AGP Picks
View all

Magnitude Introduces CISO Staff Agent, an AI Chief of Staff for Third-Party Risk Management & Supply Chain Resilience

New AI agent reasons across vendor and product assessments, monitoring, incidents and Nth-party relationships to surface portfolio-wide weaknesses and prioritize critical actions

SAN FRANCISCO, Sept. 15, 2026 (GLOBE NEWSWIRE) -- Magnitude, the autonomous governance and defense platform for continuous third-party risk management (TPRM) and supply chain resilience, today announced CISO Staff Agent, an AI chief of staff purpose-built for third-party risk. The new capability lets security leaders ask questions across potentially thousands of vendors, products and downstream dependencies to identify systemic weaknesses and quickly surface the most critical risks that require their attention.

The CISO Staff Agent analyzes and connects risk signals and context from across an organization’s third- and Nth-party environment, helping CISOs understand what matters most, investigate specific issues, surface emerging risks earlier and determine how to reduce or remediate them.

CISOs and their teams can ask questions and issue requests such as:

  • What vendor failure would create the biggest blast radius across my business and supply chain?
  • Create a presentation detailing the five highest-risk products and recommended actions. Schedule it to refresh every Monday at 9 a.m.
  • How exposed am I to concentration risk from fourth- and fifth-party dependencies that I may not even know about?
  • Across the portfolio, which controls have the most negative sentiment or negative answers?
  • What did the state of controls or risk look like six months ago, and how has it changed since then?

CISO Staff Agent Screen Shot

CISOs can also drill into specific issues, such as identifying which products lack single sign-on or multifactor authentication, or where business continuity and recovery gaps are appearing across the portfolio.

From Questions to Real Risk Reduction

CISOs can ask the CISO Staff Agent natural-language questions and receive answers grounded in continuously updated context from across the Magnitude platform. It works with Magnitude’s coordinated AI risk agents, which gather and validate evidence, assess vendors and products, monitor changes, analyze security incidents and map third- and Nth-party relationships.

That context enables the CISO Staff Agent to identify systemic weaknesses, investigate emerging issues and determine which risks matter most. It can then work with Magnitude’s Risk Impact Agent and Risk Remediation Agent to assess the potential impact and suggest actions to reduce or remediate the risk. It can also incorporate relevant external research, save analyses, schedule recurring requests and turn findings into executive-ready summaries, presentations and visualizations.

The CISO Staff Agent is also accessible through the Model Context Protocol (MCP), enabling organizations to bring Magnitude’s third-party risk context and reasoning into compatible AI experiences and workflows.

“CISOs do not need another dashboard that assumes they already know what to look for,” said Ken Liao, vice president of product at Magnitude. “They need an experienced member of their staff who can reason across their supply chain and tell them what requires their attention. That’s what CISO Staff Agent does. It can identify those issues across the entire ecosystem, N-levels deep, and help the security team focus on what matters most.”

Reasoning and Action Across the Entire Third-Party Portfolio

Traditional TPRM platforms organize information primarily around individual vendors, questionnaires and point-in-time assessments, making it difficult to see whether weaknesses are isolated or systemic. Instead, the CISO Staff Agent analyzes horizontally across all vendors and products, surfacing patterns such as repeated control weaknesses, business continuity gaps, identity and access issues, AI-related risk trends and concentration around shared downstream providers.

It can also reason within the context of a specific vendor or product, drawing on assessments, controls, supporting evidence, monitoring history and supply-chain relationships. Because many important security questions generate detailed narrative responses rather than simple yes-or-no answers, Magnitude’s AI agents can interpret free-form evidence and quantify those findings across the broader portfolio.

The same vendor may represent different risks to different organizations. Magnitude applies enterprise-specific reasoning based on each organization’s policies, risk tolerance, vendor tiering, compensating controls and governance requirements. The CISO Staff Agent grounds its responses in that organization-specific context and the evidence continuously developed by Magnitude’s autonomous governance and defense system.

“The CISO Staff Agent reasons across your entire portfolio and thinks the way an organization thinks, using its risk tolerance, tiering, and controls,” said Sean Wilcox, vice president of corporate marketing at Magnitude. “It's like having a risk analyst with 20 years of experience on staff, one who already knows exactly how your business weighs risk, and what needs to be done to minimize it, in priority order.”

Built for Continuously Changing Third-Party Risk

Anthropic reported in May that Claude Mythos Preview identified more than 23,000 potential vulnerabilities in more than 1,000 open source projects, demonstrating the scale at which frontier AI can now search for software weaknesses. This compresses the time between vulnerability discovery, exploitation and business impact, putting pressure on third-party risk programs to account for direct suppliers, products, downstream dependencies, AI-enabled services and a growing volume of rapidly changing security signals at machine speed. CISO Staff Agent is designed for that environment, helping security leaders understand new exposure and prioritize attention faster than human teams or point-in-time reporting can keep pace.

The CISO Staff Agent is available today as part of the Magnitude platform. To learn more, visit https://magnitude.ai/platform.

About Magnitude

Magnitude provides the world’s first agentic AI platform for third-party risk management (TPRM) and supply chain resilience, built to defend against Mythos-scale attacks. Its AI risk analysts continuously assess vendors and products across organizations’ entire supply chains, from direct relationships to Nth-party dependencies, delivering high-confidence risk decisions and remediations using enterprise-specific reasoning that improves over time. Magnitude is backed by Ballistic Ventures and based in San Francisco. Learn more at magnitude.ai.

Media Contact

Ted Weismann for Magnitude
Magnitude@marketbridge.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/0c9330e7-7272-4f46-9f89-2acc680a86c2


Primary Logo

CISO Staff Agent

Magnitude CISO Staff Agent lets security leaders ask questions across potentially thousands of vendors, products and downstream dependencies to identify systemic weaknesses and quickly surface the most critical risks that require their attention.

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

New Mexico Industry Digest

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.