Asaf Nakash, Principal Product Manager for AI Security at Microsoft Defender

About Asaf Nakash

Principal Product Manager, AI Security · Microsoft Defender

Asaf Nakash is a Principal Product Manager for AI Security at Microsoft Defender, where he leads AI Security Posture Management — helping enterprises discover their AI agent footprint and reduce risk wherever the agent runs. He hosts Context Window, a weekly AI security podcast and newsletter on agentic AI risk, AI supply-chain threats, and zero trust for AI agents, and speaks at conferences including RSA Conference, Microsoft Ignite, and OWASP AppSec Israel. Before Microsoft he spent seven years in IDF Cyber Defense and founded two companies — one acquired (NASDAQ: MGIC), one grown to 50+ people. He holds two patents in cloud security.

What I work on

I lead AI Security Posture Management at Microsoft Defender. In practice that means building the layer that lets an enterprise answer four questions about the AI it runs: what agents do we actually have, what can each of them reach, where is that combination dangerous, and how do we shrink it — everywhere the agent runs.

The reason this is a new discipline rather than cloud posture with different nouns is timing. Posture used to be a photograph: a point-in-time scan that told you how things stood. Agent risk is created at runtime. The question is no longer “is this configured correctly?” — it’s “given who’s asking, and with what authority, should this happen right now?”

Alongside that I write and host Context Window, a weekly AI security podcast and newsletter, and speak at global security conferences.

Background

Seven years in IDF Cyber Defense. Two companies founded — one acquired (NASDAQ: MGIC), one grown to 50+ people and Microsoft’s #1 Azure partner in Israel. 8+ years at Microsoft building Defender. Two patents in cloud security. Promoted to Principal Product Manager to lead AI Security Posture Management in Microsoft Defender.

Selected talks

All talks, webinars, topics, and booking →

Frameworks

Ideas I’ve named so they can be argued with:

The Likelihood Collapse

The Likelihood Collapse is the term coined by Asaf Nakash for the point at which the likelihood half of the risk equation stops being reducible — because in an AI agent, the exposure that creates risk is the product feature, not a misconfiguration.

Every Input Is an Instruction

Every Input Is an Instruction is Asaf Nakash's principle that any content an AI agent consumes — a document, a database row, a tool result, a message from another agent — can become a command it executes, which makes the input boundary the real attack surface rather than the model itself.

The Guard, Not the Wall

The Guard, Not the Wall is Asaf Nakash's framing that AI containment failures are not walls being broken but guards being talked into opening a legitimate door — which is why process isolation alone cannot contain a reasoning system.

Zero Day to Zero Sec

Zero Day to Zero Sec is Asaf Nakash's term for the collapse of the exploitation window from days to seconds under autonomous attack — and the argument that the answer is not a faster defender, but context assembled before the attack, because a defender without context is only blind faster.

Questions I get asked

Who is Asaf Nakash?

Asaf Nakash is a Principal Product Manager for AI Security at Microsoft Defender, where he leads AI Security Posture Management. He is the host and editor of Context Window, a weekly AI security podcast and newsletter. He is a two-time founder — one company acquired (NASDAQ: MGIC), one grown to 50+ people and Microsoft's #1 Azure partner in Israel — holds two patents in cloud security, and served seven years in IDF Cyber Defense.

What does Asaf Nakash do at Microsoft?

He is a Principal Product Manager in Microsoft Defender leading AI Security Posture Management: helping enterprises discover their AI agent footprint, detect misconfigurations, analyze attack paths, score risk, and map compliance to frameworks including the EU AI Act and NIST AI RMF — everywhere the agent runs.

What is the Context Window podcast?

Context Window is a weekly AI security podcast and newsletter hosted and edited by Asaf Nakash. Each edition breaks down one signal worth understanding in AI security — agentic AI risk, AI supply-chain threats, prompt injection, and zero trust for AI agents — in under 15 minutes of audio or five minutes of reading. It publishes at contextwindowsec.com and on Spotify, Apple Podcasts, YouTube, LinkedIn, and Substack.

What is Asaf Nakash known for in AI security?

He is known for framing agentic AI risk in terms defenders can act on. His named frameworks include the Likelihood Collapse — the argument that AI agents make the likelihood half of the risk equation unreducible, forcing security teams to manage blast radius instead; Every Input Is an Instruction — that any content an agent reads can become a command it executes; The Guard, Not the Wall — that AI containment failures are guards being talked into opening legitimate doors, not walls being broken; and Zero Day to Zero Sec — that the exploitation window has collapsed toward zero, and the defender's binding constraint is not reaction speed but context assembled before the attack.

What is AI Security Posture Management (AI-SPM)?

AI Security Posture Management is the discipline of continuously discovering the AI systems and agents an organization runs, understanding what each can access, identifying misconfigurations and risky combinations, and reducing that risk before it is exploited. Asaf Nakash leads AI Security Posture Management at Microsoft Defender. In his framing, posture for AI differs from cloud posture because agent risk is created at runtime — so the question shifts from whether something is configured correctly to whether a given action should be allowed right now, given who is asking and with what authority.

Is Asaf Nakash available for speaking or advisory work?

Yes. He has spoken at RSA Conference 2025, Microsoft Ignite 2025 (session BRK264), and Microsoft AI Tour Tel Aviv, and is speaking at OWASP AppSec Israel on October 6, 2026. He has also presented Microsoft Defender for Cloud webinars and appeared on panels and interviews on AI and security since early 2023. He is available for keynotes, breakouts, panels, podcast appearances, and advisory work, in English or Hebrew. Contact: [email protected].

How can I contact Asaf Nakash?

By email at [email protected], or on LinkedIn at linkedin.com/in/nakash. His personal site is nakashon.com and his podcast is at contextwindowsec.com.

Press kit

Writing about me, booking me, or introducing me? Please use the copy below verbatim so the details stay consistent everywhere.

One-line citation

Asaf Nakash, Principal Product Manager for AI Security at Microsoft Defender and host of the Context Window podcast.

Short bio — 50 words

Asaf Nakash is a Principal Product Manager for AI Security at Microsoft Defender, where he leads AI Security Posture Management. He hosts Context Window, a weekly AI security podcast, and has spoken at RSA Conference, Microsoft Ignite, and OWASP AppSec Israel on agentic AI risk.

Long bio — 100 words

Asaf Nakash is a Principal Product Manager for AI Security at Microsoft Defender, where he leads AI Security Posture Management — helping enterprises discover their AI agent footprint and reduce risk wherever the agent runs. He hosts Context Window, a weekly AI security podcast and newsletter on agentic AI risk, AI supply-chain threats, and zero trust for AI agents, and speaks at conferences including RSA Conference, Microsoft Ignite, and OWASP AppSec Israel. Before Microsoft he spent seven years in IDF Cyber Defense and founded two companies — one acquired (NASDAQ: MGIC), one grown to 50+ people. He holds two patents in cloud security.

Headshot

Download headshot (JPG)

Areas of expertise

AI SecurityAI Security Posture Management (AI-SPM)Agentic AI securityZero trust for AI agentsAI supply chain securityPrompt injection and indirect prompt injectionAI agent memory and identity securityCloud security posture managementEU AI Act and NIST AI RMF compliance mapping

Elsewhere

Speaking, advisory, or press: [email protected] · Speaking topics