The company behind the sound in millions of cars
Turn on the radio in almost any new car in North America and SiriusXM is part of the drive. The company delivers 160 satellite radio channels directly into vehicles, alongside a streaming business offering 425 channels. More than 60 million people listen actively each month, and more than 160 million when Pandora is included. All of that reach is largely driven by car manufacturers choosing to build the radio at the factory.
SiriusXM Canada operates as part of that organization, with over 2 million paying subscribers in Canada, plus a large population of trial users who have the radio switched on but haven't yet subscribed. Entertainment is the product, but data is the connective tissue. Every listening relationship starts with information that arrives from an automaker when a customer buys a car.
That makes the business unusual. SiriusXM Canada holds agreements with effectively every car manufacturer, and each one comes with a commitment to protect the data those manufacturers share. The company also carries a deep library of intellectual property: the broadcast content itself, the programming heard on air, and the proprietary systems behind it. Canadian privacy regulations and licensing obligations sit on top of all of it, extending into outbound telemarketing and every customer communication the marketing team runs.
Protecting all of it in Canada falls to Ben Chong, CISO of SiriusXM Canada. He has led security at SiriusXM Canada for more than 14 years, building the function from scratch and carrying it through cloud computing and, most recently, agentic AI. His remit is deliberately broad: the overall security and protection of all corporate assets, not one category of data. As he puts it, it's a holistic view of everything the company has.
His goal is simple to state and hard to deliver: keep automaker trust intact, stay on the right side of Canadian regulators, and protect subscriber data so the radios stay built into the next generation of cars. Miss on any one of the three and the built-in radio deals that carry the business are on the line.
When one wrong door opens the whole building
The fundamentals of security haven't changed, Chong says. Protect people, process, and technology. What has changed is speed. AI has accelerated the attack path so that adversaries get in faster, run simulations, and surface zero-day vulnerabilities that defenders never knew existed. He points to reports of a young attacker using AI to target victims for ransomware and to write the phishing emails that opened the door.
That pace broke the old assumption that prevention and detection alone would hold. It's not humanly possible to keep up with what AI is doing, and much of the market response has been reactive tooling rather than proactive containment. Agentic AI raised the stakes further. When independent teams build their own agents and agents start talking to other agents, the real risk is losing visibility into what's happening inside the environment.
The deeper exposure was structural. Like many companies with long operational histories, SiriusXM Canada carried rules and configurations handed down over years of legacy ownership. No one organization knows every rule on every server. On a flat network, that uncertainty compounds: an intruder who lands anywhere can reach almost everywhere, and malicious code can sit dormant for months while the team believes the problem is solved.
For a company whose automaker agreements depend on protecting shared data, the stakes were clear. Lose the data and you lose the agreements. Lose the agreements and the radio is no longer built into the next vehicle release. The greatest danger, in Chong's view, was complacency: believing an existing security model was good enough while attackers moved faster than it could handle.

From flat network to defined zones with Illumio
Chong started from a hard assumption: breaches are inevitable, so the model has to assume one is already underway. That changed the question his team was trying to answer. Not only how to keep every attacker out, but how fast they could see what was happening, contain it, and act across the whole organization. Illumio Segmentation answered that question by isolating core assets so an intruder can't move laterally to reach them.
Making the case to the business was easier than he expected. Chong walked his executive leadership team through the headlines they were already reading: supply chain attacks, ransomware, zero-day vulnerabilities, and now agentic AI. The conclusion followed on its own. Without segmentation, one incident could become an organization-wide disaster.
How the rollout actually worked
Segmentation has a reputation for being complex, and Chong is candid that it can be — if you don't know your own network. What made the difference was sequencing. Illumio started by helping the team understand its own environment, build a full asset inventory, and then narrow that list to the critical assets worth protecting first. Visibility came before policy, which kept the scope manageable.
Skills followed structure. Illumio's training portal gave staff at every level access to modules on the features they needed, building transferable skills across the team instead of locking knowledge in one person's head. Chong also credits the Illumio account management team for staying engaged long after the purchase, which he notes isn't what he's come to expect from enterprise software vendors.
What they found once they achieved visibility
The first surprise came from simply being able to see. With traffic mapped in and out of critical and non-critical assets, the team found a server exposed to the internet, with open ports left behind by configuration issues inherited over years of legacy ownership. No one had known it was there. Once the team could see it, they closed it.

Containment also changed how the team plans for a bad day. In a real breach, Chong notes, the playbook goes out the window, executives want answers immediately, and resources are limited. Defined segments let the team see where the breach is occurring and concentrate effort there instead of running in every direction.
Growing with AI without betting the company
Chong sees two camps forming around AI: those who treat it as a passing fad, and those who believe it will fundamentally change the world. He's firmly in the second, pointing to changes already visible in how people search, develop, work, and advance medicine. AI doesn't scare him; the organization's approach is to accept it, learn with it, and grow with it.
The next step is applying the same thinking to AI itself. The plan is to keep protected zones where agents can't talk freely within a segment, with defined paths so the team always knows what's communicating with the core. That way the company can keep experimenting with AI while holding the line around the assets that carry automaker agreements and subscriber data.
Segmentation isn't a project the team finishes; it's the posture they operate from. With Illumio Segmentation in place, SiriusXM Canada can keep learning and growing with AI without a pending disaster hanging over the organization.
Ergebnisse & Vorteile
- Automaker and subscriber trust protected: Critical assets holding manufacturer-shared and subscriber data are isolated from lateral attack, defending the agreements the business depends on.
- An easier conversation with the board: Segmentation was the easiest product Chong was able to sell to his executive leadership team, because the risk it addresses was immediately understood.
- Hidden exposure found and closed: Visibility revealed a server with internet exposure and open ports left by legacy configuration, which the team then investigated and remediated.
- Faster, focused incident response: Knowing which segment is affected lets a limited team concentrate resources on containment instead of spreading across the environment.
- Security skills built in-house: Illumio's training portal gave staff at every level transferable skills on the capabilities they use most.


