"MCP adoption is outpacing security, and we're waiting until something really big gets broken to even address it. We've seen this movie before." — Israa MCP security risks are moving faster than the guardrails meant to contain them. In this episode of Making Sense of Martech, host Jacqueline Freedman sits down with Israa Alwari, founder of The Winbox, an email marketing education and agency helping DTC brands scale without burning their customer relationships down in the process. Israa brings a rare lens to the MCP conversation: eight years in email deliverability, a background in public health and occupational safety, and a habit of asking the question everyone else skips: who actually owns this when it breaks? Together they tear apart the MCP hype cycle. The answer, as it turns out, is you. The brand. The business that plugged it in. This conversation is a necessary gut check before you plug in another connector: what MCPs actually do with your data, why the risk predates the protocol itself, and why the gap between adoption and accountability keeps widening for exactly the reasons you'd expect. Timestamps 03:56 — Back to Basics: Fundamentals, correctly set-up systems, guarded platforms, solid infrastructure, drive 90% of real revenue. Every shiny new tool is just an add-on to that foundation. 05:43 — Moving at 100,000mph Without a Seatbelt: Martech's move-fast culture is exactly what makes MCP adoption dangerous. Building fast without monitoring what you've built is how deliverability and data problems compound silently. 12:30 — Education Before the Checkbox: Platforms should require real education before a user can activate an MCP, not a liability-clearing terms-of-service click that nobody reads. 17:50 — The Risk Started Before MCP: Data-exfiltration risk didn't start with MCP. SaaS vendors were quietly scraping client lists out of Klaviyo three years ago. MCP is a new surface for an old, unresolved vulnerability. 20:18 — Platforms Should Build AI In-House: If a platform has built-in AI, why is it pushing users toward external MCP connectors instead of delivering those insights natively? The incentive gap is a security problem hiding in plain sight. 25:30 — The First Name Field as an Attack Vector: A malicious prompt in a first name form field can instruct an MCP to export your entire contact list. Most teams would never notice until the damage is done. 34:10 — The Business Always Takes the Hit: When an MCP breach happens, the platform, the builder, and the regulator all walk away. The only party left holding the damage is the business that plugged it in. 41:55 — Your Customers Never Consented to This: Customers gave their data to buy a product, not to train AI systems. That consent gap is a liability most brands haven't thought through once. 47:36 — Biggest MCP Risk: Your Own Employees: The most urgent MCP threat isn't an outside hacker; it's your own employees using personal AI accounts to pull company data with zero audit trail. Sponsor Brought to you by Hightouch, the leading composable CDP and decisioning platform trusted by brands like Domino's, Chime, and Aritzia. 90% of customers have a real use case live within their first week, delivering world-class personalization at scale. Learn more at hightouch.com/msom. Connect & Subscribe Subscribe to Making Sense of Martech wherever you get your podcasts. Follow us on TikTok, LinkedIn, and don't forget to like and subscribe on YouTube.