How to Not Ruin Your Security Architecture with Agentic Coding
Aanmelden
How to Not Ruin Your Security Architecture with Agentic Coding
A KNVI Interest Group Architecture session with Yury Sukhoverkhov and Gijs Brandenburg
Date: 2026-09-22 Time: 18:00 – [tbd] (walk-in and networking from [time]) Location: [on-site, location tbd] Language: English Costs: Free for KNVI members | Fee for non-members
About this session
AI coding agents are moving into engineering teams faster than security architecture can keep up. They don't just suggest code: they write, execute, and deploy it autonomously, acting with real permissions on real systems. The productivity gains are undeniable. So are the incidents: hijacked agents, poisoned plugin ecosystems, deleted production data, and credentials leaking at machine speed.
In this session, Yury Sukhoverkhov and Gijs Brandenburg take an architect's view of agentic coding. What does it actually change? Why do familiar foundations (trust boundaries, identity, least privilege, change management) quietly erode when autonomous agents enter the landscape? And which architectural principles, patterns, and governance choices keep the gains without inheriting the chaos?
The session grounds this in established threat models and current research: the new OWASP Top 10 for Agentic Applications, MITRE ATLAS as a framework for adversarial tactics against AI systems, and real incidents from the past year. The message for architects: this is not a niche tooling concern, but a structural shift in the risk landscape.
What you'll take away
You'll leave with a practical threat model, a set of design principles to apply in your own organisation, and a set of Ways of Working heuristics to incorporate into your engineering and software architecture practice. We close with a moderated discussion: how should the architecture function respond when agents become a new class of principal in the enterprise?
No hands-on experience with coding agents required - curiosity and a healthy dose of professional paranoia suffice.
About the speakers
Yury Sukhoverkhov is CTO at Ditto, a healthcare platform focused on the purposeful and responsible use of AI, and a two-time founder with around 20 years of experience as a software engineer, architect, and engineering leader. He has scaled a B2C product to 60 million users, led engineering teams across MedTech, HealthTech, gaming, and EV charging, and written software that now orbits the Earth. Yury describes himself as fluent in AI coding agents but skeptical of AI hype, and a particular focus of his is software architecture that keeps coding agents from going mad. A committed Domain-Driven Design advocate, he brings the hands-on engineering perspective to the session.
Gijs Brandenburg is an enterprise and security architect and Managing Director of CTRL Disrupt. He spends most of his time on how organisations govern risk and design for resilience, work he's done for financial-services firms and currently in the defence and public-security sector on risk-based enterprise architecture. Secure enterprise architecture is the thread running through his training as well as his work: he studied Information Security Management at The Hague University of Applied Sciences, specialising in enterprise security architecture, and holds an MSc in Enterprise IT Architecture from Antwerp Management School, with a thesis on building enterprise architecture from a risk-based starting point. Next to his work he sits on the board of the KNVI Interest Group Architecture. His approach to security is refreshingly practical: real, value-driven outcomes over ticking compliance boxes.
Programme (TBD)
| Time | Item |
|---|---|
| [time] | Walk-in & networking |
| [time] | Welcome by KNVI Interest Group Architecture |
| [time] | Session: How to Not Ruin Your Security Architecture with Agentic Coding |
| [time] | Moderated discussion |
| [time] | Drinks & networking |
For whom
Enterprise, solution, and software architects; security architects and officers; engineering leaders; and anyone responsible for governance of AI in the software delivery lifecycle.