Skip to main content
NewCIS MCP Server Benchmark v1.0.0 is hereRead the CIS announcement (opens in a new tab)
Work

Selected Work

Standards authorship, benchmarks leadership, AI enablement programs, and applied AI security work at the Center for Internet Security.

Published Benchmarks

Public Author

CIS MCP Server Benchmark v1.0.0

Center for Internet Security · Released September 16, 2026

Authored the first CIS Benchmark for Model Context Protocol servers: 55 prescriptive, vendor-neutral recommendations across 10 security domains, covering governance and versioning, transport and connectivity, authentication and authorization, client (host) and server configuration, data protection and privacy, observability and audit, supply chain security, isolation and execution safety, and resource limits and caching. Each recommendation ships with rationale, audit procedures, and remediation guidance.

What it demonstrates

End-to-end ownership of a published security standard, from scoping MCP-specific risk through consensus review to auditable, implementable recommendations that organizations can configure and verify today.

MCP Security Security Benchmarks Secure Configuration Audit & Remediation Standards

Published Guides

Public Principal Co-author

CIS Controls v8.1 Model Context Protocol (MCP) Companion Guide

Center for Internet Security · April 2026

Translated MCP-specific risks into practical guidance mapped to all 18 Controls. Covers MCP clients, servers, tools, resources, prompts, authorization, least privilege, auditability, confused deputy risk, tool boundaries, third-party server governance, and secure configuration considerations. Co-authored with Shreyans Mehta (Cequence).

What it demonstrates

Andrew's ability to translate a fast-moving AI protocol into practical security guidance aligned with an established control framework, combining protocol-level technical depth with clear, actionable implementation guidance.

MCP Security Controls Mapping Authorization Secure Configuration Tool Boundaries
Public Collaborator

CIS Controls v8.1 AI and LLM Companion Guide

Center for Internet Security · April 2026

Collaborated on the AI and Large Language Models Companion Guide, contributing to practical guidance on LLM security, model-layer risk, inference behavior, data handling, monitoring, and control mapping for enterprise AI environments.

What it demonstrates

Andrew's ability to contribute meaningfully to practical AI security and adoption guidance for enterprise AI systems, bridging model-layer technical risk with organizational controls.

LLM Security Prompt Injection Data Handling Controls Mapping Model Risk
Public Collaborator

CIS Controls v8.1 AI Agents Companion Guide

Center for Internet Security · April 2026

Collaborated on the AI Agents Companion Guide, contributing to guidance on agent autonomy, tool invocation, memory, planning, human approval gates, monitoring, and secure integration of agentic AI workflows into enterprise environments.

What it demonstrates

Andrew's ability to connect agentic AI risk to practical security controls and enablement guidance, making emerging multi-agent and autonomous AI risk patterns actionable for security practitioners.

Agentic AI Human Oversight Tool Invocation Controls Mapping Multi-Agent

Authorship note: Andrew Dannenberger is the author of the CIS MCP Server Benchmark v1.0.0. The MCP Companion Guide lists Andrew Dannenberger as a Principal Author alongside Shreyans Mehta (Cequence). The AI/LLM and AI Agents Companion Guides are collaborative Center for Internet Security (CIS) publications; Andrew contributed as a collaborator/editor. Authorship credits reflect publicly available acknowledgment pages. This personal website does not represent CIS.

Active Initiatives

Ongoing AI Benchmarks Lead / Community Coordination / Roadmap Support

CIS AI Benchmarks Community

Ongoing

Leading AI Benchmarks Community work to advance practical guidance for securing emerging AI technologies. Responsible for scope definition, community coordination, feedback cycles, and publication roadmap, working with practitioners to translate AI security risk into benchmark-style, auditable guidance.

What it demonstrates

Leadership at the intersection of cybersecurity standards, AI security, and practitioner-focused implementation, coordinating across stakeholders to produce guidance that organizations can actually act on.

Security Benchmarks AI Security Community Standards Leadership
Ongoing AI Assistant Prototype and MVP Leadership

AI Chatbot Initiative

2023 – Present

Built and advanced a documentation-focused AI assistant from proof of concept toward minimum viable product. Created a knowledge-base chatbot for internal support workflows and public documentation, maintained AI research resources tracking emerging advances, risks, and organizational implications.

What it demonstrates

Andrew's ability to move AI tooling from initial concept to a practical, support-facing use case, combining technical implementation with a clear understanding of where AI adds value in knowledge management and customer workflows.

AI Chatbot RAG Documentation MVP Knowledge Base
Ongoing MCP Server Development and Customer-Facing AI Integration Support

Platform MCP Concepts

Ongoing

Developing MCP server concepts for a security product platform. Engaging customers and technical stakeholders on secure integration patterns, governance, supportability, and AI product enablement, connecting MCP security standards to real platform and customer workflows.

What it demonstrates

Andrew's ability to connect AI security standards to real platform and customer contexts, bridging standards work and engineering concepts to practical product adoption guidance.

MCP Product Enablement Customer Engagement Integration
Ongoing Secure AI Enablement Lead / Presenter / Facilitator

AI Office Hours and Internal Enablement Programs

Ongoing

Designs and leads recurring AI Office Hours and internal enablement sessions for beginner and advanced audiences. Converts complex AI security and adoption topics into practical workflows, exercises, and clear guidance, focusing on safe AI use, prompt design, workflow improvement, and responsible internal experimentation.

What it demonstrates

Andrew's ability to teach complex AI concepts clearly and practically to diverse audiences, a direct expression of the communication and adult-learning background that informs all his standards and enablement work.

AI Enablement Training Safe AI Adoption Facilitation Prompt Design
Public Ongoing
Personal website: This is a personal professional portfolio. This website does not represent Center for Internet Security (CIS) or any employer.