Enhancing Network Security with AI and Zero Trust Principles with Rich Mogull | Black Hat 2025
Rich Mogull, SVP of Cloud Security at FireMon, discusses the importance of security in Vibe coding and shares insights from his career. FireMon focuses on security operations, introducing a new Insights product that analyzes firewall usage and compliance. The role of AI in automating firewall management is highlighted, along with an integration with Illumio for better rule management. The session concludes with a discussion on Zero Trust principles and resilience in network security.
Transcript
Hey everyone. Welcome back here to Techstrong tv. So we came off of that crazy show floor to our luxurious broadcast suite here at the Luxor Hotel.
MGM Tell My Wife I love her. Yes. Um, but thanks for joining us in our continuing Black Hat 2025 coverage.
My next guest really needs no introduction to, to security people and, and, uh, our audience at Techstrong. It's my friend Rich Mogul. First of all, rich, welcome back to Techstrong tv.
Thanks. Thanks for only the best for you, rich. Only the best.
But, um, thanks for coming up and being with us. I appreciate it. Rich.
Of course you're at Fireman. Yep. You Know, I forgot your title is a VP of Cloud, SSVP of Cloud Security.
You Got it. That's P of Cloud Security. The S is for special.
Well, you know, I wrote an article last month. The S in Vibe, in Vibe coding stands for security. And you know, that brings me up.
Remember we did a podcast once with the CEO of Mongo Dp. I will never forget Me. I bring it up all The time and I talk about it all The time.
And why not is this is no sequel, mean no security, and they said We'll have security when our customers Was their answer. And then everybody got breached and then they added security. And I think the same thing's gonna happen with Vibe.
Yep. Coding Agree. When people start demanding security, they'll do something about it.
But until then, as I said, the s in Vibe coating stands for security. Um, but Rich, you're at Fireman as we mentioned, but of course, if you know Rich Long distinguished career as a Gartner analyst covering the, uh, Data security DLP DLP space. Yes.
Yep. That, that, well, those were my days. Those were my years.
DLP and stuff like that. And then of course, rich and our good friend Mike Rothman went on to found, uh, Securosis. Yep.
Uh, kind of reset, broke the mold in security analyst firms over the years. And then you guys, rich, you were the primary driver of, of a product vision that that came out and that's how you came to Firemont. Yeah.
So they, uh, acquired our startup Disrupt ops about mm-hmm. Three or so years ago. And, uh, yeah.
And then So it's been a ride. It's been a ride, my friend. It's, uh, yeah.
Any little corner of this industry you could hit. I've probably, I I'm hard. Well, you know, I always like to think it's a round room And there are no corners.
But you're, you're right. We've been there. But you, you wanna know the nice thing coming to Black Hat?
Our next guest is in the green room waiting for us here. Fred Wilmar. I've had a chance to meet so many people and you've met more, you know, more than me.
And, but we've met so many people and you come to this or you come to an RSA maybe twice a year we get together and, uh, it's good to see these people. I mean, some of these relationships are 20, 25 or more years old. I've Known you for over 20 years.
Absolutely. I'm ashamed to tell you longer than that, my friend, because I think the first security bloggers network was over 20 years ago. Party.
Yeah. I think it was 2003. I, I'm bad at math.
No, I know. Well, I, it's easy 'cause we're in a 25 year, so it's easy to say what 25 years is, right? Yeah.
But next year it'll throw me off. Anyway. Hey Rich, we're here to talk a little bit about Fireman, though.
I think most of our audience knows Fireman, but for those who maybe aren't, why don't we start there at that 50,000 foot level? What, what is Fire? Yeah.
Fireman focuses on security operations, and the area that we're most focused on is network security policy management. So NSPM is the core product. Uh, we do also have, uh, my old product, which is a cloud security posture management product.
Uh, we have an asset manager product as well. Okay. And if you have really large complex, uh, it doesn't need to be really large.
If you need to manage firewalls from different vendors, different environments, make sure those things are all compliant, uh, fireman is kind of the best at that. Yep. And just, you know, to serve as a cybersecurity historian, fireman, of course, was spun out of Gary Fish's.
Yep. Fishnet Security. The CTO of Fishnet was a guy named Jody Brazil.
Yep. Brazel. And, and Jodi, they spun it out as Fireman.
And Jodi was the first CEO he left for a while, but he came back. He's still CEO. Yeah.
So it was, uh, it was a pretty wild story. So Jodi, I, I invented it basically because he was doing these consulting projects and he did the, let's see if I can automate myself out of a job. Mm-hmm.
And he came up with ways to do automation, connected to all of these different firewalls and have this consistent policy enforcement went to Gary. Gary spun it out. So Jody was, he was the tech founder.
Everything became CEO. Now, when he left, after some, I guess some external investment years later, uh, I was his next startup. So he was my co-founder of Disrupt ops, uh, him, Brandy Peterson, Mike Roth, and Adrian Lane.
We all founded this company, disrupt Ops. And then Fireman acquired Disrupt Ops and it was like a reverse merger because Jodi then took fireman back over again. Right.
It's an, it is an interesting story, but, you know, if politics makes strange bed flows Yeah. It, security stories are constantly, you know, strange. It's a strange industry.
And circular. And circular. Right.
Exactly. No corners. Um, but Rich, I, I, you know, speaking of network policy management and I, I left a a an A, uh, an initial outta there, didn't I?
It's NSPM Network Secure. I worked Security Policy Manager Management. Yep.
Fireman recently put out a report. Yep. Talk to us.
What's it about? So, Uh, we had this new product called Insights mm-hmm. And well, you know, kind of product kind of feature.
So we actually leveraged some of the stuff that I had done in cloud as the base platform for this or me, our team. I mean, it was 30 people when we get acquired. But, uh, the insights product for customers that are willing to share the it, um, use this, it uses their data and does analysis to help them optimize their use of their firewalls.
So it gives you all this really wild reporting and stuff that nobody else has seen before. Well, we found out that there was, uh, some interesting things that we didn't even know because historically we've got our little silos of customers here, here, and here. And we had a way to look at kind of the data in the big picture.
Now again, all privacy preserving customer driven, like let's, let's be careful we're not stealing our customer's data, but we found that like 90% of firewalls had, uh, critical policy failures. And what, what do we mean by that is it's a compliance failure, uh, and obvious compliance failure. And it can be anything like somebody left Port 22 open where that shouldn't have been.
Or, uh, clearex protocols where it shouldn't have been or, or anything along those lines. So those policies, and, and there are standards around, like PCI, for example, we map those specific firewall rules to what PCI requires. And there were that the high degree of failure, but then there's some, or sorry, it was 60%.
I'm gonna cheat and pull my numbers up. 60%. Okay.
The high severity compliance checks, the 90% is actually 95% of numbers, uh, falling Short of critical levels. Yeah. Well, it wasn't even that.
It's like inefficiencies. So 95% of the application objects that people define, so you can define application objects in firewall rules weren't used. Right.
So your turn on your burden CPU cycles, you have these bigger complex policies that are gonna be problematic to deal with. And, uh, and You're not point in compliance that you're not secure. Yeah.
So here's what I find not fascinating, revolting that, you know, I've known about fireman since he spun it out. Yeah. I remember going to Kansas City Yep.
Talking to them. Um, and we've had firewalls, next generation, firewalls, web application firewalls, this firewall, that firewall. We've had companies like Fireman and, and some of their competitors back in the day two fin and, uh, I forgot the other one.
I forget 'em all, But whoever they are, but, you know, that have preached firewall policy management religiously for 15, 20 years. Well, It's in every audit and every assessment. So why, why do we still deal with this?
Why are we still, it's ai help me. Yeah. Right.
I mean, can AI automate this once and for all? I mean, and we actually have some of that available in insights to help you, like explore your environment. So we have an AI chat bot up there, uh, which you didn't even know when you asked me the question, but the, it's more of, um, so this was new to me.
Like even though I've been in security forever, I haven't really dug into firewalls too much. And, uh, after the acquisition, even though I'm very cloud focused, uh, some of what I had to do also began having to focus a lot more on the network security angle. Specifically.
There's so many reasons why. One is like somebody will put a rule in to get something working. Mm-hmm.
They'll forget to take it out or manually trying to manage these rules in these heterogeneous environments. If you have, you know, checkpoint IMP Palo and Cisco and Fortinet, and a lot of organizations do, and even they try to standardize on one, then they're gonna acquire or have a merger or something like that, and they're gonna get other ones out there. So it's just creates all of these extra levels of complexity.
The other is, is when you're dealing with these at scale, the process of manning managing those rule changes and pushing those out to where they need to be, like, it blew me away. How much goes into that? There's organizations that literally have dozens of people dedicated to just managing firewall rule changes.
And it's not an exaggeration. I, I was like, wait, you have how many people? And I'm like, don't you have any automation?
They go, yes, this is after the automation. These are all the exceptions. 'cause some of these orgs just have these, you know, incredibly large, complex environments.
Oh, Absolutely. And then the mid-size, they don't have enough people to manage what they do have. And that's also been a problem.
Yeah. Forever and ever. Right.
But that's why we love the insights because that is exposing information to them. That was, that data was al always there. But within the, the market, like we weren't providing that in a way that was like impactful.
Like, you can go to your CEO go, we're failing 60%. I mean, that's the average in the report, not the 90, I said at first. Right.
The 60% we're failing 60% of our compliance checks, uh, you know, that are higher above. Mm-hmm. We're, we have 95% of our application objects aren't even used.
Like that's just wasted space and added complexity. Yep. So that's the kind of stuff that was like the, I'll, I'll be honest, when our team saw the results, they were like, oh, this is really good.
Well, it's good for fireman. Right? But well, yeah.
It's bad for what's going on out there. I think you pulled the 90% number, 60% of enterprise enterprise firewalls fail. High severity compliance Jack.
Yep. Another 34% falling short at critical levels. Yeah.
So that's where you probably got 90, 95%, 94%. I wanna pivot if we can a little bit. Recently Fireman announced an integration with Illumio.
Yep. The Zero Trust. And of course Ilum Illumio is the leader in the segment network segmentation market.
Let's talk about that. Yeah. So, and that was, uh, actually what one of the things that I was involved with.
So that was, uh, kind of the products that I work on with the Illumio integration. So we're not releasing all the specific technical details around this, but when you're using these microsegmentation products and you have traditional firewalls and other network security controls in your environment, uh, there can be conflicts. So a lot of time, the reason an enterprise is gonna bring in I lumio is because of, uh, a couple of different things.
Maybe not enough firewalls, or they need deeper segmentation, you know, and there's cost effectiveness becomes a factor there. Uh, you can't necessarily drop boxes everywhere in. And then there's also the additional layer of what products like Lumia are good for is they start giving you a better ability to manage rules based on what something is.
As opposed to firewalls, which were designed purely to protect a good network from a bad network. Well, the problem that you can encounter is that for products like I lumio at work, they have to have agents everywhere. And so there's a couple of different layers of issues where you, you can potentially run into issues.
One of those is, uh, imagine you are a hospital or manufacturing or other facilities. You can't always install agents on everything. Mm-hmm.
And so you're still gonna need the firewalls to provide the rules, uh, around protecting those objects. But you still want it to work well with Illumio. So what we've done a lot of the, and as we announce more about this, get out more details, but it actually can glue together the firewalls and illumio in intelligent ways so that they can actually be more compatible.
The other issue is, is what if you want your, uh, illumio assets to talk to each other, but you've gotta get across the firewalls. And sometimes that can be a problem as well. Sure.
So those are like the two most common problems that we've kind of built this to, uh, go ahead and be able to address. And, and that's why it's great 'cause we can get to the asset level, attribute level security, and we can do it with your existing firewalls and then, and have that also work with the microsegmentation with the Rail. Got it.
Now look, it's a zero trust play. Yeah. But we should also mention it.
It is, uh, it's, it's about resilience too. Yep. Right.
And, and that's a big thing, right. You know, people may not associate, uh, network security, uh, posture manager NSPM with resilience, but that's part of the resilience model, right. Is try to contain Yeah.
Where we, where we, where we're threatened, where something goes on, right. So we don't lose the whole ship. Yeah.
Being able to respond more dynamically. So there's that security, resilience play, and then there's also the resilience of what if a firewall goes down or this goes down or that goes down and being able to actually, you know, have the ability to like update your environments to account for those kinds of situations. Yeah.
And, and it plays into the zero trust thing, which I, I think is finally, you know, with all due respect to John Kinder, that guy I was talking to John a couple weeks ago, a lot of people poo-pooed it and gave it a hard time, but it's really become part of the Concept. Every, every company I talk, like I had to do a bunch of research for our new products that we're working on. And uh, it blew me away that they all had some kind of zero trust initiative.
Yeah. It's, it's the way it is. Yeah.
It's the way it is. Anyway, rich, I think we covered the topics that our corporate overlords have, uh, asked us to, to cover. Is there anything else that we missed, you think or?
No, it was, uh, I mean pretty good. The, uh, you know, tying in a little bit back to the zero trust piece of it too. The part is is I like, like you, I I poo-pooed some of the early stuff.
Mm-hmm. Let's, let's be honest, we all did. Yeah.
And, but I've come around on it because, uh, particularly now, 'cause we have all this complexity, uh, that's been added to our networks with cloud and with containers and, you know, ephemeral, virtualized assets and everything else. And like a lot of our security models just haven't worked for that on the network security side because it's port protocol source destination. And as somebody who's very cloud centric, this has been the, I had forgotten how much harder a problem.
It's in a data like cloud. I have a lot of capabilities. I can do all these.
Well, you thought, and that's funny. 'cause initially we thought we didn't have that in the cloud. Right?
We didn't have enough control, we didn't have enough insight, we didn't have enough ability to manipulate what we needed. But now you're saying, you know, I'm so used to doing that, that this stuff in the data center is a lot harder. It is a lot harder.
But some of those principles, like in cloud, I can very easily write rules that refer to the assets or the attributes. I mean, that's a really powerful part of this. Mm-hmm.
Like this asset with these tags connect to this thing over here. And those are things that we have really struggled intensely with in the data center. And so, you know, either with our, you know, bringing that asset intelligence and doing it in a way that works for enterprises, like that's a big part of all of this is, is really easy to show this stuff off in a lab.
Agreed. But you go into some of these large, It's a real world and Our clients are huge. Some of these environments.
Oh, I, I remember that. I mean, I, you know, I know the firewall story. What, what freaked me out and when I first became from really familiar with Fireman is you had customers who had dozens, if not hundreds of Firewalls.
Hundreds or thousands is not uncommon. Yeah. It's crazy that have to be manage and now in multiple locations.
And now you've gotta layer in cloud capabilities, like understand the cloud network and then harmonize the cloud network with the on-premises network. Um, because you've got all this hybrid stuff that needs to talk to each other and yet in the end, we want this thing to talk to this thing and not talk to this thing. It's A relatively simple thing, right?
Yeah. And so that's where like this lumio partnership and other things that, you know, come out someday be being able to have more of an ability to kind of make those decisions, uh, and have that, that higher level intelligence so you're not down to a five couple firewall rule anymore. I Get it.
Hey Rich, we're about outta time. I appreciate you coming up here to the thanks for having Taj Mahal. And, uh, Am I allowed to leave?
You know, you just, you gotta see why is there plastic? Yeah. A corner there?
Yep. We're gonna edit all this out, guys. Um, just make sure you stop in the bathroom.
Wash your hands real good. Okay. Rich Mogul Fireman here at Black Hat.
We're gonna take a break. We are going to continue with my friend Fred Wilmont coming up next on Textron tv.