Hacking Microsegmentation for Machine Workloads

Hacking Microsegmentation for Machine Workloads

Hacking Microsegmentation for Machine Workloads

Overview

Traditional microsegmentation relies on network controls like IP addresses, subnets, and firewalls, a model that is poorly suited for the dynamic nature of machine workloads and OT environments. In this discussion, David Spark, Howard Holton, and Galeal Zino explore the frustrations of implementing legacy microsegmentation and why a shift toward identity-first, Zero Trust connectivity is essential for securing modern, interconnected systems. They examine the risks of flat networks, the challenge of securing API-to-API communication, and how a true Zero Trust approach reduces blast radius and simplifies administration.

3 Key Takeaways

  • Legacy Microsegmentation is Flawed: Relying on IP addresses and firewalls for microsegmentation creates complexity and fails to provide true security, acting more like “spilled milk” that cannot be contained.
  • Machine Workloads Demand Identity-First Security: Machine workloads, including AI agents and API connections, require dedicated, verified identities and strict policy enforcement, not just broad network access based on location.
  • Zero Trust Must Reduce Blast Radius: A successful Zero Trust implementation must fundamentally reduce the blast radius and avoid trusting any element within the stack, focusing on explicitly authorized connections rather than assumed trust.

FAQs

Why is network-level microsegmentation ineffective? Network-level microsegmentation relies on IP addresses and firewalls, which do not accurately reflect identity and are difficult to manage in dynamic environments. It often leads to complex, brittle rulesets that fail to adapt to modern workloads and can easily break production environments.

How should organizations secure API-to-API communication? API-to-API communication must be treated as application-to-application access, not just human-to-application access. This requires explicit authorization, dedicated workload identities, and continuous verification, rather than assuming trust based on network location or shared credentials.

What is the core principle of Zero Trust according to this discussion? The core principle of Zero Trust is to reduce the blast radius and assume that everything within the technology stack could be compromised. It requires authenticating and authorizing every connection based on identity and policy, rather than relying on network perimeters or assumed trust.

Transcript

David Spark: Howard Holton help me out here. Give me your pet peeve when it comes to, microsegmentation.

Howard Holton: Mmm, it’s a good question. It’s also kind of a tough one because microsegmentation’s been around a long time. But I actually think my pet peeve is, early microsegmentation sucked so bad that it’s hard to get people to listen when you talk about microsegmentation in…

David Spark: Could you think that’s burned in their brain, the early version of it?

Howard Holton: I know it is cause it’s the most common feedback that I ever get. I’m a big microseg fan, and it’s the most common feedback I get is, nope. We did that before, we’re not doing it again. It was too complicated, it was a waste of money. And I hate that feedback cause it’s just wrong.

David Spark: All right, we’re going to change minds today. Your number one pet peeve, Galeal, for microsegmentation.

Galeal Zino: That one’s difficult to beat. I have to agree and disagree though. Um, for sure, I agree with with the start. Uh, I’m not so sure that it’s fixed yet. So if I had to put a pet peeve out there, I would say the vendors are still broken. I’m sure we’ll talk in more detail about that.

David Spark: Okay. Let’s do it. Get ready, it’s Super Cyber Friday. Welcome everybody to Super Cyber Friday. Today’s topic is we teased it already, hacking micro segmentation but for machine workloads. Now we’re going to talk about micro segmentation in general, but we’re really going to zero in on machine workloads. An hour of critical thinking about how to reduce your attack surface from agentic threats because if you haven’t noticed, that’s kind of a hot topic right now and that’s why we’re discussing it. Hey, our guest today, we got Galeal Zino, the CEO of Net Foundry. And your favorite and mine, Howard Holton, founder and principal analyst over at Fronia Council. Hey, our sponsor today is Net Foundry. Thank you Net. That’s Galeal’s company. Thank you so much.

David Spark: Hey, lots of ways to participate. We got our chat room. Submit your gripes about implementing microsegmentation. So if you’ve actually had to do it, we’d love to know what drove you nuts about it. Uh, hey, we haven’t had somebody on camera in a while. If you want to join us on camera and ask a question, make a comment, just say, bring me on. Ask a question of our guest. If you look on the right hand side, there’s a little speech bubble with a question mark in it. I want lots and lots and lots of questions from you. Send me your questions. And vote for your favorite question as well. All right, here’s today’s schedule. You’re going to submit your gripes about micro segmentation. We’re going to play the public interest. We’ll play which password is more popular. You will play for a prize in that second game. Here’s an example of a prize you could win. An awesome CISO series water bottle like that. Or a, or a fleece, something like that. But only one person’s gonna win. By the way, Howard and Galeal, you are competing against them. So, uh, please. I, by the way, won. I think it was last week. And the problem was, it was something it was the, the vendor, the vendor game where we would show the logo of the vendor and it would slowly come on and you have to guess what it was. Yeah, you play, they were all past sponsors so I knew all of them. So it within I was Well you passed on number two. Number two said I had plenty and passed to me, and you just reminded me I haven’t redeemed mine, but I want to make this public and clear. I’m holding mine until there is an adult size onesie. When there’s an adult size onesie, I’m happy to submit.

David Spark: Speaking of that, speaking of that because of one the the the by the way, you know, when I’m done with this, Josh, who is our line producer, please show the the prize list. Um, someone finally bought the onesie. One of, uh, somebody in Houston I know just became a dad and he bought the CISO series onesie. So, very excited about that. Um, hey, our next show in two weeks, uh, because we’re not gonna have a show next week, or no, no, excuse me, I take that back. It is next week, October 2nd. No, yeah, October 2nd, I’m sorry. It’s we’re not having the one October 9th because of the holiday weekend. This is next week. Uh, hacking, uh, your career growth mistakes. So register for hacking your career growth mistakes. You can click on the link at the bottom. That’s for next Friday’s event. If you are permanently registered for all events, you don’t need to click on that link. All right? Cause you’re already registered. But if you’re not registered for all our events, please do click and register. When you do that, you won’t be taken out of the meat. And then the very last thing I want to mention is stick around for our meetup. That link at the bottom will change to our meetup at the end of the show. Um, so, um, you can stick around for that. All right. Let’s get into our topic. Right. I just want to set up oh, there, by the way, there’s the onesie. By the way, thank you, Josh, for throwing up. These are the things you’ll be playing for. They do not have By the way, do not hold out for the adult size onesie. It’s not gonna happen, Howard. But you could get an awesome fleece, you get a sweatshirt, you guys are going to be competing against everybody else. All right, that’s coming up later when we play the password game. All right, let me throw this out. Let me set up the our topic. Microsegmentation. And I’m going to throw it to you first, Galeal, on this one. Just setting up, for those who don’t know, which I’m sure everyone does know, microsegmentation was the whole issue of, well, you know, the candy bar metaphor. Hard on the outside, squishy on the inside. If you just set up a firewall to secure your environment, the second they get through, which they can get through, like with legitimate credentials, then it’s a field day on your entire network and your business for that matter. So up came microsegmentation, which was the idea of let’s create a bunch of mini firewalls all throughout the organization. So you know, if someone doesn’t get in, they won’t be able to move that much. Great in concept, often difficult to implement. So I’m gonna throw this to you Galeal. Galeal, I know you have a history of this. You mentioned some past frustrations. Where let’s just start with let’s balance it. Where were the successes and where were the failures with microsegmentation?

Galeal Zino: Had a customer recently put it this way, David, Howard I thought it was quite good. Which is, you know, listen, we and this is an OT, but IT’s not that much different. Uh, you know, we do a limited number of upgrades a year for a reason, right? Maybe in OT, maybe you do four, maybe you do two, maybe you do one. Why? Because uptime and human safety are more important than anything. Um, and so the way he phrased this was, hey, like, listen, if I’m gonna do a micro seg project, uh, and that is going to be more risk, more perceived risk to my up time, than if I had micro seg, if, then why would I do it? And, and I think that encapsulates it fairly well, because I think, quite frankly, vendors have not delivered a solution, uh, that is going to prioritize actually what the customer cares about, which is uptime.

David Spark: Very, very good point. And by the way, we just did a recording in Houston where this very issue came up. And the question was, can you apply zero trust principles that you normally do in the cloud to OT? And the general answer was no, you can’t, because of what you just said there, Galeal. All right. Howard, my question for you, pros and cons of microsegmentation. What’s worked, what hasn’t?

Howard Holton: Complexity always bites you in the ass. Like that’s the biggest problem, right? Um, microsegmentation, especially traditionally before we had a lot more automation baked into modern microsegmentation, was kind of a bit of a crapshoot. Um, people would get frustrated with the discovery stage. They’d put some micro segments into place, they’d experience, uh, an outage, right? Um, and the outage would be like that thing we only did do once every 30 days we didn’t plan for, right? Uh, it takes something down, something wouldn’t work, it’d happen three times, they’d get frustrated, and then microsegmentation became shelfware.

David Spark: All right. Now, is there anything you’ve been happy with with the round mic segmentation?

Howard Holton: I’m I’m actually pretty happy with kind of the direction like I’m glad some of the vendors didn’t give up on microsegmentation and kind of went through the dark days of the technology and and kind of emerged and integrated, um, some automation and and better visibility and observability into the system. Um, and really started taking the tack of like, eat the elephant one bite at a time. Zero trust is about reducing blast radius. Microsegmentation is a great way to reduce blast radius. In order to make that work, it actually has to be healthy and successful. So don’t try to do it all at once. This is an ongoing program and do it that way.

David Spark: That’s actually some very good advice. Right, we got tons of great questions. And by the way, thank you to the audience for throwing your questions in. Here comes your first one. Which is easier and or more effective to implement, and I’m going to totally throw it to you on, Galeal on this one. Application level microsegmentation or network level microsegmentation? And maybe the answer’s both. Your thoughts?

Galeal Zino: Network level is dead on arrival. Uh, it’s an oxymoron to begin with.

David Spark: Well that’s how it was introduced. Correct me if I’m wrong, yes?

Galeal Zino: I I think I might be in the minority here, but I I think it’s still, and I’m, by the way, I’m a, you know, I’ve been doing network engineering for 30 years, I still think it’s dead on arrival. The reason is, you know, even if I think about your candy bar analogy earlier, David. Um, you know, it’s spilled milk, right? It’s spilled milk. Uh, and you can’t put it back in the bottle. So if you’re going to try to use IP addresses, VLANs, and firewalls to do quote unquote micro seg, I mean, just good luck to you, right? Like it’s, I’m sorry, it’s not going to happen. It’s not going to happen for the most mortals.

David Spark: Because this goes to the complexity issue, right? Too complex is how Howard set up earlier.

Howard Holton: Mm, no. It’s, it’s also dumb. Like, the point is not, um, the point is far greater than just firewalls. The point is far greater than just subnets. Like microsegmentation and segmentation are not the same thing. Microsegmentation takes a deep look at what’s running on the system, who’s authorized to talk to it. And without, um, and layers in automation to make sure that you’re making the right choices and not doing it manually. And if you, if you’re like, well, I’m going to create 437 subnets in my network, and I’m going to create 300 VLANs, and I’m going to turn on host based firewalls. You’ve just created a nightmare that no one is ever going to be able to manage after you, and you failed job number one, which is make sure that the next person can be as successful as you are. Microsegmentation is the antithesis of that. And it just sounds the same on the packaging.

David Spark: By the way, I got more more questions by the way, the legitimate the the the quicker you can answer, we’ll get through more of these questions. Great, please send us more questions. I love this one. And this is right up your alley. Like, this is right up your alley. From Sierra Montgomery. If a compromised workload acquires valid credentials and begins behaving like a legitimate service, which is common, what signal does your microsegmentation architecture use to distinguish legitimate machine to machine communication from lateral movement? That seems like the $64, 000 question. Galeal, your answer.

Galeal Zino: Attestation, attestation, attestation. Like a this is my pet peeve with NHI credentials. And I think Sierra is kind of getting at that. A credential by itself. I’m not I’m not connecting a workload based on a credential cause a credential does not prove if Howard should have that credential or David should or Galeal should or an AI agent should. Um, so credentials, great. I need them. They’re necessary but not sufficient.

Howard Holton: Uh, what.

David Spark: I’m sorry, you’re saying… what was it you were trying to mark to me?

Howard Holton: I like that. I like that question. I think that’s a good question. But as to the last one, like, it can’t both behave as a proper process and be malicious at the same time. Like the question itself has a logical fallacy contained within it on that last question. Right? And so there’s a problem there. Right? If I’ve authorized a host to communicate to this service over this port, which is what I want to do with microsegmentation, then it’s an authorized service acting over that port and communicating with that service. We’re not doing deep packet inspection traditionally in microsegmentation. I don’t know why you’d want to. It’s not the job of microseg. Right? So if it’s accessing an API that it’s authorized to access in the way that it was authorized to access it, it is not a malicious service in that way. If it’s accessing a different service, like if it added an application and it’s an authorized machine and it added, and it’s using credentials but it’s accessing a different service, well, that’s not authorized in the microsegmentation platform and being denied by default anyway. So I, I, I guess I don’t understand. I think there’s a logical fallacy in that question to begin with. But I like Alex’s question. I think that’s a good one.

David Spark: Well let me throw this one. this complaint from Sean Blackwell. And I don’t know so either one of you jump in on this. Complaint, implementation of microsegmentation on infrastructure servers, claims EC. But attempting to implement on developer environments, major pushback due to don’t touch the jewels Internet based company. Galeal, your thoughts on that one?

Galeal Zino: I agree with Sean with traditional micro seg. But I think as both Howard and I are saying, uh, if we look at microseg more as a principle and something we want to attain to improve uptime and reduce complexity, then actually a good litmus test would be what Sean is kind of pointing at, right? Which is, the developer environments would actually be like, huh, this simplifies my life and improves security, right? That that’s a great litmus test on if we can get to that point. I think we can. We just can’t be doing it based on firewalls and IP addresses.

Howard Holton: Let me, let me reply to that one cause I think there’s a logical fallacy there as well. It’s not an Internet based company, it’s an idiot based company. Dev, test, staging, prod, that is the flow. What in the hell are you doing when your dev, your test, and your staging aren’t a replica of your production? It’s not about the family jewels, it’s about if your development, testing, and staging environments don’t look like production, it’s gonna break the second you put it in production. What the hell are you thinking? What crackheads are running that company? They need to look the same. So if you’re doing microseg, also why would you not start with your testing environment and your staging environment? Because you can break things there and it doesn’t break production. If your answer is keep your hands off my dev test staging, only do this stuff in production, cool. So break first and worry about it later? I don’t understand the logic.

David Spark: Yeah, well, you’re right. Okay. By the way, Josh, our producer, please throw up the game. We’re gonna we’re gonna get the game up, but I’m going to ask you a question cause it takes about a minute or two for people to let me, let me reply to that one cause I think I think there’s a logical fallacy there as well. It’s not an internet based company, it’s an idiot based company. Dev, test, staging, prod, that is the flow. What in the hell are you doing when your dev, your test, and your staging aren’t a replica of your production? It’s not about the family jewels. It’s about if if your development, testing, and staging environments don’t look like production, it’s gonna break the second you put it in production. What the hell are you thinking? What crackheads are running that company? They need to look the same. For so if you’re doing micro say also, why would you not start with your testing environment and your staging environment? Cause you can break things there and it doesn’t break production. If your answer is, keep your hands off my dev test staging, only do this stuff in production. Cool. So break first and worry about it later. I don’t understand the logic.

Howard Holton: Yeah, well, you’re right. Okay. Here by the way, everyone if i didn’t go to kahoot k a a h o o t dot i t. We’re gonna be playing uh the public interest first. This one we’re just playing for bragging right. The next game you will be playing for a prize. Um, but uh, Galeal, while everyone’s getting by the way, if you have not gotten in, please uh enter and get in the game because you’re competing against the audience as well. Uh, but while I want you to essentially walk and chew gum here, Galeal, because I’m gonna ask you a question too. As you’re entering that. How does, here from this is from Vivek uh, last name’s uh, is it his name’s not appearing here. Vivek Satarajani. Vivek Satarajani who asked, and this is for you I’m thinking specifically about your platform that foundry, how does a platform alert on a compromised token moving laterally between segments. Is it is this an appropriate question for you, Vivek?

Galeal Zino: It’s a great question. Although we take the opposite approach in that we assume tokens will be compromised uh and architecturally we want to make sure that even if a token is compromised, your service will not be compromised. A token itself is not what’s going to grant access.

David Spark: Okay. Uh, good tip. All right, have you gotten into to the game Vivek?

<BREAK FOR TRIVIA CHALLENGE>

Galeal Zino: It David, for me it says like you’re in. Do you see your nickname on the screen? Is that where I should be?

David Spark: Yeah, yeah, yeah. Then you’re in. You’re in. You’re in. Then you’re in. You’re good. All right, well that’s good. All right, then I’m going to give a ten second countdown on this. And then we’re going to um, oops, here marked on. All right. ten second countdown. We’re going to start the game. Uh, all right, here you go. ten, nine, eight, I see people still getting in, seven, we’ve got a nice crew coming in, six, five. Now if you’ve no nobody’s ever played a uh Kahoot game before, this is the way it works. You are, you are graded on two things. First, be correct, second, be fast. So correct first, second fast. And you’ll see there were scores will go up and uh, we will determine who the winner is. It’ll be very clear how to play this game if you’ve never played it before. Here’s the music. All right, we have four questions. Which term has the most monthly search queries? All right, overlay or topology. I answered, and we were going to see how well any of us did. Now I’m always surprised the number of people who do not choose to play the game and I blew it. Did you blow it too, Howard?

Howard Holton: No I got that one right. I think I was wrong. I mean I think there’s no way I could believe that topology beats overlay.

David Spark: No, but here’s the thing with this game. And I always point it out, there’s always another usage that is just beyond our understanding. Like, it’s like, there’s a nightclub called Topology that is so popular everybody goes to you know you’ll never know. All right, yeah, look at that. So I am the idiot who chose overlay. All right, how’d you do Galeal on this one?

Galeal Zino: Yeah, I got it.

David Spark: All right, good. All right, here comes the second one. Subnet or VLAN. All right, I I’m hoping I’m right on this one. We’ll see. Oh, so I’m thinking just subnets an older, used term. Is it used as much now? I was thinking it’d have like, fat fingers, people searching for sublet. What type sublet. I was hoping to win based on that kind of logic.

Howard Holton: Well the N isn’t right next to the L on the keyboard.

David Spark: I’m a much doubt at it. I was like, where is that ad? I’m on my way to a perfectly incorrect game. Way to go Alex. Way to go. All right, going four for four very difficult on this show. So where are we? So MS we got a bunch of people who’ve gone two for two here. All right. Let’s go. Oh, it’s not even close. Although very little volume. But wait is subnet used that often now? Like, I kind of think it’s like an older, dated term, yes? What do you think?

Howard Holton: Kind of. I don’t know why you’d Google subnet I guess. You might Google VLAN cause you want to learn how to do VLANs but I don’t know why you’d Google subnet.

David Spark: I got that one wrong. I think I’m guessing, this is the way I’m guessing. And I think hoping I’m right. Oh. Yeah, wow, I got that one right. See I guess I was going to go with perimeter, but I was thinking there’s got to be a rapper named like DMZ. And like that’s why it would probably be. That’s what I was planning on some performer with that name. Well. The robot is kicking our ass right now. All right, last one. I’m one for three. Wow, look at how well perimeter did.

Howard Holton: That’s insane.

Galeal Zino: Yeah.

David Spark: There’s so many non-tech uses of perimeter though. That’s that’s why.

Howard Holton: Oh my God. That’s a good one. No idea.

David Spark: I have no idea. I just picked North too.

Howard Holton: We all picked North.

David Spark: South only two people got it. Oh my God, that’s really funny.

Howard Holton: East and West are identical. That’s hilarious. I just randomly picked West. I like that coast better. I don’t know what to tell you.

David Spark: That that’s very funny. All right, good job. By the way, good job to our producer, Rich Straffolino put that together. You’re right, Alex, not run DMC.

Howard Holton: I’m sending Rich some hate mail. That was a terrible question. I hate that one.

David Spark: MS in third. Second two out of four. Wow, look at this. You can get three out of four and you still come in number one. All right. Well the robot wins. How appropriate for today’s episode.

<END FIRST TRIVIA CHALLENGE>

David Spark: All right, we touched upon what you’re doing there at Net Foundry, Galeal. Run DMZ is what you get when you leave North Korea. Good line, Rich. Very funny. DMX, David. RIP. Thank you, thank you. There was another DM and that was not the correct rapper. I’m throwing this to you though, Galeal. I want to get a little bit clearer picture of how Net Foundry is dealing with this and we’re going to get a little bit more into machine discussions. So please tell me, just for our audience so we have an understanding, you quickly, your background in micro segmentation, you’ve been doing it for 30 years, why you started Net Foundry and what is your offering that sort of addresses this issue quite differently?

Galeal Zino: Yeah. I mean starting with the back end of that, the real customer goal here is uptime. Right? You’re not doing micro seg quote unquote, unless your ultimate goal is better uptime, more simplification, these type of things. Um, so number one, we try to align with that North star. And North should have been the winner by the way, in that Kahoot. Um, so we’re going to try and align with that North star. Um, number two, as Howard said, a big part of the problem is it takes too long to try to get to where you want to go. Um, so we try to give immediate results. There’s no reason why if your actual goal is up time and simplification, why can’t we do that for you right away? So that’s goal number two is immediate results. Goal number three, very simple. Avoid firewall surgery, avoid network surgery. Avoid words like subnet, VLAN, IP address, DNS, NAT, SNAT, etc, etc, etc. Um, which David leads backwards into my background, because I’ve been doing that alphabet soup full of acronyms uh for a very, very long time. Uh and it’s really difficult. Uh and it’s great, I was lucky I was a network engineer at the start of kind of the commercial Internet, built a global Voice over IP um service when Voice over IP was like hard to do. Um, became the world’s largest, um which was super, super cool. Uh, went on, did a bunch of similar things in unified communications, and video and telepresence and you name it, APIs, microservices. Um, and eventually, David, got a little bit tired of hitting my head against the wall, which, by the way, that wall was often things like micro seg. Um, and decided, hey, why don’t we try to uh build, uh why don’t we try to tilt the playing field so that the next person who has to solve these problems um doesn’t necessarily have to beat their head against the wall.

David Spark: By the way, you are the classic founder story. By the way, and I always love this. That’s why I ask you where you came from. The classic founder story is I was doing this. I couldn’t do this well. It drove me crazy. I can’t be the only person who has this problem. And then you go make the business for that. Absolutely love that.

David Spark: All right. Let’s get to our topic. Right. I just want to set up oh, there, by the way, there’s the onesie. By the way, thank you, Josh, for throwing up. These are the things you’ll be playing for. They do not have By the way, do not hold out for the adult size onesie. It’s not gonna happen, Howard. But you could get an awesome fleece, you get a sweatshirt, you guys are going to be competing against everybody else. All right, that’s coming up later when we play the password game. All right, let me throw this out. Let me set up the our topic. Microsegmentation. And I’m going to throw it to you first, Galeal, on this one. Just setting up, for those who don’t know, which I’m sure everyone does know, microsegmentation was the whole issue of, well, you know, the candy bar metaphor. Hard on the outside, squishy on the inside. If you just set up a firewall to secure your environment, the second they get through, which they can get through, like with legitimate credentials, then it’s a field day on your entire network and your business for that matter. So up came microsegmentation, which was the idea of let’s create a bunch of mini firewalls all throughout the organization. So you know, if someone doesn’t get in, they won’t be able to move that much. Great in concept, often difficult to implement.

Howard Holton: What should we be looking at, and then how do we measure it? You need to be able to answer the question, what identity can talk to what identity according to what policy and posture? Right? Sounds simple, um, but that’s a really powerful question to be able to answer. Notice I didn’t say IP address. I said what identity can talk to what identity according to what policy and what state. What is the map? What is the graph? What is the what are we actually talking about? Number two, I think that’s metric number one, can you answer that question? Um, and how, how many answers are to that question, how many identities can talk to how many services? Number two, um, how do I deal with when something happens that was not expected? I’m gonna assume breach, I’m gonna assume a problem. What do I do? Where is the kill switch that allows me to take care of that problem without compromising uptime? Uh, without compromising human safety, without compromising business continuity? And number three, finally, I’m cheating, I guess I’m giving three metrics. Um, my third metric is how much of that can I see and how much of that can I govern in a centralized way? Like right in front of me, right? Not by going to N different environments, firewalls, blah, blah, blah, but see it right in front of me. Those are the three those are our guiding principles. We want everyone to be able to answer this.

David Spark: Okay. Is this something that Net Foundry can actually answer, these questions?

Galeal Zino: Yes, we are a part of. I’m not gonna say like we are the only thing. this is not easy, otherwise it’d already be done. Um, but what Net Foundry does hopefully is enable you with both like the North star to get there and a defined path that gives you immediate ROI, immediate simplification and immediate benefits like on day one. Like not day 100.

David Spark: Howard, your response.

Howard Holton: So first I want to I gotta put on my gloves cause I couldn’t disagree more.

David Spark: Okay. Let’s hear it.

Howard Holton: My board as the CISO, what my board said 15 years ago was, we better never get hacked. 10 years, they said, okay, so if we get hacked, when? Today they say, how bad will it be? That is their question to me, that is the question they want me to answer in every board meeting they invite me to. How bad will it be when we get hacked? So what is the metric I need? I need to know what is the effect microsegmentation has had or any other cybersecurity technology on how bad it will be when we get attacked. And how do we know that for sure? And that doesn’t mean you have to get down into the nuts and bolts. It can simply be, before, our network was a wide open space, it was the candy bar analogy. Today, we have created 47 restricted blast radiuses. This is how we know they work. This is how we pay attention to it. This is how we manage the notifications. That’s the reduction.

Galeal Zino: By the way, I don’t think your two answers are I don’t think your two answers are in conflict here though.

Howard Holton: No, but but but I don’t want any of the detail from Galeal, as the CISO, I don’t want any of that detail. I literally want to know what is the change in how bad will it be.

Galeal Zino: But hold on. This brings up a good point. You may be answering the two of you may be answering the exact same question for two different audiences. Correct me if I’m wrong, Galeal, this is a question you answer for yourself, what you answer for yourself and your security team, correct?

Galeal Zino: Correct, and, and I like the way you just actually articulated it. Um, I think that’s exactly what it is, right? Assume that you will be hacked, because of course you will be, and you might already be. That’s the whole point of microsegmentation. It’s, you know, blast radius. Go on, Galeal.

Galeal Zino: No, no, same page.

Howard Holton: The only reason I say it that way, I get one slide as a CISO. That’s what I get to my board, I get one slide, I get like five minutes. They really don’t want to talk to me, they really don’t want to hear me, and they’re tired of me asking for more money. The way I get more money, the way I kind of unlock the budget that everyone on this call needs, I make that one slide tell them how I’m spending money to make it less bad than the last time they gave me money. Like literally, that’s it. So, so anything you can do to support your CISO to help with that specific conversation is what I want you to think about. And I get one slide. So if you give me 25 bullet points, I can’t put them on a slide. I don’t have space. You know what I mean? So that’s what I, that’s why I phrase it that way. And that’s really what I would love the audience to take away from that.

David Spark: All right. Murad said from Boston, AI agents and LLM powered automation are becoming machine workloads themselves, calling APIs, reading data, and sometimes taking actions. How should you segment an AI agent whose needed connections change with each task? Oh my God, that’s a good question. I’m throwing this right in your face, Galeal. Answer this.

Galeal Zino: Yeah, I love that question. Uh, AIs like in a sense are non-human workloads, in a sense they’re human workloads or something new. So first things first, let’s not try to take our old bag of tricks and apply them to agentic flows because they are different. I think if we’re successful, then we treat them as identities which have a certain map or graph that we define what those identities can talk to under what conditions. Uh, and we have the visibility and enforcement and evidence uh to make sure that they stay on that graph.

David Spark: Okay. Anything to add to that?

Howard Holton: I think the answer is, it’s, you’re by default making it more complicated than it needs to be, and it is likely, if you try to design something that is too entirely flexible, what you’re going to end up with is opening yourself up for AI chaos in your network. So think about the use cases that matter, and actually microsegmentation is a great way. We think about it, we’ve determined this is a valid use case for AI, we’ve now added that capability on our microsegmentation platform to AI’s capabilities. If you do it the other way around and hope that your microsegmentation tool set is going to keep up with your AI, you’re basically saying I want micro seg to follow my chaos monkey. Do it the other way around, use microsegmentation to restrict the chaos monkey, use your discussions, your policy changes to then allow AI to have the access that it needs. Cause by default it doesn’t, it’s going to be a chaos monkey.

David Spark: All right. From Philip Group, bonus points for anyone who can actually identify the individual. Whose idea was it to make OT interconnected to the insecure public internet?

Howard Holton: That was me. I’m terribly sorry. Um, I just, you know, I had three margaritas at lunch and then two martinis and just decided hey let’s see what this looks like. I don’t know the answer to that, but yeah.

Galeal Zino: It might be even worse, David. Um, is who decided to give other than some cool dystopian novel that we read after a few shots of whatever Howard is drinking, other than that, since when do we take an AI agent and say, hey cool, here’s some API keys, here’s the internet, here’s some enterprise resources, go do something useful.

Howard Holton: Oh, I see that like 40 times a week. It’s not good, it’s never good, but I see that pattern actually over and over and over again.

David Spark: All right. This question from Dustin. I very much like here. And I would love my hope is you’ve got a good answer for this one, Galeal. From Dustin Sachs. What can microsegmentation teach an organization about their environment early that they will regret not having known when they get to the end of the implementation? So essentially, what do we learn about microsegmentation in a nutshell?

Galeal Zino: So if you do it the classic way with networking and firewalls, I’ll tell you the first thing you’re going to learn is your firewalls can’t handle it. You will melt your firewalls. Uh, and so then, and by the way, your firewall vendors are really unhappy about this, then you need more vCPUs, you need a different version, you need an upgrade, or you need more an ELA, right? And that’s getting worse because of agentic. Because the reality is, forget about the names, for the most part, we are doing macro segmentation type rules on firewalls. Even that was freaking painful. Uh, now with AI and the connections between OT and the internet that we just talked about, now you really do need to do micro seg on your firewalls. Guess what? You cannot do it, it melts the firewall. That is the first thing you will learn if you try to do it the wrong way.

David Spark: Here, by the way, I’m going to jump to this question right here. I’ll let you answer this one first. From Michael Williams, So what is the best enforcement method? Passive policies? An active approach within the networking layer? I gotta assume active, but I think there’s a I think it’s more or the question mark. Your thoughts, Howard?

Howard Holton: I mean, it’s it’s or the question mark, right? Microsegmentation is neither of those things. It’s not passive policies. Your policies have to be active policies, they have to be working. You might do passive policies to do some data gathering, but then the active approach within the networking layer, I don’t think that’s accurate because it’s actually an active approach within the networking layer, the data control layer, and the application layer. So I’m unsure right, I mean, Galeal, you might have a different kind of view of it, but

Galeal Zino: Yeah, I’m with you there, Howard. I think, you know, the first what’s behind Michael’s question there, I think, first of all, if you’re trying to do it as a day two, back to our like the milk is already spilled, um, good luck to you. Um, it’s really not gonna happen. Um, so secure by design was like the term, Howard, that first came to my mind when I saw that question.

Howard Holton: Oh yeah, yeah, yeah. The problem with trying to do it in a firewall, I really like your hardware approach, but it’s also, great, you just get hit by an affordable bleed. The firewall has now been bypassed, so have all of your rules. Like, we’re supposed to build security as a layer of Swiss cheese, right? Because everything has holes, nothing is complete. And if one thing gets compromised, you have all the other layers to make sure that none of those holes go all the way through the block of cheese. So why would you burden your firewall with that extra work that it’s not really good for, it was never really designed for, and is going to melt it, but also adds a huge amount of capability weight and security weight to a tool that sits on the very edge of your network and is likely the first target to be attacked when there’s anything new, any new zero day that could potentially attack it? Right? You lose that layer, you’ve just lost the entire control plane.

Galeal Zino: I love that framing, Howard, right? Because the job itself changed in the meantime, right? Like there’s more non human workloads, forget about even pre AI, but even as we speak, right? There’s not a human at the other end of all those workloads that’s being filtered by that firewall, right? Most of those workloads are server to server and now they’re going to be agent to agent. So to me the whole job.

Howard Holton: Application to application. As soon as we started talking about APIs, right, we made that change. The second APIs became important, we stopped thinking about human to application access and we’re talking about application to application access. And the second that happened, if we didn’t fundamentally change to adopt that, we broke. And then AI, and unfortunately too many people are talking about AIs as another application, it is not another application. It doesn’t look like another application, and when you dig in it doesn’t act like another application, nor does it act like a human. Right? So if you were already behind and all you thought about was human workloads and you never really got your arms wrapped around application workloads, now we’ve added AI and if you listen to the common talk, they’re going to make you think that’s another application workload, which is just another failure domain, right? It’s another path to failure and destruction. It’s kind of a scary time, really, and we’ve got to move and we’ve got to get our act together and we really, if you just focused on the fundamentals, I think you’d be in a good place to accept this and then move forward, but we don’t like messing with the fundamentals.

Galeal Zino: And Howard, I’ll, you know, it’s a Friday too, right? I’m optimistic anyway, right? Like, I’d like to think AI gives us a good reason to leapfrog, right? And we have to kind of redo everything quote unquote to a degree, right? Maybe we can do it the right way this time. Maybe we can take more of a secure by design approach where the litmus test is, as you said earlier, the litmus test is, it simplifies our life, not makes it more complex, and it makes things more secure, prioritizes uptime and business continuity. Like I don’t know, maybe I’m being too optimistic on a Friday, Howard, but I think we can use AI as an opportunity to do things the right way.

David Spark: I totally believe that. All right. Let’s start wrapping up here. The question we are talking about here is hacking microsegmentation for machine workloads. What was the critical issue we have not talked about with regards to microsegmentation around machine workloads specifically that we should have been discussing?

Howard Holton: So, who owns it? Like, I think that’s a big question. The networking team rolls up to the CIO, not the CISO. Security is owned by the CISO. You would logically think microseg probably is a cybersecurity thing and thus owned by the CISO. You really have to answer that in your organization because I’m not spending my budget on your thing, even if it helps the organization, I got my things I gotta spend my budget on, right? And so, like, understanding that in your organization is going to help a ton. And if the CIO owns it and the CISO wants to have his mitts in it, there’s you’re going to create a conflict, a natural conflict. A lot of this stuff comes back to people more than it does technology. The technology is kind of the easier part overall.

David Spark: Very good point. And by the way, I would just say that is also the $64, 000 question around anything agentic AI because putting ownership to it is not easy, and I don’t think anyone wants it either, do they, Galeal?

Galeal Zino: Yeah, I think maybe this I agree with Howard, I think cloud might be a useful point, not that history repeats itself, but you know it somewhat rhymes. So we did get a lot of convergence amongst identity, infra, security, when it came to cloud. If you look at the platform teams at some of these kind of cloud native enterprises and now AI native enterprises, we saw a lot of convergence that Howard is referencing. So maybe that’s where it goes. Maybe Howard, do you see with agentic, though, going a completely different direction? I’m not sure.

Howard Holton: Well, I think we talked a little bit about the most critical things, which is this mismatch between what the vendors are trying to sell, the vendors are hammers, everything’s a nail, right? There’s a big mismatch between that and the question that Howard mentioned earlier that he needs to articulate for his board, which is how am I going to reduce risk, reduce complexity, and, if anything, increase uptime? I would say that David, that is the million, billion, trillion whatever dollar question. I think the second level question is how do we do those things in an agentic world? Because if we answer this question, this micro seg question for yesterday’s world, we’re still going to lose. Like we have to answer this in an agentic world context.

David Spark: And by the way, this we’ve been keep hearing this over and over again, especially like around agentic SOCs too, this whole idea of you just can’t apply the past principles. This is all new principles here, it’s all new.

David Spark: All right, let me do a few slides just to quickly wrap up the show, and if we have two minutes, I’ll ask one more question. By the way, if you have not clicked on the link at the bottom of the screen, do that right now because that’s going to change. We are going to do our post-show meetup afterwards; please stick around. Howard is going to be there, Galeal will be there, and I’m going to be there as well. We can continue this conversation, talk about other stuff. I’m very eager to chat with a lot of you face to face. And we get a lot of new faces in here, so especially if you’re new and you’ve never come to our post-show meetup, you are specifically the person we want here.

David Spark: Let me throw up just a little house cleaning here. Huge thanks to Galeal’s company, NetFoundry. Thank you, Galeal Zino, who is the CEO of NetFoundry, our wonderful sponsor for today’s episode. And our favorite Howard Holton, who is now the Founder/Analyst of Fronia Council. Hey, what’s starting today at 4 PM Eastern is our show Department of KNOW with Dmitri Sokolowski and Kristin Fross of CH Media. It’s a 30-minute show where we look at the past week’s show. In fact, you should all go because Rich Straffolino, our producer, is the host of this show. And if you’re angry with him about screwing up Question 3, you should go and let him know as much as possible. You can tell him live during this show how upset you are!

David Spark: Do you want to sponsor Super Cyber Friday? We have availability in October. That would be Cybersecurity Awareness Month. Ping us at info@cisoseries.com. And I do not want to be remiss—we need to include this slide here: We need a Super Cyber Friday Express slide. For those of you who may not know, we now have a show called Super Cyber Friday Express. This show that you’ve heard, that’s an hour long, gets compressed. We squeeze it down to a 20-minute best parts version. We take out the games, there’s no point in the games in the audio show. If you just want that, and there are episodes you missed and want the best parts version, subscribe to Super Cyber Friday Express. Today’s episode will be up later today. Just go to your favorite podcast app, type in Super Cyber Friday, or go to cisoseries.com/subscribe.

David Spark: All right, how much time we got left? We got two minutes. All right, I’m throwing one question your way. Sorry guys, let me scan quickly… Okay, this is relevant to the ownership question we were asking earlier, from Aman Sood: Who owns microsegmentation policy six months after deployment? I like this one. Howard, I’ll let you answer first, but answer quickly ’cause we have very little time left. Is it the security team, network team, infrastructure team, application owners, somebody else?

Howard Holton: Yeah, it’s the CIO generally, um, but it could be the cloud team if that’s where they’ve attacked first. It could be the networking team. It could be the infrastructure team, but I think that would be much, much rarer. Um, I think the CISO, the security team comes third.

David Spark: Alright, so you didn’t answer Aman’s question, did you? Security team, network team, infrastructure team, application owners…

Howard Holton: Me? No. Security team, networking team, infrastructure team. So it’s the networking team and infrastructure team first and second. Third, security team.

David Spark: Okay, thank you very much. Alright, I’m throwing this to you. Wrap it up, give us your answer in 30 seconds or less, Galeal. Who owns microsegmentation policy six months after deployment? And you can do it in order.

Galeal Zino: Network team, uh, because of what Howard said earlier. The network is the conduit and the enabler of the attacks. It’s also the thing that connects the legitimate workloads. So it’s whoever owns the network.

David Spark: Awesome. Good answer. We can get into more of this later. Guess what everybody? We’re going to wrap this up. Huge thanks to Howard Holton. Huge thanks to Galeal Zino. Huge thanks to our sponsor NetFoundry, and our producer Josh. And to Rich for making awesome games, and for proving that he is not a bot, ’cause he makes mistakes like we all do. We appreciate Rich. Go see his show, complain to him live on the show today. I know he’ll really, really enjoy it. Go ahead and complain to the man. All right, let’s take us out of here, Josh. And everyone click on the link below the screen…