June 6, 2026·By Stephen Talley·9 min readYour MCP servers are production infrastructure. Treat them like it.In April a researcher showed that 200,000 MCP servers will run whatever command you hand them — and Anthropic called it expected behavior. If you wired up MCP fast, you now own an attack surface. Here's the short list of what to lock down.securitymcpagent-systemsinfrastructureoperators