Exploring Zero Trust and AI Innovations in Security with Illumio’s John Kindervag
John Kindervag, Chief Evangelist at Illumio discussing the importance of Zero Trust and its foundation in microsegmentation. The evolution of Zero Trust is highlighted, along with the role of AI in enhancing security and visibility. Common misconceptions about Zero Trust as a product rather than a strategy are addressed. The session concludes with insights on AI’s influence in security and Illumio’s innovative solutions and partnerships.
Transcript
Hey, everyone. Welcome back here to Tech Drunk tv. You know, in our lead up to our, uh, special Black Hat coverage this year, uh, coming at you August 6th and Sevenths.
Um, we're doing a series of, of interviews with what I consider industry titans, industry luminaries, uh, about important security topics that, you know, we, we talk about a black hat. I could think of a better guest to have in that series than my next guest here. Uh, he needs no introduction to those in the cyber world, but I'll introduce him.
Anyway, my friend John Kinder Bagg John is the chief evangelist at Illumio. Of course, he's had a distinguished career as an analyst, a practitioner, and really sort of known as the Godfather of Zero Trust, if you will. John, welcome back to Text Drunk tv.
It's great to have you on. Hey, great to see you Shimmy. It's been been a while.
Been too long, man. Yes, it has. Yes, it has my friend, you know, but you're looking good.
Good for you. Thank you. Thank you.
Yeah. Uh, So John, before we jump into Zero, trust the Black Hat and all these things, look, as I said, everyone knows Zero Trust, and, and if they know Zero Trust, they've probably heard of you, but maybe not everyone knows Illumio and, and some of the great things they're doing. If you wouldn't mind, let, let's just spend a quick minute bringing people up to speed on Illumio.
Yeah. Illumio is a company that, uh, we started, I, I guess about 10, 11 years ago. Um, and they do microsegmentation, which is a key technological need in Zero Trust to create the micro perimeter that defines what we call the protect surface.
A answering the question, what are we trying to protect? So, I've known the company since it was founded. In fact, I did the first ever analyst inter interaction with it when I was at Forrester, and they've been a big supporter of Zero Trust.
And when I had the opportunity to come over here, uh, after looking at what they've, uh, built, you know, over the last 10 years, I really wanted to do that because it, it gives me a way to articulate what we need to do to build zero trust environments. And, uh, there's some really cool technology and some innovations here that we're doing around how we build segmentation, how we create policy, how we map out the transactions on the networks so we have complete visibility, and then how we take that visibility and gain what we call insights from that. So it was a perfect fit for me in this, the, you know, the later, uh, stages of my career as I, as I age out here.
Oh, Come on. The best is yet to come, John. Be Kidding.
We'll see. We'll see. You and I, we go back 20, I was just thinking how long I've known you, man.
And it goes back to the, It's gotta be 25 plus years, dude. Yeah, yeah. Unfortunately.
It goes, it goes back to the still secure days with Raj and everybody. Absolutely. Yeah.
I had, I had black hair, I had hair, period, and it was black and a different world for sure. My friend, um, you know, I remember when Lumio was launched too, John, there was their chief commercial officer. I forget the guy.
He was A Cohen, probably Alan Cohen. Yeah. What a great guy, Alan.
Yeah. And what's interesting though is Lumio was always about that microsegmentation. Yeah, right.
They were really early though. Yeah. You know, and it was almost like a, a, a solution in search of a problem or, you know what I mean, of like what, getting that market match.
Yeah, no, there was a problem and there was a solution. 'cause I had already written about the need in 2010. I wrote the second zero Trust report ever wrote the first one in, uh, September of 2010.
And then November, 2010, I wrote Build Security into Network's, DNA Second Ever Zero Trust report. And I, it was mostly about how to segment networks to create what we now call protect surfaces. And I said, uh, new ways of segmenting networks must be created because all modern networks must be segmented by default.
And so I've been on, you know, on this train for a long, long time because I don't see any way to provide any level of secure transmission of packets without segmentation technology. Yep. I, I, I don't disagree with you there.
You know, John, though, you mentioned you wrote this first one, what was it, September of 2010, you said, right? Yeah. So just coming up here on the 15 year anniversary.
Right, right. Let's talk, if you don't mind, you know, take a walk through memory Lane. This is your life, John.
You know, John, let, let's take a walk through though, over the last 15 years and, you know, how has Zero Trust evolved since that seminal first and second paper that you wrote back in 2010 to where we are today? A lot of it is still right there, right? But the world's changed a little bit too.
Well, I mean, I think the strategic elements of it are, are the same. I mean, zero Trust was designed to be strategically relevant, uh, and, and impactful to the highest levels of any organization. So, you know, grand strategic actors, CEOs, presidents of companies, generals, admirals, those kinds of people.
But it was designed also to be tactically implementable using commercially available off the shelf technologies at whatever state those technologies were in. I knew the strategy wouldn't change, but the technologies would, and that's turned out to be true. So the advancements have been that there's more technology focused on achieving the goals outlined in zero trust of stopping data breaches and, and, uh, designing the network from the inside out so that you have complete visibility into, into what's going on.
And, and attackers don't have places to hide. Agreed. Good.
John, when you wrote those papers back then, did you ever think this, the ZE Zero Trust would, would catch on the way it has and become sort of a standard? Oh, absolutely not. I mean, I'm the most surprised out of everybody because when I first came out, uh, with this stuff, there was, you know, a lot of people would come up to me and tell me that I was completely insane.
I was an idiot. Uh, those were the nice comments, right. And, uh, we've been there.
Yeah. And, uh, but then, you know, uh, some people started to do it, experiment with it, and got a lot of positive feedback. And then some people who were extremely important but are quiet, uh, came out and said, no, this is, this is the wave of the future.
And I remember one guy said to me, you realize zero trust is gonna be your life from here on out. And I said, you're in Talk. No, No, it's not.
I mean, because I was working on, uh, encryption stuff at Forrester. I ran the data security and privacy playbook. I was working on analytics and what is the future of sim and I created the concept of a virtual SOC and all these things.
And so I thought, no, this is just one part of it. But he was right because he had some insight that I didn't have on some of the, some of the, some of the people in organizations who were very into zero trust. They just weren't publicly yelling it from a mountaintop.
Excellent. Excellent. Um, so John, let's fast forward to the last couple years.
You know, you, you can't walk three steps without tripping over some ai, generative egen, whatever's next. Right? Um, how, how is AI helping herding zero trust initiatives across the board?
Uh, it, you know, it actually helps a lot. Uh, I, I wrote a, I wrote a, a blog post a while back, why I'm not losing sleep over ai because everybody else is worried about, oh, ai, they're gonna be able to make more sophisticated attacks. Yeah.
But ai, we're gonna be able to have much better visibility and stop those things before they can ever get there. So it's, uh, you know, I was just up in, uh, Bletchley Park giving a speech, uh, outside of London, north of London. And, uh, I've always been inspired by the movie, the Imitation Game, about breaking the non code because in the Turing Yeah.
In the movie, the ca uh, the guy playing the character of ER says, uh, what if only a machine can defeat another machine? And that has always been sort of an inspiration. And so that's what we're doing.
We're building the machine to defeat the machine. And Zero Trust is the strategy behind that machine, the idea that you use to, to put all the parts and pieces together in the machine. And that's what I was always focusing on, is how can I eliminate so much of the manual stuff going on and automate this?
And so AI allows us to do that. And so while they may be able to make more sophisticated attacks, there's not gonna be policies in place that allow that attack to be successful in properly, uh, designed and, and deployed and maintained zero trust environments. And so those attackers are gonna move on to somebody else's environment that's more of a low hanging fruit.
And that's the key thing, right? Is that, that, you know, we're not gonna, not everybody is gonna do it. So there's always gonna be some soft targets, and those soft targets are going to be attacked.
As somebody in the federal government said to me, attackers don't def defend attack well defended, uh, environments. They just don't because it's too costly. Right.
They have an ROI, so once they figure out, this is hard, uh, it is gonna be expensive, we're moving on somewhere else. Agreed. John, when you look back at the 15 years, and you, you know, in your role at Illumio, you're, you're talking to organizations every day that are implementing microsegmentation network segmentation, implementing zero trust for people out here, let, let's save them some idiot tax.
What do you, what do you see as the most common mistake people use make commit when they, when they try to implement a Zero trust type of initiative? There's two mistakes that are common and typically tied together. One is they think it's a product, so they become very product focused versus protect surface PO focus.
They don't know what they're gonna protect, right? So I buy a product, what do I do with it? Well, what are you trying to protect?
I haven't thought about that yet. Well, you're gonna fail. The second big problem is they try to do it all at once for everything.
And you can't, you have to do it in bite-size, manageable chunks. There's no way, you know, take your favorite consumption metaphor. The, uh, journey of a thousand miles begins with the first step, or how to eat an elephant or, or a, uh, One spoon at a time.
Yeah. The Whole thing. Yeah.
Uh, yeah, the whole thing, right? So, uh, but people get too, too big and, and, uh, so those are the two main things that cause people problems. They, they, they start too big try to do everything, and they think they can buy a product instead of, um, you know, develop out a strategy.
Yeah. I, I don't disagree. I mean, John, we've both been in security community a long, long time.
I would say what the, the first one that you mentioned there about buying it before they figured out how they're going to use it is, is such a, It, I remember did a survey one time, I forgot, was it 27%? Like some outrageous number of security tool purchases became shelfware, actually not became, shelfware were always shelfware. They never got unpacked, right?
Because someone bought 'em. It was a great magic bullet. And then they realized before they could unpack it and install it, there was actually some work that had to be done, and it wasn't the magic bullet that they were hoping it was gonna be.
And, and, and so it just stayed there. And then you ask them, is that solution any good? Oh, no, that solution was terrible.
Well, you never even unpacked it. Right? And, but this is, that's the wacky world of security cyber that we, we come from, right?
So that is, is a big thing. And, and that's why I, I don't call zero trust of product, right? It's an initiative.
It's, it's the whole enchilada. It's people, process and technology. And, and if you're not gonna put that kind of effort into it, don't waste your time, dude.
Right? I, that's, Yeah. And the effort isn't that hard.
Some people think it's no real really hard. It's actually when people get, uh, get, get to a point where they understand it. I, I had one customer call me up and he said, wow, we argued about doing zero trust for a lot longer than it took us to deploy our first zero trust environment.
So that, that's the thing that shocked us. We, we just had to, you know, talk about it, talk about it, and talk about it, and talk about it. Instead of doing a small version of a small, a single protect surface, what I call the learning protect surface.
You know, do something that, that has low sensitivity, uh, early on so that you can begin to learn how to do it. So if you, if you mess up, it's like street basketball, no harm, no foul, right? You ain't bleeding.
Mm-hmm. I'm not calling a flat there. No Bleeding.
Right. We got plenty eyes. Right.
You're Right. We've got plenty eyes. That's Right.
That's all. Yeah. Yeah.
I, I, I, I, I'm from New York. That's how we played there. That's right.
Yep. But you know, it, it is interesting like that, John, we are coming into summer security camp season, right? Black hat Defcon besides Vegas and a bunch of other things in the next week or two.
Um, unfortunately you are not there this year. We'll miss you. But what should people keep their eye on there?
What, what, you know, what, what do you think of the, the themes and things that you, we Should watch? Well, it's, it's gonna be all ai. I mean, the, the nice thing about AI is at least it's, it's kind of taken a little bit of the hype off of zero trust so that pe people can think of zero trust in a, in a more, uh, coherent, uh, less hypey way.
So it used to be zero trust with the big hype now is ai. Uh, so I think, you know, you, you need to look at what you're gonna get out of your AI and what's, what's happening there. And it, and, and, uh, is it really ai?
And there, there's a, you know, my favorite definition of AI comes from a mathematician friend of mine who says, AI is stati statistics plus if statements. And when you boil it down to, to something like that, you can really see, uh, what's happening. But, uh, you, you know, you're gonna see a lot more stuff about how to use AI than protect the stuff that you put into ai.
And that's gonna be the threat to these organizations. Excuse me. The, the threat to these organizations.
We're seeing it already where organizations are using AI and then finding their sensitive data, uh, their intellectual property inside these LLMs, because there's no way to govern them yet. Yeah. Well, we, we, not only that, we haven't figured out sort of the best practices and processes, like, don't blame Theis for this.
It's people uploading that data to the ai, you know, it's, it's always the same story, John. It's the guy behind the keyboard, right? Right.
But That upload sensitive data, That's where the technology has to evolve to the point where it understands what the, what data is sensitive and says, no, you can't upload that because Well, yeah. So we're putting guardrails in, we're gonna do ethical AI to make up for dumb people. Right.
Is that, you know, Uh, yeah. I mean, yeah, and let's talk about that, because I don't know that the people are dumb. I think their incentives are misaligned.
Right? So I talk a lot about incentives, and I've written about that like for Financial Times in London, and I think we have perverse incentives in our, in our industry. And so a lot of times it's like, just get this thing done and get it done fast and use ai.
I hear people are being told, use ai, so they use it and they, you know, they don't, the nuances of how it works, do they understand that when they upload a document to get it analyzed, that it goes into some massive database called the largest language model, that that is somewhere else, and and they've totally lost control over it? Probably not. They probably don't know how it works.
So I think, I think it's not that the people are, are doing bad things or, or, or doing dumb things. I think that, that they're doing things that they're incentivized to do, and the technology isn't there to protect them from getting themselves in trouble. Right?
So it's a lot easier to, to create policy to keep people from getting themselves into trouble than it is to educate them on all of the nuances of all these technological innovations that have been coming down the pike so fast for, for such a short period of time. I, I agree with you, and you know, John, I think I learned in law school a million years ago, generally it takes society three to four years to catch up on technologies. Yeah.
Right? And, you know, we live in a tech bubble. We're both in the tech world.
So, you know, of course, AI is, AI is almost old TA to us already, even though it's only been, you know, two years. But, um, it's gonna take time. It's gonna take time for, I, I learned this when I did the DevOps Institute too with DevOps.
There were no best practices for DevOps. There were emerging practices for DevOps. And I think we're gonna go through a similar period here with ai, especially AI with technology security.
There'll be emerging practices that'll eventually solidify into, uh, you know, truly best practices. Yeah. And, and we can learn from that might take 15 years, maybe.
Let, I don't know if we'll be here talking about it then, though, Chuck. Probably not. Who knows?
No. Hopefully we're on an island somewhere enjoying it. Anyway.
Hey, let me bring it back to Black Hat where we gotta wrap up. You won't be there as you mentioned, but the Ilum, Ilum, Illumio folks will be there. Yeah.
Uh, a little bird is telling me where at Booth, uh, you're at Booth 5 4 4 5, and you're gonna, speaking of ai, you guys are gonna be showing off your new AI powered CBR solution called Insights, live demos, learn more about breach containment offerings or Booth, uh, 5, 4, 4 or five. Is that right? Yeah, yeah.
I'm doing that. I, I, I hope we could show more than that. We got some other cool stuff going on.
We got a, I I think speaking of ai, we've got a new integration with Nvidia. So you can buy an Nvidia card with, uh, Illumio, uh, you know, packaged up in it and run it in there. And I think that that's gonna be, it's originally designed for OT environments, so you mm-hmm.
You can get it on the, um, the Bluefield smart Nick from Nvidia. So you can take out a Nick and an OT environment network interface card and replace it with the, the, this, uh, Nvidia card that has Illumio on it, and then segment out all the traffic coming in from layer two for this, uh, OT device. That's probably really, really hard to secure, uh, given how OT generally works.
So I think that's another thing that, that is super exciting, really. And, uh, I would see that proliferating into a lot of hyperscalers who run Nvidia, uh, at, you know, as their accelerator. I, I will tell you, NVIDIA's done a hell of a job working with the industry companies like Illumio in, in kind of building, integrating these solutions into their, not just their hardware, because everyone of course thinks of them as a chip hardware company, but fact of the matter is they're making them unbelievable software, which is really building out the ecosystem Yeah.
That are locking people into the, this hardware. Um, it is a great example of it, right? It, it's ju it is just in there.
Um, John as always, man, it's great having you on here. It's good seeing you stay well and healthy and out there reaching you too, man. Zero trust.
All righty, John Kinder, uh, from Lumio Chief Evangelist won't be a black hat, but Lumio will stop by their booth. Again, that's 5 4, 4 5, I believe. And, uh, we will see you then.
Until then, though, this Alan Shiel, stay tuned. We have more black hat coverage coming up your way.