Skip to content
ARC Research
ResearchSecurityAugust 1, 2026· 15 min read

Security for Modern Operators: Zero Trust, CSF 2.0, and AI-Era Threats

A cited briefing on NIST Cybersecurity Framework 2.0, Zero Trust Architecture, the emerging Cyber AI Profile, and OWASP’s Top 10 for LLM applications — translated into outcomes teams can actually run.

Key findings
  • NIST CSF 2.0 (2024) elevates Govern as a core function and frames cybersecurity as enterprise risk management for organizations of any size.
  • NIST SP 800-207 Zero Trust removes implicit trust based on network location; continuous authentication and authorization become the default for users, devices, and workloads.
  • NIST’s draft Cyber AI Profile (NISTIR 8596) organizes AI-era cyber work into securing AI systems, using AI for defense, and thwarting AI-enabled attacks.
  • OWASP Top 10 for LLM Applications 2025 highlights prompt injection, excessive agency, supply-chain risk, and unbounded consumption as first-class application risks.

Academic and standards background

Enterprise security guidance has moved from perimeter checklists to continuous risk management. NIST’s Cybersecurity Framework began as critical-infrastructure guidance and, in CSF 2.0 (February 2024), became explicitly usable by any organization. CSF 2.0 adds a Govern function alongside Identify, Protect, Detect, Respond, and Recover, and it links outcomes to online informative references rather than prescribing a single control set.[1]

Zero Trust Architecture (NIST SP 800-207) is the complementary architectural model: no implicit trust from network location or asset ownership; authenticate and authorize before establishing a session to a resource; assume breach and limit lateral movement. It responds to remote work, BYOD, and cloud assets that live outside enterprise-owned perimeters.[2]

AI changes both the asset surface and the attacker toolkit. NIST’s AI RMF addresses trustworthy AI risk broadly; CSF 2.0 explicitly points organizations to treat AI risks alongside financial, cyber, reputational, and privacy risks. In December 2025, NIST released a preliminary draft Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile / NISTIR 8596) to help organizations use CSF 2.0 outcomes when securing AI, defending with AI, and thwarting AI-enabled attacks.[1][3][4]

What the evidence and standards imply

CSF 2.0’s practical message is governance-first: roles, policies, supply-chain oversight, and communication of cyber risk to leadership are outcomes, not afterthoughts. Organizations that only buy tools without owning Govern outcomes tend to accumulate controls without decision rights.[1]

Zero Trust implies identity-centric access, continuous verification, and resource-level policy — not a single product purchase. Migration is incremental: inventory resources, map transaction flows, enforce strong identity, and segment access while monitoring for lateral movement.[2]

For AI applications, OWASP’s Top 10 for LLM Applications 2025 is the most widely referenced community catalog of application-layer failure modes. The 2025 list emphasizes prompt injection; sensitive information disclosure; supply chain (models, plugins, data); data/model poisoning; improper output handling; excessive agency; system prompt leakage; vector/embedding weaknesses; misinformation; and unbounded consumption (cost and resource exhaustion beyond classic DoS).[5]

Taken together, standards bodies and practitioner catalogs converge: secure the AI system components, constrain what agents may do, treat model/tool supply chains like software supply chains, and measure both cyber outcomes and AI-specific abuse cases.

Grounded outcomes for operators

1) Run a CSF 2.0 profile for your operating context. Start with Govern and Identify: who owns AI and cyber risk, what systems matter, and which suppliers touch them.

2) Implement Zero Trust patterns where they reduce blast radius fastest — privileged admin paths, production data stores, CI/CD, and agent tool endpoints.

3) Map every LLM/agent feature to OWASP LLM risks before launch. Prompt injection and excessive agency deserve explicit mitigations (input/output controls, tool allowlists, human approval for irreversible actions).

4) Use the Cyber AI Profile framing: Secure (harden AI components), Defend (where AI improves detection/response), Thwart (prepare for AI-amplified social engineering and automation).

5) Require evidence: access logs, model/tool inventory, change control for prompts and RAG corpora, and incident playbooks that name AI failure modes.

Limitations and how to read this brief

Frameworks are voluntary and outcome-oriented; they do not certify security by themselves. The Cyber AI Profile cited here is a preliminary draft subject to public comment and revision. OWASP rankings are community consensus, not a regulated baseline. Adapt controls to your threat model, sector obligations, and risk appetite.

Sources & citations

Primary and secondary sources used in this brief. Open the original document to verify claims in context.

  1. [1] NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 2024.
  2. [2] Scott Rose, Oliver Borchert, Stu Mitchell, Sean Connelly (NIST). Zero Trust Architecture. NIST SP 800-207, 2020.
  3. [3] NIST. Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) — NISTIR 8596 preliminary draft. NIST CSRC, 2025.
  4. [4] NIST. Draft NIST Guidelines Rethink Cybersecurity for the AI Era. NIST News, 2025.
  5. [5] OWASP Foundation. OWASP Top 10 for Large Language Model Applications 2025. OWASP, 2025.

Want this applied to your stack?

Studio can score the paper against your environment: what to do first, what to ignore, who owns it.