/
Partners & Integrations

5 Practical Steps for Frontier AI Security Readiness From a WWT Cyber Expert

On Christmas Eve 1849, a fire that started in an exchange on Kearny Street burned roughly fifty buildings out of the middle of San Francisco.  

The city was built of wood, packed tight, and had no organized fire response. The town council met that same afternoon and passed a resolution to organize fire companies. Every one of those risks was visible before the fire. It took the fire to force the meeting.

Steve Hollar, a technical solutions architect at WWT, sees the same pattern playing out with frontier AI models today.  

The risk of fast-moving, AI-accelerated attacks has been building for years. Security teams have understood the fundamentals long before frontier AI made headlines, but what’s changed is the urgency around them.

We sat down with Steve to learn how he’s advising clients to approach frontier AI. He laid out a five-step plan that offers security leaders a grounded, practical way to get prepared now.

Step 1: define the protect surface before you build anything

Before any architecture gets built, Steve said, organizations need to answer a more basic question: what are we actually trying to protect?

Zero Trust founder John Kindervag breaks Zero Trust down into a five-step model around one core idea: the protect surface. That’s the specific data, application, asset, or service an organization is trying to defend.

The five steps to Zero Trust include:

1. Define your protect surface. Identify the critical data, applications, assets, and services that matter most.

2. Map the transaction flows. Understand what legitimately needs to communicate with that protect surface, and from where.

3. Build the architecture. Design the architecture around what steps one and two revealed, placing controls as close to the protect surface as possible. Segmentation is typically how that placement gets enforced.

4. Create the policy. Establish the who, what, when, where, why, and how of access for each protect surface.

5. Monitor and maintain. Inspect and log traffic to the protect surface continuously, and feed what you learn back into step one so the next protect surface starts stronger.

Steve said the first two steps are the ones organizations skip most often. “A lot of times we see interest in the architecture or buying a new solution,” he said. “But we recommend starting with defining the protect surface from the start.”

Skipping straight to architecture means building controls without knowing what they’re actually protecting or why. Understanding your protect surface ensures you can tie your Zero Trust strategy back to business value.  

That turns a Zero Trust program into a strategic asset.

Step 2: start small to prove the model before you scale it

Once your team defines the protect surface, the next step is deployment, and this is where Steve sees the most operational risk.  

Frontier AI is accelerating the threat, and the instinct for a lot of organizations is to accelerate their response to match.

“Frontier AI models are pushing us to move fast and break things,” he said. “But we don’t have to take that approach. We can still approach things very methodically and practically.”

His advice is to start with a low-stakes protect surface or a visibility-only deployment before rolling controls out across the full environment. This proves the model works, builds internal trust in the process, and earns the right to extend it to your highest-value assets.

Starting small removes the friction of deployment hurdles, Steve explained. It allows teams to operationalize Zero Trust, understand how it works in their environment, and then move on to other protect surfaces over time.

Steve recommends visibility-first deployments, especially for teams just getting started with Zero Trust. They shrink dwell time, the time attackers can be inside your environment undetected, even before enforcement is in place.

“Even if we don’t have enforcement in place yet, we can start to identify hotspots and add high-level controls,” Steve said. “Having that visibility still helps limit dwell time and risk, even before full enforcement kicks in.”

The path to a faster, AI-ready security posture is a methodical rollout that starts small, builds trust and operational muscle, and scales from there.

Step 3: build containment into the architecture

With a protect surface defined and a deployment model proven, the next step is architecting for containment. This controls what happens after a breach occurs.

“We want to stop the kill chain,” Steve said. “This means limiting what an unpatched system can do if it’s accessed and breached.” For Steve, stopping lateral movement is the difference between a major, catastrophic attack and a small, everyday cyber incident.  

Steve believes that frontier AI has fundamentally changed the clock on the kill chain.

The attack methodology is the same one security teams have studied for years. But the speed at which an attacker can move through it has accelerated. A good containment strategy needs to operate at the speed the threat now demands.

Step 4: train your team before the breach happens

Architecture and policy only work if the people behind them know how to respond under pressure. That’s why Steve puts rehearsal on the same priority level as technical controls.

WWT runs an Advanced Technology Center where organizations can test Zero Trust architecture in a safe environment before touching production. They also operate a Cyber Range where security operations teams run tabletop exercises to build muscle memory for incident response.

The value lies in testing architecture and training teams ahead of a real incident, regardless of which provider runs the exercise.

“Just having the ability to test stuff, to get exposed to it, that’s valuable,” Steve said. “And tabletop exercises are still really valuable, no matter who’s running them.”

If your security team has never practiced responding to an AI-accelerated breach scenario, that rehearsal is worth scheduling before an actual breach forces the issue.

Step 5: maintain the right posture as the threat evolves

Finally, the work shifts to long-term posture. Steve’s biggest concern at this stage centers on attitude as much as technical readiness.

“We’re a little slow as an industry to adopt the idea of connecting securely,” Steve said.

He drew a comparison to how networking itself evolved. Early networks were built to connect everything to everything. As the risks of that openness became clear, the industry adapted and built in the controls that connection required. Frontier AI is simply the next stage of that same evolution.  

Steve is also careful to flag overcorrection as just as risky as denial.

“We’re also going to see a risk of organizations overpreparing and thinking AI is going to take over,” he said. “Yes, there will be incidents, and there will be consequences. But if we prepare well, design quality controls around the things that matter, and keep up good hygiene, we can manage that risk well.”

Steve likened it to wearing a seatbelt while driving. We don’t expect or plan to get in an accident, but we’re ready to protect ourselves in case it happens.

“The biggest guidance is just don’t be afraid,” he said. “Risk exists across our whole daily life. Putting the proper controls in place, like a seatbelt while driving, is what really moves us forward safely.”

The right response to frontier AI is preparation, not panic

A lot of CISOs feel pressure to prove they’re reinventing their security strategy for the age of frontier AI.  

Steve hears that anxiety constantly in client conversations, and from his perspective at WWT, it’s based on a misunderstanding of what frontier AI is.

“The most common misconception I’m hearing is that frontier AI is fundamentally new,” he said. “An AI system is just another workload. It’s got complexity and scale we haven’t seen before, but we already have controls, like breach containment, that secure against it.”

Steve compares it to how networking itself evolved, adapting its controls as new risks emerged. He sees frontier AI as simply the latest development cybersecurity has had to absorb.

The work that matters right now is the same work security teams have known about for years: Zero Trust principles, limiting lateral movement, reducing attack surface, and building real visibility into the environment.  

Frontier AI hasn’t added new items to that list, just raised the priority of every item already on it.

Ready to put these steps into practice? Explore strategies to prepare for frontier AI threats.

Related articles

Experience Illumio Insights today

See how AI-powered observability helps you detect, understand, and contain threats faster.