The Adversarial MCP

MCPs are everywhere these days. With the proliferation of desktop AI interfaces, hooking up your data and productivity tools has become a massive force multiplier. For me, connecting email, Slack, calendar, Linear, and even Strava was a no-brainer - enabling daily updates and meeting prep with full awareness of my interactions, conversations, and activity.

But things got really interesting here at Adversarial when we added telemetry from our application logs and tools like GCP and Cloudflare. Suddenly we could troubleshoot in real time and make sense of reams of nuanced API and user login events. We could draw insights from datasets that were never worth our precious time to comb through by hand.

That evolution is taking place everywhere - going from Q1 2026's ancient world of interactive prompting to today's rich, contextual assistance informed by your environment.

When it comes to cybersecurity, the same telemetry and investigation patterns benefitting engineering teams are empowering incident response and forensic work. Agentic SOC platforms and individual staff AI tools leverage MCPs from EDR platforms, cloud service providers, web application firewalls, and operating systems to figure out what happened at record speed. Given the tight parallels between SOC work and infrastructure engineering, it's unsurprising that the same advances are lifting both at once.

But what about GRC?

If your risk register doesn't have an MCP, you are missing out. What started as a skunkworks weekend project from Adversarial engineering has become a can't-miss, "how did I ever live without this" feature overnight. "What are my top risks?" is the obvious first question - but you don't need an MCP to answer that. Where the MCP shines is more thoughtful questions like:

Which sources of risk data are providing the most actionable data?

That's the elusive ROI measurement on security tools - almost by accident. The analysis brushes up against some of the reporting and metrics we built into the platform dashboard. In fact, the MCP is often our own proving ground - a place to experiment with reporting and visualization, and to prototype what later becomes a first-class feature. Here, for example, is where similar experiments led: the dashboard Sankey diagram that maps the fidelity of each risk source:

Now a higher-level question...

Are there organizational behaviors we might change that would substantially reduce risk without much friction?

The takeaway? (OMG I'm sounding like Claude myself!)

A product's MCP use cases tell you what the product does for you. And for a cyber risk system of record, those use cases are exactly the universe of insights you need from your security data - and the decisions you can make from them.

None of this works if the risk data is raw. Taking vulnerability scanner outputs - or even audit results - at face value means inheriting the source's take on urgency, which just amplifies the crisis of dumping overrated findings on engineering to fix. That's where the Adversarial approach - leveraging AI to get urgency scores right in context - absolutely shines: the same rubric, applied consistently, to every risk, every time, with decision-making governed and memorialized.

That's Adversarial.