We Gave Our Security Team An MCP and Told Them To Go Wild

Five weeks ago we turned on the Nagomi MCP for our own team, pointed it at our own staging environment, and opened an internal channel with one rule: try anything, then tell us what happened.
What came back wasn't a features list. It was dashboards nobody had asked for, a breach report that made a few people pause, a mobile mockup, a brand new metric someone invented mid-conversation, and a genuine argument about whether our own risk ranking was ranking the right things.
This post is about what that month of MCP use taught us. Before we get into that, though, we want to post an honest question about the functionality: does it actually matter that Nagomi is releasing an MCP?
The Protocol Is Not The Point
Here's an awkward truth to publish in a launch post: Model Context Protocol (MCP) isn't a novel Nagomi idea. Most serious security platforms offer an MCP or are about to. On its own, and in the security realm, MCP is essentially a pipe; it standardizes how an AI client discovers and invokes tools exposed by a server, allowing the client to interact with security data and capabilities through natural language queries. In essence, it allows customers to skip the vendor console and run queries how they want, using the LLM they want, in the language germane to their personal workflow.
This protocol layer, in and of itself, is not a differentiator. What sits on the other end of it is.
Why, then, is Nagomi bothering to announce this capability externally? Because the MCP is only the interface. The value surfaces from what Nagomi exposes through it.
Our own product spec describes the Nagomi MCP as an "exposure brain": a read-only, bounded connection into everything Nagomi already correlates, assets, vulnerabilities, misconfigurations, control coverage, threats, exclusions, business groups, and the toxic combinations among them that add up to business-impacting risk.
In more concrete terms: a vulnerability scanner's MCP can tell a customer what's vulnerable. Ours tells them what's exposed, given their control coverage. Correlation over raw access is the entire bet behind this launch, and it's the reason the dogfooding project mattered more than the ship date.
Five Use Cases Discovered From Dogfooding
To ensure our internal team used the MCP like our customers would, the R&D team didn't hand out a demo script with instructions on how to use it. They provisioned access and got out of the way. The results were interesting, creative, and informative. So we wanted to share a few with you:
- A tailored defensive plan. One engineer wanted to take the platform’s “Top 15” remediation list and turn it into something more actionable for various scenarios. The default ranking is a useful, volume-based view of remediation priorities, particularly when teams need a consistent baseline across environments.
However, some customers may want to tailor the ranking for their priorities, and so the engineer built an interactive rescoring tool on top of the MCP. They created five tunable mechanisms for impact, threat, convergence, redundancy, and effort, plus included a free text box that allowed for individual input such as, “which exposures create the highest risk right now?” The result is a ranked list that can be reconfigured per needs, risk tolerance, active exploits, and so on. Point it at a healthcare environment where ransomware is a chief concern, and the list reorders around ransomware. Point it at a different environment where identity risk matters more, and the priorities change accordingly.
That's not a new Nagomi feature. It's the MCP doing exactly what it's meant to do: reach into the defensive plan, coverage data, exclusions, and group scoring already available, and let the user compose a view of the data that’s meaningful to them. Ask a question in plain language, shaped to that specific question’s needs, query Nagomi’s data and analysis, and get a tailored answer.
- A report that killed the attack path. Another employee asked a more pointed question: given everything Nagomi knows about our environment, what's the easiest attack path? The MCP returned a data-driven answer without hesitation: the attack path mapped to known adversary techniques, a single choke point where two separate paths converged, and a prioritized list of fixes based on how much of the path each fix would obfuscate.
The result was more useful than a blanket answer because it showed the reasoning behind the path. The employee could see how the exposures connected, where the attack path depended on those connections, and which fix would interrupt the chain most significantly.
It’s also a fair reminder that correlation cuts both ways. The same relationships that help a defender prioritize remediation can reveal an attacker’s path. Once Nagomi connects assets, vulnerabilities, missing controls, and dependencies, it can describe how those conditions combine into an exploitable path.
- The measured ROI report. A Nagomi rep preparing for a customer call wanted to show the customer measurable, attributable improvement in the customer’s environment. The goal was to highlight which fixes were possible because Nagomi surfaced the underlying evidence, plus provide the value of those fixes in terms of cost saved and risk reduced.
Three natural language prompts later, the rep had a report showing quantitative ROI for cost and risk reduction. The report used the customer’s real remediation history, and every assumption was editable, so anyone reading the report could alter an input and watch the number adjust according to the underlying model.
By default, Nagomi doesn’t supply this report type, and that’s exactly the point. During this test, the rep asked for specific reports on the efficacy of the platform and the MCP pulled together the data necessary to build it, quickly, and with a minimal amount of effort. The value isn’t that MCP generated a report quickly, though; it was the customer-specific output, at the ready, without the need for vendor R&D.
- The daily threat intel digest with your exposure attached. Our CPO wanted to stop spending every morning reading numerous security newsletters then manually correlating applicability to our company and our clients environments. It was a basic ask to save time without cutting any context or content.
He therefore built a skill to scan multiple cyber RSS feeds, summarize the new intel, and prompt the MCP to ask the critical questions: are any of the named CVEs in our environment, has Nagomi seen the noted TTPs, how do our controls map to these risks? The skill runs each morning, and what’s returned isn’t a vanilla news roundup; it’s a threat digest that maps to the environment to pinpoint exposure.
The skill is the easy element. The essential aspect is that it eliminates a time-consuming task, one that can easily be automated with AI. The more significant part is feeding the intel into Nagomi so Nagomi can automatically compare new threat information against exposure, controls, additional threat intel, and context to surface issues. Nagomi performs the hard-but-tedious works of correlation, saving analysts time and effort. The security team gets to focus on the strategic implications.
- The app nobody asked for. One teammate had a simple question about the Nagomi dashboard: why open a laptop just to check posture? The employee used the MCP output to mock up an Android app, essentially a pocket version of the CISO dashboard they named “The Best Dashboard Ever.” Screenshots were posted to the exercise’s Slack channel as a proof of concept, and the idea caught the attention of leadership, who asked to see it for themselves.
The interesting part isn’t the app itself; it’s that the R&D team didn’t need to feature flag the idea while the "customer" had to wait for it to be built. The exposure data was available through MCP, readily available for anyone to take that context and imagine a completely different client around it. The interface was no longer limited to the Nagomi console or priorities of the engineering team.The employee could turn the data into what was needed for their workflow, their preferences, in a format that worked within minutes.
Why This Matters More Than A Launch Date
Five weeks ago, we gave our team one rule: try anything. What the team found was answers to individual, custom use cases, based on verified data about the environments.
Though Nagomi could have taken months to anticipate and build for each and every use case, it’s now unnecessary — our MCP allows customers to use the platform how it best suits them.
The addition of an MCP doesn’t make Nagomi exceptional because the protocol does something other MCPs can’t. What makes it stand out is that it’s based on Nagomi’s existing exposure intelligence, and allows users to consume intelligence in a form they can interrogate and reshape per their preference.
The protocol is the interface. The differentiated part is what sits behind it: the correlated exposure data, the analysis, and the evidence that let the underlying context answer customers’ questions. That’s a much more beneficial place to start than a feature list.
Want to see how Nagomi’s Agentic Exposure Ops Platform handles your environment? Request a demo.
See Nagomi in action at nagomisecurity.com


.png)
