A Zero Trust Leadership Podcast

Zero Trust for the AI Era | John Kindervag, Rich Mogull, and Don Yeske
Season Four
· Episode
14

Zero Trust for the AI Era | John Kindervag, Rich Mogull, and Don Yeske

John Kindervag, Rich Mogull, and Don Yeske join to celebrate the launch of their new book, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era.

Transcript

Raghu: [00:00:00]

Welcome to The Segment. I'm your host, Raghu Nandakumara. AI is giving attackers new ways to move faster, but the question for defenders is a familiar one. If someone gets in, how far can they go? To help me tackle that, I'm especially thrilled to be joined by three amazing guests.

Raghu: John Kindervag, the creator of Zero Trust and chief evangelist at Illumio. Rich Moggel, chief analyst at the Cloud Security Alliance, whose work spans cloud and AI security. And Don Yeske, who brings years of federal cybersecurity leadership to his work, helping agencies protect sensitive data. John, Rich, and Don, welcome to the show.

John: Thanks, man. Great to be here. Yeah, thanks for having us.

John: Now, what do all four of us have in common? Yeah, including me. We each contributed to a new book, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Between us, we've got a [00:01:00] lot to say about what attackers can do, what defenders can control, and where organizations should start.

Raghu: So John, with that, this whole book, the genesis of it was very much from what you created, uh, back in 2010. So why was it important to publish this book, and why now?

John: Well, certainly we're seeing a lot of disruptions and questions in the world of AI, right? And so we needed to address how does Zero Trust fit into the world of AI.

John: And there was a lot of pressure on me to write a book, but I... Oh, a wise person once told me a long time ago that there are no great books, only great chapters. And so instead of me trying to, you know, do a lot of research and quote the Rich Moguls and the Don Yeske of the world, I reached out to people that I knew who were experts in this and said, "Contribute a great chapter [00:02:00] so that then we can combine them all and have a great book, and we can answer these questions about how do we control AI and protect our sensitive data assets, and how do we use, uh, Zero Trust methodologies and strategies to do that."

Raghu: So Rich, Don, when John approached you and said, "Hey guys, can you contribute a chapter to my book?" What were you thinking? Oh, no. Another deadline?

Don: I, I was, I was just grateful for having been asked, frankly. I have a little bit of imposter syndrome going on here, uh, sitting next to John Kindervag on a, on a podcast. Being asked to write a chapter for a book, that kind of blew my mind actually, initially. So, uh, honest answer, I, I, I didn't feel like, uh, you know, I was necessarily the right person to do that, but I gave it my best shot.

John: Well, you were Don, because you wrote your master's thesis on protect [00:03:00] surfaces, and that's... I needed somebody to write a chapter on protect surfaces, and who else better than somebody who studied it and wrote a master's thesis. I mean, you know, when I come, when I think back on where this all started, uh, 16 years ago this month, uh, and now I find people are writing master's thesis and getting doctorates in Zero Trust, that was un- unbelievable.

John: But like when Rich wrote, a thing about, AI and Zero Trust, his comment, "Zero Trust or zero days, your choice," I mean, I had to have Rich on. And that, you know, like, uh, I've known Rich for more years than I can... I can't remember when I first met you, Rich. That's how long it is. Yeah, it's been a long time.

Rich: I mean, and we are, uh, both, I would like to say, recovering analyst of, uh- Yes ... of different sorts, even though I... It's still my title, but it's not that kind of analyst anymore. And, uh, a- and when John asked me to do this, at first it was, like, kind of... Because Zero Trust has not been an area that I have spent a lot of [00:04:00] my focus.

Rich: So y- you know, a- as somebody who's... Well, it's been about a year I've been at Cloud Security Alliance now, but long before that, about 18 years of, uh, and about 15 of those focusing heavily on cloud and that style of deployment architectures, uh, it, it was definitely like, I'm like, "John, what do you, what do you want me for?"

Rich: And then he mentioned that quote, and, uh, that particular research that I had published on there. I was like, "Yeah, that, that's a good fit for this. Okay, I'm in."

Rich: And my reaction was, "Why me?" I'm sure there is at least a gazillion other more qualified people to write a chapter than... Maybe he just needed that extra chapter and that's, he handed one to me.

John: Um- No, no. But I mean, I've, l- look, I've known you for a long time before you ever joined Illumio too, back when you were at Citibank, and you were one of the first customers of Illumio. The first, you were one of the first people who understood the value of segmentation. So when I needed a chapter on the segmentation imperative and why segmentation is important as a foundation of Zero Trust to control access [00:05:00] to these new vulnerable zero-day, uh, systems from attackers that have these new powerful attacks, uh, w- who better than somebody who spent 15 years at Citibank to, uh, doing that kind of stuff?

John: So it all, it, to me, you know, it was a great o- opportunity to bring people that I knew and admired together, people that I, I have their books on my desk right over here, you know, a- to, to create something that was, that was unique and different and, and better than one person could do, no matter who that person was.

Raghu: So D- Don, right, as John said, right, you've essentially done your thesis on protect surfaces. I did. And a protect surface is a, is a key part of how you actually make a Zero Trust strategy real, right? So explain what a protect surface is and why it's so important. Well, let me, let me answer that in the reversed order.

Don: Uh, I'll, I'll start by explaining why it's [00:06:00] important. The reason I chose protect surfaces as the topic of my master's thesis at NDU, is because of my experience implementing Zero Trust at the Department of Homeland Security, and earlier than that, at the Department of the Navy when I was serving as the CTO there.

Don: And the reason I have, over the course of that experience, come to believe that, identifying protect surfaces is the one first critical step you have to take, is because I've seen what we've actually done. Mm. And we've done what we were told to do. And what we were told to do is go implement, you know, various cybersecurity tactics that are good tactics, right?

Don: Go implement multi-factor authentication. Go implement, you know, uh, you know, better, uh, uh, recording and, and staging and distribution of your event and incident data, right? Go segment your networks. These are all good things to do, and they will actually produce good results, but they will only [00:07:00] produce good results if, and this is a, this is a critical if, if you're actually measuring what you're defending.

Don: If what you're measuring is the implementation of tactics, there is an endless space in which to implement those tactics. And the government's actual experience doing that is not, this is not me saying it, this is... CISA published a report in 2025 that was required by Congress, and that report listed how far we had come from the, the, the definition of those tactics, from the issuance of those orders.

Don: Like, tell me how well you did. And the report was not good. Uh, it had some good things in it, but what it said was, for example, the example I gave earlier was, uh, implement multi-factor authentication and implement phishing-resistant multi-factor authentication. In the year, at the moment when, uh, OMB memorandum [00:08:00] M-22-09 was, was written, we were at about 60%, give or take, Kentucky windage, about 60% of federal agencies had done what the task required, which was for your public-facing stuff only, offer people the alternative of signing up for phishing-resistant MFA And about 8%, give or take, of public-facing applications that were, that were produced by the US government offered that alternative in a phishing-resistant form.

Don: When that task was due, which was over a year later, we'd reached about 70%. When the report was written in 2025, we'd reached 80%. That feels like progress, right? We went from 60% of the doors closed to 80% of the doors effectively closed. And over the same period of time, we actually decreased the amount of phishing-resistant MFA and increased the amount of not [00:09:00] phishing-resistant MFA over the same period of time.

Don: So think about that. Like, the whole US government engaged all of its might and all of this, all of this technical and, and programmatic apparatus to go do this one simple thing, just turn on phishing-resistant MFA. We failed because a door that is 60% closed or a door that is 80% closed is what? Open. Mm.

Don: Right? And, and all of those things together, even if you added up every tactic that was given in M-22-09, even if you added up every tactic that was given in the DoD at the time, uh, Zero Trust reference architecture and the implementation guide, does that add up to secure? It might if you focused all those actions on something in particular.

Don: If what you're measuring is, did I make that one thing safe, right? It, it, it is, it, the, it is the most important [00:10:00] thing we can do is figure out what the hell we're protecting. And when we figure that out, the rest of this is very good guidance that you can absolutely implement But don't implement it blindly and don't try to do it to everything all at once because you will fail.

Don: People are already overwhelmed by Zero Trust, and it's, it goes all the way back to 2010, and people are overwhelmed by it. Now we're talking about frontier AI and applying Zero Trust in the age of frontier AI. That is overwhelming unless you simplify the problem. And the way to simplify the problem is figure out what you're protecting, measure at the end of the day whether or not you protected it, and improve accordingly.

Raghu: So with that, Don, you spoke about frontier AI. So Rich, you've been at the Cloud Security Alliance very much, in my opinion, sort of front and center and really pushing forward kind of what is necessary to secure organizations, um, and sort of keep up with the pace of frontier [00:11:00] AI developments.

Raghu: And I think the, the post mythos, sort of the readiness white paper to be honest, is essential reading for any security practitioner. And in that you talk about the adoption of Zero Trust and then key controls. Um, when we're talking about sort of protect surfaces, in the age of AI, in AI forward organizations, what become the key protect surfaces?

Rich: Or does, do those change at all? Yeah, I mean, so when this all started, I kind of took a step back, and it was actually before the release of Mythos, I kind of did a, an initial blog post looking at adversarial AI, and it was driven by some of the things I was seeing at PromptGTFO, if you knew what that was, one of Gadi Evron's, uh, things and, and seeing a lot of researchers and how they were using it, uh, how I was using AI and how it was enhancing my own research.

Rich: And I came up with this concept, uh, I called it core collapse, and I won't go into all the details of that unless we end up having time. But essentially, trying to distill the problem down around [00:12:00] adversarial AI. How does it improve adversaries, and then how does that map to what our defenses are? And a lot of this I think is going to tie in with what, what Don was just talking about, and of course with what John's been talking about for 10 year- or more than 10 years.

Rich: Basically, for adversaries, we saw it was having kind of three effects. It was increasing the skill level of an attacker. It was increasing the ability to discover new vulnerabilities and chain exploits, which I guess ties that piece in together. But very early on, even without Mythos, we were already seeing evidence that this was occurring.

Rich: And it was increasing the scale, because you could use things like agent swarms to, uh, go after a single target, or you could take one vulnerability and attack all targets. So I kind of took it from the perspective of let's classify how this is actually changing attacks. And things that are limited there is, one, it's not magic.

Rich: There's not new classes of exploits that are appearing. [00:13:00] Uh, there's, you know, we're, we're not seeing some... These things are not magic. They're just relentless, and that's really what that key difference is, and they're becoming more widely available. So that was the setup. So what does that lead in terms of going back to the attack surface side?

Rich: So let's correlate that with the kinds of the nature of if I was an attacker and I had 1,000 people I could throw at a problem, and they all had a pretty decently high and consistent skill level, what are the kinds of things that would change? What would be that surface on the defender side? Uh, so a lot of that was around, or at, at least what I was seeing, is the biggest areas that we see in terms of our, on the defense side is once an attacker, they, they have to look a lot to find the front door in or the back door in.

Rich: And once then they get in, then they're exploring the graph. They're doing the search function on the inside of our organization. Any red [00:14:00] teamer does this, any pen tester, any malicious attacker's doing the same thing. Let's get my foothold, my dirt attack's got all of this, privilege escalate, expand out.

Rich: Well now What does that mean in terms of having AI agents doing all of that? They can attack from a thousand simultaneous directions at once. They don't get tired and they don't sleep. I mean, they might just die and then a new one spawns, depending on how many tokens you have as you're going at it. And then once they get inside, they're all going to swarm around that, and then they're going to do the same thing, and they're going to just...

Rich: It, it's just a search function on their part So what does that mean in terms of attack surface, protection surface? I mean, it, it- it's kind of everything. It's everything. Because things that would take a long time for a human to get to, swarms of AI can get to them much more quickly. Now, right now they're super noisy, they're leaving a lot of residue, they're whatever.

Rich: Throw that all out the window. Essentially, they're going to go, [00:15:00] they're going to hammer that maze, and they're going to explore every single pathway in that maze as they come in. And that's kind of what led me back to y- Zero Trust. I mean, I've been talking a while. I'll just leave, like, one anecdote. When I was really working on this research and I actually wanted to do...

Rich: I had a longer mathematical paper, about 20 pages, kind of, of attacker-defender asymmetries and how AI affects and defenses affect. I'm riding along my bike and I'm like, "Oh, damn." I mean, that's how I, I clear my head. Go out for a bike ride, go out for a long hike, something like that, to really think through the problem.

Rich: And I was working through the fake math in my head, and I realized, "Oh my God, the only thing that's going to help us is more security boundaries." Well, how do we implement more security boundaries? Better compartmentalization. Well, how do we do that? And it's like, "Ah, crap, it's Zero Trust. Great."

Raghu: Nice. Uh, well, we're going to come onto the maths part in a second, right? Because I, I do, I do have a question around that. So John, protect surfaces, right? When [00:16:00] you published your first paper on Zero Trust in 2010, there was no mention of protect surfaces in there. In fact, that came about later. Right. What, what was it in sort of the evolution of your thinking that made you think, "I need this term, because without this, Zero Trust is just a good idea"?

Raghu: What was that, John?

John: Well, I mean, it was because, first of all, I, uh, you know, step one of Zero Trust was originally define your data, and I was looking at it from a purely holistically data perspective. And then people said, "Well, I want to use it for my assets. Uh, I want to use it for my IOT." I wa- and I started doing a lot of that stuff.

John: And, and then I thought, okay, Warren Buffett's partner Charlie Munger has a st- saying, "Invert. Always invert," right? So when you have a problem, invert that problem. And I was thinking about the problem of the attack surface, which is, to me, uncontrollable. It's constantly growing like the, the universe, right?

John: So it's expanding, and everybody's talking about controlling the attack surface, and I thought, "Well, that's [00:17:00] pretty, pretty difficult." And I, I had this e- example that a lot of people have seen of protecting the president of the United States, and I thought, "Oh, that's the exact opposite of the attack surface, is the protect surface," right?

John: So I can shrink the attack surface down orders of magnitude to something very small and easily known. That's the protect surface. And we even have a chapter in this book unique amongst, I think, all cybersecurity books probably that will ever be written. We have a chapter from a very renowned, redoubtable Navy SEAL, Clint Bruce, uh, who was one of the...

John: He was a Navy SEAL officer, went to Annapolis, uh, played football for four years, played in the NF- NFL and decided that wasn't challenging enough, so he went to become a Navy SEAL. And he talked about how his favorite weapon is a map, because a map is bounded, it's four sides and an X, and an X is where I am or an X is where I need to be.

John: And he talked about terrain that they looked at, like when they're in [00:18:00] Afghanistan and they're looking at things that they can't control, the influence terrain. So frontier AI, we can't control that, right? It will influence our decisions, we can't control it. And then we, we have, uh, terrain that we can control that he calls impact terrain, but there's too much of it.

John: You can't do it all. And so he talked about then the high ground, the, the, the hill that you fight from, the thing that you hold and control, and that's really what the protect surface is. It's the high ground in the battle against whatever adversary we're facing, whether it's a human adversary or an AI adversary.

John: And, and that's when, when I figured that out, um, and that it's been, I think, 2016, something like that, 2017, I don't remember what year. When I figured that out, I figured out that would, that would make Zero Trust more easily, easily consumable for [00:19:00] people to understand, and that turned out to be true because, you know, now they, they know what they're trying to do.

John: Find the list of protect surfaces, figure out how important they are, and then build out your environment one protect surface at a time. Because where I see Zero Trust failing is when people try to do it all at once for their whole organization, and that never works. It's too big.

John: You can't do it. So you always have a low maturity in that organization. But you can have a high maturity in a single protect surface, right? Like PCI. So I'm a recovering analyst, Rich, but I'm also recovering QSA, right? And QSA is a... PCI is a 12-step program, so I'm always going to be in recovery, right? Uh, but, uh, you know, what we learned is to segment out and so that we could...

John: We were only concerned about the scope of the cardholder data environment, and that becomes a protect surface. And so I, I went back on that, on that experience as a QSA and designing [00:20:00] PCI-compliant environments.

John: So it was, uh, it was 2014. Um- Ah, was it? Okay. Yeah. Yeah. I, I had to look that up. Uh- Yeah ... it was, it was, uh, 2014 and it, and just to, just to foot stomp this, what seems to have motivated that is exactly what you said.

John: People were kind of looking at Zero Trust at the time and, and going, "Hey, you know, this all sounds good, but how do I actually do it?" Right. And in, in, in my view anyway, and I, I'm sure in yours, this is what makes you able to actually do Zero Trust and not just talk about it as some sort of panacea you'll never achieve.

John: And one of the things too, you know, because I've had people say, "Weren't you upset that people didn't jump on the Zero Trust bandwagon early?" Because it took a, it took a long time before lots of people started talking about it. And the answer was no, because I got to make a lot of mistakes that other people didn't have to, and then put them together into a methodology.

John: So we have the five-step methodology: [00:21:00] define your protect surface, map your transaction flows, architect the environment, write the policy, and then monitor and maintain. And that's actually how the chapters are aligned in the book as well. So as you're going through this book, you know, it's available for free for download. It'll be step one, step two, step three, step four. So Don's chapter is step one, define your protect surface, and then we go all the way down through monitor and maintain.

John: So there's, you, you can logically follow these authors as they tell you how to do each step in the five-step process.

Don: I asked for my chapter to come after the chapter on terrain and, and war fighting from, from the, the expert that provided it, uh, so I could...

Don: You know, I didn't have to articulate those concepts myself, I can just build on them. Yeah. Uh, other than that, uh, you know, I didn't actually know where it w- where it would fall, but John was very gracious, like, "Yeah, that makes sense to me." So that's what we did.

Rich: You know, i- it's also fascinating for me, we're having this [00:22:00] discussion now, so, uh, I, I'm not only a recovering analyst, I'm a recovering vendor and product manager.

Rich: And right before this, I was over at, uh, at FireMon, which obviously they've got a... Just coincidentally they got a partnership with Illumio. I was there when that was starting, was involved in kind of the early parts of that. But the, that piece of it aside, the thing that I was working on over there, which, uh, still not at liberty to discuss, was very much focused on this exact issue of organizations struggling on their Zero Trust journey.

Rich: Not just Zero Trust, uh, uh, I would say not even just microsegmentation, even macro-segmentation of their networks, because they were becoming overwhelmed. And, and we all know large enterprises, the complexity of those networks is just off the charts, and layers and layers of history. I mean, you could mine those things.

Rich: I have a history degree, not a, a tech degree, and I, I could probably use my history degree to like explore those networks. There's... And like probably find some Egyptian tomb back at [00:23:00] the, uh, you know, down in the... Imhotep is like, you know, he's over in the, that slash 24 subnet over there. Uh- But there was that intimidation factor.

Rich: And that's kind of one of my hopes that'll come out of this, because this is-- we're also seeing this as people are dealing with the stuff I'm focused on, which is how do you prepare your organization for frontier AI, uh, adversarial frontier AI. And it's that, that where do we start being intimidated, scoping things down, figuring out, you know, what does that protect surface need to be, which is something that my independent research with Don and I have never interacted once forever before, but that became a role in kind of the equations and stuff that I was coming up with for, uh, for my research and, and how that interacted.

Raghu: So Rich, because you've got the mic, right? So quoting you from your chapter, and particularly about sort of the math side of it, you say, "Attackers face a bounded search problem." This is in the context of essentially attacker-defender asymmetry. Um, [00:24:00] "Attackers face a bounded search problem. Defenders face a combinatorial complexity problem."

Raghu: Yeah. For our listeners, and really for me, explain what that means in layman's terms, and why it's important to understand that concept.

Rich: Yeah, if you think about it, for an attacker using, with or without AI, they get to pick who they want to attack, they get to pick what they're looking for, they get to pick how long they're going to put an effort into that.

Rich: Uh, and so that's why I call it a bounded search problem. They're searching within... A- and what, what came to me on that bike ride I mentioned before was the problem space. What's the problem space an attacker has to deal with versus the defender? How big, how many variables, you know, math way above my skill level, you know, recall history degree, uh, and not a mathematics degree.

Rich: So that's that bounded search problem. They get to control what they're looking for. On the other [00:25:00] side, as defenders, we have to defend all resources from all potential vulnerabilities and all potential exploits from all potential attackers for all time. So that's this times this times this times this times this times this.

Rich: And so the attacker per, a- as us for a defender, our problem space is, I mean, it's not infinite, but it's, it's close enough for government work that it is effectively infinite as far as we're, we're facing that, that particular part of the problem. So they get to control everything. We don't get to control much because we don't get to decide what technologies the business use, uses.

Rich: We don't get to decide when vendors discover and issue patches to their products. We all rely on all these third-party products. We have all of these things that we don't get to control on our side. We don't get to control the next M&A that now our attack surface is increased by, or our protect and our attack surface is increased by 10% because we just grew 10% by buying and acquiring and integrating all [00:26:00] of this and plugging everything in together.

Rich: So that's that, that structural asymmetry in the math But the objective and what led me to Zero Trust, and, and if the, the original blog post I'm... I call it Core Collapse, has a bunch of this in there. There's a much more detailed paper with a, a lot more in-depth math. Um, a- and it's, I call it pseudo-math or conceptual math.

Rich: You know, it's kind of like the Drake equation for is there life in the universe? It... We don't know exactly, but it's more about understanding the variables and the dynamics of that relationship. And as I was digging in, well, what can we do to make the attacker's life harder on that combinatorial complex?

Rich: And there's some things that are pretty obvious, like if we reduce the number of things we have to protect by decommissioning old stuff that we can't patch and take care of anymore, that is much easier than trying to defend all the different ways somebody could get into it. We just, we aren't very good at that.

Rich: Businesses, we- we're all like, we're all tech huggers, server huggers. We don't like to let our children [00:27:00] go. Uh, but the other thing is, is if I add security boundaries, so from the attacker you get from point A to B to C to D, and D is where their objective lives. If I have serial, so this is the key difference.

Rich: These need to be inline boundaries, not, oh, we have antivirus and we have a perimeter firewall. Those are two parallel boundaries. I need serial boundaries for the paths into that thing on D, then that adds combinatorial complexity for the attacker. Simplest explanation of this. If I put two firewalls by two different manufacturers between the attacker and the thing that they're trying to get to, they, that increases by a power of two the complexity of them trying to get through both of those things together, because they can't get one 0-day, you've got to get two 0-days and two different things, and then the communication pathways in between them.

Rich: So that's kind of what led me to that, "Ah, crap, it's zero day," moment as I was out on that ride.

John: Well, if it's any [00:28:00] help, Raghu has a math degree from Cambridge.

Rich: Oh my God, no. I am on the wrong podcast. Don't read my research.

John: But, but let me ask you too, though, because we get into policy, and I know that that's what you focused on at, at FireMon, because I've, you know, been working with Jody on that stuff.

John: Yep. And one of the problems I see is if I have two firewalls with two different manufacturers, I have, uh- Probably an order of magnitude of complexity in policy management, and we don't manage our firewalls well now anyway. So how would you address that? Because I think that... I mean, I don't know how many ti- I used to do firewall auditing, and I'm w- you know, the third or fourth rule was any, any allow, right?

John: And so you would, uh, there's like you got an expensive box, but it's not really functioning as a firewall. So how do you deal with, uh, policy complexity when you're trying to get that commentorial, uh, [00:29:00] uh, uh, you know, explosion there?

Rich: Yeah, I mean, that's a, the, a huge issue obviously. And so let's do a disclosure here.

Rich: I do still have a financial stake in FireMon. So I got to be clear about that because in my role as chief analyst of CSA, I need to be completely independent and objective. And so I'm going to answer as best I can, you know, with those constraints in place, just so the audience, you know, fully understand. And that's not why you guys brought me on the show today.

Rich: You brought me on because of the CSA stuff, not my former- Right ... role over at FireMon, which is like a year expired at this point. But I do have a, a little bit of a stake over there. Uh, that said, so when we look at policy management, uh, uh, at the top level, one is obviously different kinds of tooling and such are going to help with that.

Rich: I actually think AI can play a very strong role there in terms of being able to analyze and normalize the, the policies a- and explore pathways. I, I've even experienced some of that myself, so I build, [00:30:00] I still build technology here at, at CSA, like our member platform that I'm working on, and I've used AI significantly in terms of analyzing that.

Rich: I've used it to analyze my Amazon policies on various things. So it can be pretty effective for that. Obviously needs a hook in to be able to go ahead and do that. So that's one approach. But at some point, to be manageable, there's got to be some normalization layer and some kind of a normalization technology to look through this.

Rich: So, uh, I mean, that's the work that you guys are doing with my former employer. It, it's all around, you know, how do you harmonize your, you know, your Lumio rules with the physical firewall rules and kind of do those pathways around that. I mean, I think that that's, that doesn't absolutely is not, doesn't go away anymore.

Rich: But as intimidating as this problem is, and going back I think to some of Don's principles- If we can control the scope of what we're looking at at a given point of time. [00:31:00] If we can... We can't reduce the combinatorial complexity of our organization too much. We can get rid of some old stuff, but in the end we still have some of that.

Rich: We can add complexity for the attackers, but reducing the complexity on our side, we can do some of that through simplization, through standardization, but in the end, it's still going to be pretty, pretty high levels of, of complexity. Uh, and again, this leads me to like if we adopt a y- and you, you guys are the, the deep experts on the Zero Trust side, but if we can adopt that from a, a strategic approach to that and manage those rules as policies that get pushed down into the individual technologies at a lower layer, and we can do that within particular scopes.

Rich: So if we start breaking out and segmenting our application stacks more so that it's just not everything talking to everything, and then I have to figure out all those problems. Going back to that firewall example, I do this all the time in cloud. I have... And I don't u- I use security groups. I'm not using firewalls, but I use...

Rich: It's a concept I call the [00:32:00] minimum viable network, where if you only have this connecting to only to this, to only to this, on only those allowed ports and protocols, that really simplifies what you need to understand from that problem. It's when we've run everything through a few big boxes that it leads to that, those higher levels of, of complexity.

Rich: So I'm not sure I fully answered that, because I think I gave you like four different answers. But I do think that having a, a top-level policy approach and abstraction layer that we the humans can define the business rules, and then have that be able to be interpreted at the technology layer using a range of technologies to implement, while also trying to narrow the scope and have more segments, more stacks, as opposed to connecting everything together.

Rich: It's... A- and we, we start with the crown jewels. I'm at, I'm on a project right now with an organization, helping them figure out what are the three most important apps. That was the first question I asked. And then how can we isolate those ones out and build the rules around those, and then use that to start extending further.

Rich: I don't know how that aligns.

John: Yeah, no, it aligns perfectly. I mean, you know, that's step [00:33:00] four, uh, define your policy. And in the book, uh, you know, George Finney's writing about, uh, the Kibler method policy, who, what, when, where, why, and how. That really helps people understand how to create policy. And then Jonathan Flack, uh, who is a CSA guy, uh, but also has done a lot of work in the, in the, uh, in the US federal government, especially the military, is talking about policy-based access control, uh, th- that you can derive out of that.

John: So yeah, I mean, w- I think we're in agreement. We just need to see what are the combination of controls that are effective based upon the thing we're trying to protect. Because too often, and Don said this in another podcast, that most organizations are acquisition organizations that acquire technology.

John: And my point is policy is what's instantiated in products. It would be great if we didn't need-- if, if we could [00:34:00] instantiate policy without products, but we have to have products, right? So it really comes down to policy. The policy is more important than products. So if you don't know what your policy is, how are you going to define what the, the right po- product is?

Raghu: So, from there, Don, I've got a question for you because you have a quote, um, in your section that says, "The accumulation of tactics isn't strategy." Right? Correct. And Don has just said that a lot of companies are kind of just, they just accumulate products. So I'd love for you to connect strategy to tactics, to products, and ultimately to policy.

Don: Go. Okay. Dance. Yeah. Um- In, in three minutes. Okay. Let's first, let's start by understanding what those terms mean. Um, a tactic is, uh, something that is well understood to be good practice, right? So, uh, the, the examples of tactics that [00:35:00] are given that, the chapter, uh, that I wrote are military tactics, things like, uh, ambushing people where you know they're going to be and where you can achieve positional superiority.

Don: Uh, you know, uh, that's, that's a good tactic. Uh, flanking, that's a good tactic, right? Um, tactics are good practices, but tactics alone do not add up to strategy, right? Uh, doing all of the right things and just hoping for the best is not strategy. And to simplify that, um, I actually offered a different, uh, um, analog than the president.

Don: I love, by the way, if you haven't seen John deliver, uh, his, his analogy about the president and protect services, you should because it's great The point I was trying to make about protect surfaces and tactics and strategy is this, uh, and I used a, I used a different analogy for it. Let's assume that instead [00:36:00] of trying to protect, uh, computers, trying to protect services, trying to protect data sources, what you're trying to do is manage boats in a harbor.

Don: And let's assume that every boat in your harbor has holes in it, and they're all different kinds of boats, and they all have different numbers of holes and different sizes of holes, but every boat has holes in it, right? Some of them are, uh, yachts, and some of them are dinghies, some of them are battleships, right?

Don: They all have holes in them. And you, as the harbormaster, as the guy trying to tackle this problem, have only so many hands and only so many patches and only so many hours before what happens? Every boat in the harbor sinks to the bottom. If y- you can, you can determine how you deploy your resources, right?

Don: And a, a really bad choice in this moment would be to take every resource you have and deploy them blindly at every boat that they can reach, right? Just [00:37:00] take every, every bit of patching material we have, every person we have, and just go to every boat and try to patch every hole you can find. That, my friends, would be stupid because you'd end up with the same result, right?

Don: If you, if you only have, you know, 60% of the patching materials you need to patch all the holes, or 80% of the patching materials you need to patch all the holes, and only that number of people available to go do this work in the time that you have, you're just going to end up with a harbor full of sunken ships, right?

Don: So, so instead, and connecting tactics to strategy, where does strategy fit? Strategy is assessing all of those boats and going, "How important are they? How damaged are they? How easy would it be to save this one?" Right? And then coming up with not a list of holes in boats, but a list of boats that you can save, right?

Don: What can I actually keep afloat [00:38:00] given the limitations I have of resources and people and time? What are the boats I can actually save, right? Um, taking... I, I, I find it's, it's good to take things out of technology and just think of them in a, in a, in a non-technical way to explain the concept. That is the concept here.

Don: The strategy aspect of it is picking what you can save. And going and trying to save those things. The tactics are all the ways in which you can save them, right? Uh, you know, all of the, the patches are still the patches. They're the same thing, right? You want to, you want to close every door you can close, right?

Don: And control every risk you can control. Control, cybersecurity controls are simply requirements. Mm-hmm. And there are different ways of meeting those requirements. To your question about acquisition and John's point, government agencies are geared to acquire things, but they're not unique in that regard.

Don: Companies are also geared to acquire things, right? [00:39:00] And too often we think of technology problems as acquisition problems. We think of the problem itself as being, "Well, what do I have to buy?" Right? "What do I have to, what do I have to pay for in order to make this problem go away?" Unfortunately, you can't buy Zero Trust.

Don: You can buy things that will help you get after Zero Trust, but you, the owner of your enterprise, must have a good picture of what your enterprise looks like and, you know, which things are full of which holes and which ones you are going to bother trying to save

Rich: Yeah. Can I jump in? I've got, I think, a related analogy to what you were just saying, Don, which is something that's affected kind of how I've approached this problem, both in terms of the research I'm writing, but also when I'm working directly with members and, uh, because, because some of our members, we engage with them more deeply.

Rich: We actually work with them through these problems. Uh, so my side hobby is I'm a disaster response paramedic, uh, and I've been a paramedic [00:40:00] for 30 years, and I've deployed to things like Katrina, Maria, and other big things, and I've also been a street medic, mountain rescue, stuff like that. And a lot of, uh, what we have learned in that world is, or what I have learned in that world is that human nature is we want to do what Don just said, which is prioritize, figure out the most important things, patch the holes of those first and then look at, and then in the end, maybe you have to sacrifice some other things.

Rich: We see that in a lot of domains. In his example, you see that in military operations, you see it in my side of emergency operations, and I think we see it now, and we always have in terms of technology. What you learn if, when you've done these things for a while in, in kind of more, I'll, I'll call them more stressful environments is human nature is we lose track of things, and there's a lot of different ways we do that.

Rich: We get, um, uh, we get tunnel vision being one of the biggest ones, and not being able to step out, or you don't have all the information you need to make a decision. And so what we do in the emergency services world, and [00:41:00] particularly a- as paramedics, is we train very heavily on algorithms for making these decisions.

Rich: So for example, if there's a mass casualty incident in front of me, if it's small enough, I just kind of run a little bit on instinct, but once it gets to a particular level, we have a, a, a rigid framework, simple triage, rapid transport, and there's, that tells me who are my reds and my yellows and my greens based on three simple tests as I go in to look at an individual.

Rich: It's designed so within a few seconds, less than 30 seconds, you can triage that particular patient and then move on to the next one. But that's like the level one, and then the next layer is, is once you do get to actually treating a patient, we have different layers of priorities and algorithms, and these things are all written down and they're documented and they're drilled and we train on it.

Rich: So let's take that to what we're doing now. I think a lot of the problems that I've seen, and particularly in those, those couple years I was over at FireMon, uh, dealing with organizations struggling with [00:42:00] the complex networks and the policy management and the Zero Trust, which was a lot of what my role ended up being, was that it, it, you get overwhelmed And there's no, like, kind of punch list you can kind of go through.

Rich: John has provided that for years, but there's a difference between reading about it and then putting that into practice or fully ingesting it, fully internalizing it and understanding it. Don, I think that's probably directly aligned with what you were just talking about. And I think now AI is this massive pressure that's forcing us to make these changes more quickly.

Rich: We don't have years to evaluate it to slightly improve or maybe we're going to materially improve, but we haven't been pushed to do that because the stuff we've been doing is largely good enough. Yeah, we still have breaches, but they've been at a manageable level. Now that's probably going to fade away. We have to move more quickly.

Rich: And so I think like for example, one of the things this book can help with and, and other things that probably aren't even developed yet is, you know, let, let's throw those algorithms, those prioritizations out and figure that out. [00:43:00] Like protect surface combined with attack surface is what do I need to defend?

Rich: How do I prioritize that? I mean, I think that's a, like, for example, that's what I recommend to organizations. What are my most important business assets? How exposed are they? What's the exact architecture of those? Boom. Let's start knocking those down in a punch list from top priority to the lower priority.

Rich: What I've run into is running into orgs, and there was one recently, they were doing a big microsegmentation. Uh, I think actually they were using Illumio for this. But they were, they weren't going to implement because they had to model everything first. They didn't just pick something and start. They didn't prioritize.

Rich: Meanwhile, their security director is talking, complaining to me. He's like, "I just want macro segmentation of like isolating these four environments out. Let them still work on their microsegmentation. Let them still work on that larger Zero Trust strategy." But they got so hung up on looking at everything at once and not doing what Don said, that all those boats were sinking in that org [00:44:00] because nobody was like sitting there and prioritizing these three boats matter more than the rest.

Raghu: Uh, and Rich, I think that, that's a really important point that you just made there, and it absolutely reflects, because you can literally divide up or you spoke about microsegmentation. You can divide up like the set of organizations that are doing microsegmentation well and making repeated, and I should stress rapid progress.

Raghu: It's the ones that identify small opportunities for wins and continuously, essentially identify protect surfaces, securing that, moving on to the next one. Boom, boom, boom. Right? And they make, and whether that's macro, whether that's app ring fencing, whatever, they make progress on it. Whereas the ones that sort of say, "I want to do everything all together, all at once," right?

Raghu: Those are the ones that are just constantly spinning the wheels because for them it's like they never get enough data to make a good decision, right? By boiling down that problem to a small set, they have the data that they need to make [00:45:00] d- good decisions to, um, and then to make progress. So Don, I want to come to you, right?

Raghu: Um, with I'd like to un- like just understand in conversations and implementations that you're having today, when it comes to sort of, uh, AI forward organizations, is there any change in the nature of the Zero Trust conversation in those organizations and about the things that they want to protect, their concerns?

Don: There is. And, um, you know, the, what you're alluding to, I, I work at Virtru these days and, uh, I, lead our global public sector solution architecture efforts at Virtru. So that means I'm in contact with people who are getting in contact with Zero Trust and trying to solve it at the level of data, right?

Don: Individual data objects. That is a really heady, hard thing. And as those customers are doing that work, many of them, are, [00:46:00] going through the same evolution that we Virtru are, and many others are in our adoption of AI. there are a couple things to note here. One is, that, that the defender actually does have one advantage over the attacker, and, and it's what George Washington described in describing, uh, the early years of the Revolution.

Don: We win by not losing. They lose by not winning, right? So, the defender has a natural advantage in that, your problem can be made simple and you don't, you don't have to win, you just have to not lose, right? So with that in mind, I would add this observation. We all have a- access to the same frontier AI, and it's not a question of what the models can do, it is more a question of what we can do with them.

Don: An hypothesis that I've been developing along these lines, this is not in this book, [00:47:00] but, since you asked, an hypothesis I've developed here is that there are three things that predict how well or poorly an organization can actually use AI, and it gets right at the heart of your question. Those three pillars are context, AI produces better results with better context, right?

Don: So if we can generate better context and use it more wisely, more efficiently than the people we're competing against, whether that's us competing in a market or cyber defenders competing against their attackers, right? Context makes better results, right? The second pillar is, rules and skills.

Don: We figure out how to do things, but as organizations we need to learn how to do things, right? We have access to the same AI. We can use it defensively, but we can use it better if we do a better job of curating rules and skills associated with how we're actually using the technology we have at our disposal.

Don: The third pillar, which is the one that this book is [00:48:00] about and that, you know, sort of we've been focused on as cybersecurity professionals forever, is guardrails. And, and the, the basic premise of guardrails when it comes to AI and Zero Trust is this The, the frontier model you're using, the agent you're using, the environment in which you're using it must be constrained by things that that agent cannot control, right?

Don: When you give constraints in the form of instructions to the agent or prompts to the model, those are suggestions. We need to apply constraints that the AI can't actually unapply or choose to ignore. If we're doing those things properly, and Zero Trust is how you do that properly, right?

Don: One of the things you have to do is secure the data that the AI can actually reach and read, and secure what it can do with that data in a constrained environment that you control. So we're going through that same evolution now with, with many different entities, and the unique thing about [00:49:00] this moment is we're all learning this stuff in real time.

Don: That hypothesis I just laid out to you, I generated in the last month, and, and after the fact of generating it and publishing that on LinkedIn, I saw an article from Forbes three days ago that basically posited the same hypothesis about, you know, organizations that, that get better at context are going to do better in the world.

Don: Google published an open model for context management based on kind of a prototype of this thought in June, right? And we're talking in September. So this is all happening in real time. We all need to learn, and we all need to learn better, and the way we do that, and the way we use our AI-driven tools to do that will predict our success.

Raghu: So Rich, I want to just connect to that, right? So again, going back to that Mythos Readiness white paper that the CSA published, uh, in, in May, um, and it was [00:50:00] like, it's like every word felt that it was very carefully chosen, right? And there was a very concerted effort to reemphasize the importance of security basics, security foundations.

Raghu: Why did you think that this was the opportunity to do that and to make that clear?

Rich: Yeah, I mean, keep in mind there were 60 main contributors- Yeah ... 250 or so reviewers on that one. And, and yes, I was one of the main primary authors, uh, on it that kind of pulled it all together. Uh, and I can't even tell you how complex the discussions were and Zoom calls and everything, all in the, all over the course of four days to do the first draft of that.

Rich: But in terms of the fundamentals, there was a c- little bit of contention i- in recommending those, because the fundamentals are hard. I mean, uh, I think, like, 15 years ago on Twitter, I said, "Simple doesn't scale," because I was tired of [00:51:00] anytime there was a breach, some, like, you know, hacker, vulnerability researcher come out and be like, "Oh, well, they're stupid because that's an easy fix, and they made a mistake."

Rich: And I'm like, "You have clearly never worked with large enterprises." Yeah. Nothing is simple at scale. And so that's the challenge that, you know, we face. So for me, there was a, a lot of push obviously in that paper around using AI defensively, particularly around code scanning, vulnerability absorption, because that's huge.

Rich: That's a whole huge part of this is never mind the attackers, just dealing with the fact that, you know, Patch Tuesday is now pushing 1,000 vulns with every patch set that's going out, uh, as opposed to, you know, less than 200, which was the average before this. So there's that side of it. But, uh, it, it... I, I just...

Rich: We have to be able to scale our fundamentals, and I also think that means blowing things apart. So going back to Don, you just keep buying a whole bunch of products, and you're just buying a bunch of tools. Clearly, that's not the answer because we're not using the tools we have in [00:52:00] many even large, well-run organizations.

Rich: You know, the big financials buy two or three of everything just to see, you know, maybe it'll work somewhere. It's going to become consistency, simplicity. And so core collapse, the metaphor that I chose for this, the reason I chose that is if you don't know when a star is burning, uh, or when a star is getting ready to explode, and you went to Cambridge, so you probably do know this.

Rich: Uh, at the end, it basically runs out of fuel, and silicone is, interestingly enough, the last stage of fuel. Then it gets to iron, where it can no longer produce positive energy to push out, does not have the force to, the expansive force to keep the star, and then within basically microseconds, the entire thing collapses, and then it explodes typically in a supernova.

Rich: To me, that was a great description of where we are now because we're blowing off all the- stuff that doesn't work. We're [00:53:00] collapsing to the core. That's what we need to do. Segmentation, isolation, security fundamentals. We've layered all this other stuff on because we couldn't get the business to listen to us in many cases, or because vendors were selling us a lot of stuff.

Rich: All of that garbage is getting blown away, and we're going to get to the core of what we need for security, these fundamentals, and we're going to use AI and other things ourselves to help be able to implement that at scale.

Raghu: Awesome. John, question for you before we go to the rapid-fire round. You, um, essentially formulated Zero Trust in 2010.

Raghu: We had the cloud revolution mid-2010s, right? We're in the middle of the AI revolution right now. How have you seen Zero Trust withstand that test of time and evolve?

John: Well, Zero Trust was designed in two ways. One is it's strategic, so it's designed to resonate up to the highest levels of any organization as a big idea.

John: But it's... A- and that will, the [00:54:00] strategy part of it doesn't change. But as Don talks about, the tactics will always change because the technology was going to get better and better over time, of course. And so it, it was that decoupling of strategy and tactics, which oddly enough I learned from, uh, working a- as a contractor at TI from another guy who was a consultant, uh, who, uh, Colonel, um, uh, John Warden, who was the chief strategist of the First Gulf War, who taught me what strategy really was.

John: And so it has this strategic component that really, really resonates with people. And so the strategy can, can fit within whatever technology changes happen. And that was, that was how it was planned to begin with, because I knew things were going to change, and they were going to change really fast, and they were going to speed up.

John: I mean, we already had Moore's Law, and now we've burned through Moore's Law. I mean, Moore's Law [00:55:00] is, you know, gone, right? And, uh, uh, but what's interesting, the history of it, I just published a thing, Rich, uh, last week or maybe the week before about my experience with Doom, learning how to do networking because I wanted to play video games, right?

John: The history of, of how we got here is pretty accidental and, uh, and, and not greatly strategic. And I think that that's going to happen more and more. And so as, as, as we see th- this AI stuff come out, yeah, I mean, you're exactly right. Rich is on the frontier of frontier AI. Uh, it, it doesn't change the, the fundamentals.

John: There's still attackers, there's still things that are vulnerable, and there's still controls, and, uh, we still can, we still have an ability to win the cyber war.

Raghu: Awesome. All right. We're at almost at time, right? So we're going to wrap with a quick rapid-fire round. [00:56:00] Gentlemen, one word or very, very short answers.

Raghu: I will cut you off if you don't. Right. Rich, we'll start with you. One word you'd retire from the Zero Trust conversation. Complexity. All right. Don, what's more dangerous, an unknown vulnerability or an unknown path through your environment? The latter, definitely. Unknown path through your environment. Okay.

Raghu: John, to you, what's one thing AI changes about security and one thing it doesn't?

John: It changes our ability to look at the telemetry coming in and make the system better, and the, the thing that it doesn't change, it does- it doesn't change the relationship of an attacker getting, - access to something to attack.

Raghu: Rich, finally, what's a security metric you wish leaders would stop celebrating? Most of them.

Raghu: All right. And Don, finish this sentence, a resilient organization can-

Raghu: Identify how it does things. Ah, love it. [00:57:00] Fantastic. Well, Rich Mogull, Don Yeske, John Kindervag, thank you all so much for your time today, for your contributions to this book and for the wonderful conversation.

Raghu: To all our listeners, the book Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era, um, sort of that John has brought together, features chapters by Don, Rich, and a whole host of other incredible individuals in cyber.

Raghu: The link is in the show notes. Go and grab your copy. Go and check it out. A whole collection of understanding what Zero Trust is, why it's so relevant, and most importantly, the steps, the guidance to put it into practice in your organizations today to build more resilient organizations. Thank you. Cheers.