every adapter update.
Nothing to count
No deployment, release, contract, spend figure or usage disclosure appears anywhere in this reporting. Tharippala describes patterns he says he sees across customers, but not one is identified, sized or dated, so there is no adoption signal to measure — only advice.
Tidier than the source
The overstatement is not in Tharippala's mouth; he hedges carefully, refuses a universal red-team timeline and says there is no one-size-fits-all answer. It creeps in through the counting. Turning conversational lists into six jobs, twelve costs and sixteen attack classes implies a settled framework where the interview offers a knowledgeable ramble, and the sixteen only holds if 'memory and RAG poisoning' is one thing. Splitting 90 days into three 30-day blocks goes further still, converting a stated priority order into a schedule he never gave.
Vendor field CISO, vendor-shaped conclusion
A field CISO is a pre-sales role, and the argument runs the way that role's arguments run: self-hosting is harder than you think, the skills are scarce, the compliance work never stops, and hybrid with some workloads consumed as a managed service is 'often the practical answer'. None of that makes the checklist wrong — the six transferred duties are real whoever names them — but Help Net Security's Q&A format puts no counterweight in the room, and Versa's own commercial interest in that conclusion is never disclosed to the reader.
Confident about what was said, not about what is true
We can be fairly sure of the content: the quotes are direct, the speaker is identified, and the emphasis is unambiguous. Confidence drops on everything past that. One publisher, one interviewee, no adoption to check the advice against, a commercial interest running in the same direction as the conclusion, and a transcript that ends before two of the promised answers. Treat the checklists as a competent practitioner's opinion worth acting on, and the failure claims as untested.