Taming Network Policy Sprawl with AI
Broadcasting live from RSAC’s Broadcast Alley, Techstrong Group’s Alan Shimel reconnects with longtime friend and FireMon CEO Jody Brazil to explore the chaotic evolution of network security policy management. While the industry’s shift toward Zero Trust and micro-segmentation is undeniably the right move, Brazil candidly explains how it has created a massive administrative nightmare of fragmented rules and billions of complex access paths that human brains simply cannot process alone. To combat this sprawl, Brazil details how FireMon is leveraging AI-driven chatbots and analytics to bring operational control back to the enterprise, while also highlighting their raw, practitioner-focused “Cyber Confessionals” podcast that exposes the unvarnished reality of keeping the modern business online.
Transcript
Hey everyone, we're back here live on our day three coverage from RSAC on Broadcast Alley, which is just a fancy way of saying Moscone West, right near the keynote room. But anyway, this gentleman here I've had the pleasure of knowing probably longer than either of us want to admit, but it's probably 25 years or something like this. It's Jody Brazill.
Jody is the longtime CEO of Firemon. Actually, passed, then left, came back. That's right.
They pulled him back in, and present Firemon CEO. Excuse me, CEO of Firemon. When I first met Jody, truth be told, though, he was the CTO of FishNet- That's right ...
Security, which was very early MSSP. Early like 2001, 2002, they were already well-established. And in that story is the genesis of Firemon, actually, right?
That's right. And Jody, I don't want to steal your story, though. First of all, welcome.
It's great to see you. Thank you. Look, our audience is your audience.
They've heard of Firemon, but they may not know the whole backstory. And let's go from there and "This is your life, Firemon" and bring us up to what's Firemon today? Yeah.
I appreciate that. We have the genesis story of Firemon started where I think most of the engineers live today, which is it's a complex problem and mistakes happen. , I get a phone call from one of our customers at FishNet, actually, that they were down, and it was costing them literally millions of dollars a minute because these firewalls were the gateway between billing records, and it was down.
" Of course, it's my fault. The firewall's broken. So I drive into the data center, and it's fine.
It's healthy. The firewall's passing traffic, it's all good, but I start sniffing traffic on both sides, and they're right. The traffic they're worried about is on one side, not making it through the other side.
So it takes me a long time. There's nothing in the log records, and I dig through, and I eventually find somebody on the team had created a rule that was explicitly dropping that traffic with no logging. Super simple fix, delete the rule, push the policy, and it's all fixed.
But vowing to never be in that spot again, I wrote some scripts to say, "Just tell me what's going on. What changed? Who did it?
" And I could track those changes. And that became the genesis of Firemon. Those little shell scripts a few years later we said, "This is a market opportunity.
" We built Firemon. So it started out as a simple problem, and the world has gotten more complex. I was going to say, it was a simple world then.
Yeah. But we didn't realize it- Exactly ... but it was a simple world.
And so things have gotten way more complex. And of course, the capabilities of Firemon have grown and progressed through the years. What's changed, I would say, is the world that we're in, the complexity.
Where it used to be interesting when a customer had 5 or 10 firewalls, today it's hundreds or thousands. Right? The number of rules used to be tens or hundreds, and now it's thousands of rules.
And so the complexity has grown, but not just the complexity of an individual firewall. The technology has changed. We used to have access control lists and then proxies and then stateful inspection and now next generation firewalls and even micro-segmentation technologies.
Yeah. So the world has changed. Our ability to support the cloud, the on-prem, the micro-segmentation technology like Illumio, which we announced a strong partnership there.
What's interesting that I think is sometimes overlooked, but the world we live in, is that it doesn't matter which technology you use, and it doesn't matter how awesome the technology is, if the policy that's enforced on that technology is weak, your security is weak. And it's just gotten more complex. So the more complex the policies, the more complex your environment, the more difficult it is to effectively implement those policies, the more likely it is that you're going to have mistakes in those policies, and the more you need a solution like Firemon to provide that control plane across the network security policy infrastructure.
So I got a question I've been dying to ask you for three or four years already. All right. I'm weird like this.
So this year it's all about agentic AI. Mm-hmm. But three years ago, four years ago, zero trust was all the rage.
Sure. Everything was going zero trust. I was driving, I'm such a freak.
I don't know. I'm driving somewhere thinking about zero trust. Yeah.
" Did that make firewall rules harder or easier? Because with zero trust, I could start from this base of everything is shut off. Mm-hmm.
And then one by one, I'm going to put in a rule here, a rule there. Yeah. But I almost did a reset.
I took everything down to closed and then turned them on one by one. So I took some of the complexity out, and at least I didn't have a lot of garbage in my- Sure ... firewall rules.
It was clean. Mm-hmm. Or did zero trust make it harder because now I had to discover what came on and do a...
I don't know what's the matter with me. Yeah. How do you view zero- The practical implications of zero trust.
Yeah. So we are, at Firemon, huge believers in zero trust. It's the right concept.
Obviously. Yep. And it's even the concept that the firewall vendors themselves started with.
If you don't put any rules on a firewall, it should start closed. The last rule should be a drop rule, and it's closed. The challenge is embracing and adopting zero trust principles is really complex.
So imagine if your existing policies allowed access from internal to external. From a policy management standpoint, that's simple, right? Yeah.
One rule, allow it. But it's wildly insecure. " We're all good.
And we know that that's not true, first of all, because there are bad actors internally, but also because a system can get compromised. And soSo as you embrace those zero trust principles, you embrace micro-segmentation from a firewall perspective, and you start making very specific rules, which is great from a security perspective, but really difficult from a management perspective. So now what we have is policies that have thousands of rules.
You have hundreds or thousands of firewalls, and then if you look at any individual rule, it might have 10 or 100 source objects and 10 or 100 destination objects, plus all the specific service objects and applications. From an administrative standpoint, you're trying to manage billions, if not trillions, of access paths, right? Right.
You can't keep that in your brain, right? That doesn't make sense. You can't hold that in your mind.
So instead, you have a general sense of maybe what's allowed, but you don't have any real practical sense- That's right ... of what's happening. So now you've lost control of the ability to manage the technology.
So it's not that the technology's bad, it's not that the zero trust principles are bad, it's that our ability to manage it is really difficult. So it's a complicator, not a simplifier. That's right.
And yet what I love about Illumio, a great technology partner of ours. Illumio's approach to it, I think, is genius. Brilliant.
Which is to say, "Let's not think in terms of an individual asset. That's hard. So let's instead think in terms of tags," right?
So think about this machine as tagged web server, and so are these other 50 things, and I'm going to allow access just to web servers. Well, that makes sense, right? I can logically put that in my brain and make that work.
And so instead of thinking about trillions of access paths, I now break it down to something manageable. And certainly in a POC or in a small sandbox, Illumio is awesome, and you can see the power of the technology. " Instead, we embrace something like Illumio, and it has to live inside of the broader ecosystem.
So you have those 200 Fortinet firewalls as an example. So you allow access in your awesome tag-based policy in Illumio, and inside this one little zone, it works great, but as soon as you have to transit- Right ... in from one data center to another data center or to a cloud, all of a sudden, there's the legacy technology that's in place that isn't aligned to that policy.
And so once again, it gets back to where I started, which is security is all about managing the policy. Yep. Doesn't matter how awesome the technology is.
If the policy isn't secure, then your- You're out of luck ... infrastructure isn't secure. Yeah.
And so bridging those two worlds has become a real problem for enterprises trying to embrace micro-segmentation or zero trust. So bringing zero trust to the enterprise requires that we somehow bridge that gap between the legacy technology and these new principles. Let's talk about legacy technology to new technology.
I got to assume AI- Mm ... must make it easier to manage my policies. Yeah.
Write new policies, go through, look at the policies I have, and tell me good, bad, indifferent, ugly. What a- Yeah. Is that something...
So did I make the zero trust mistake again, Jody? I don't think so. The potential for AI is amazing.
The implementation can be challenging. So we see the power of it, and we've brought AI to policy management through a number of different capabilities. A chatbot, but it gives you access to all of your policy data.
So if you think about a large enterprise, you don't have one Cisco firewall. No. You probably have 50 Cisco routers and maybe 20 Fortinets.
Plus, you're in AWS and Azure, and so AI struggles to understand the complexity of even a single firewall policy, but certainly across that heterogeneous environment, it's really difficult. So what we bring is the ability to query your entire policy across the entire enterprise through a very simple-to-use chatbot interface. But then beyond that, think about one of our core capabilities is compliance or analysis, assessment of your policies, just as you were talking about.
And we evaluate it across a broad spectrum of capabilities and a number of different KPIs that we bring to our users. So think total number of rules, total number of objects, how many unused rules, how many rules represent high risk or critical risk in the organization. We collect all that data and present it in a really powerful dashboard of insights.
It's a pile of metrics, right? Each metric has real value in itself, and inside of it, we don't just have the raw data. We show you trend data, are you getting better or worse, and then we even show benchmarks.
So comparatively against peers or others that have Palo Alto or others that have Fortinet, are you better or worse than those benchmarks? And while that's all great, making sense of hundreds of data points is hard. You know what's really good at that?
AI. AI. Right.
So we can feed the AI, our agent, that says, "I want you to analyze my state of being," that doesn't just take the raw policy data, but takes Firemon's analysis against that raw data and now makes sense of it to say, "You're doing better than the benchmark as far as number of critical risk rules for a Palo Alto environment, but it's trending in the wrong direction over the last three weeks. " But does it suggest improvement? It does, right?
Here are the rules you need to be taking a look at. Here's the action- And that's the power ... to take.
Exactly. Right? We did Techstrong Gang here earlier today.
" Right. "I want to see what actions can we take that-" Yeah ... solves the issue.
Let's solve problems instead of just reporting- Yeah ... problems. And I think it's easy for AI to point out problems.
It is. We used to have this at my executive team. " Yeah.
And we need that from AI, too, right? I think so. And this is an interestingPoint, I had this conversation with somebody on the show floor yesterday about agentic AI and the direction of agentic AI.
And the question was, how fast are organizations going to embrace autonomous agentic AI and security? And I have a strong opinion. We- Surprise.
Yeah. Go ahead. We started a, and I would encourage your members to come check it out, but we started something called Cyber Confessionals, and it's from the ground floor, from those that are actually practitioners in the world doing the hard job of network security management.
And it is the stories that they've run into and what we've learned through those stories, and they're great podcasts. They're quick listens. They're great stories.
Is that while it's really hard and complex to do security, you know what causes the most problems within an organization? It's not the security. It's when they cause an outage, a disruption.
Yeah. Right? So they're doing their job to the- That was always it.
I know. They're doing their job to the best of their ability, and they see a threat, they go block the threat, and nobody cares. But if you go do your job really, really well and accidentally take down the email server, you're fired.
And these are the stories, right? But Jody, 25 years ago, when I first met you and I was selling VAM, the vulnerability assessment tool- Mm-hmm ... this was the same thing I heard.
How come you don't, why does it take you 180 days to patch? Right. Because if the CEO doesn't get one email he was supposed to get, we're all done.
And it hasn't changed. It hasn't changed. So I believe in the power of agentic AI and the opportunity, particularly what you described, which is, can you analyze and bring back a suggestion of how to fix it?
Right. But I believe, at least in the near term, that the human-in-the-loop approach to agentic AI is probably the path forward in security. There's just too much fear to allow the agents to go off and help themselves.
I don't disagree. Look, again, the lesson I learned, not with VAM, but with our IDS, IPS. Yeah.
Who turned on the blocking? No one turned on the blocking. Yeah.
Right? We don't do that. Yeah.
We got to be really, really comfortable- Yeah ... before we go to autonomous or- That's right ... even automatic.
That's right. That's just the nature of security people. So I see it.
There are some niche use cases where I think autonomous agentic AI has a fit. It's just going to be a long road. We may be talking about decades before it fully is embraced.
But along the way, I think we're going to get some tremendous value in the world of network security policy management from AI. Firemon. com.
That's right. Where is the Confessionals? Security Confessionals?
Yes. Cyber Confessionals. The podcast.
Yes. Cyber Confessionals. Yep.
Excuse me. So you can find that on our website, and you'll see a link. Yeah, the podcast, it's great stories.
They really are great stories. Very cool. Of course, you're here, but if people are watching this, they're probably not here, so that probably wouldn't do them any good.
Where else are you going to be soon? What do we have coming up? Of course, we'll be at Black Hat.
It feels like- Yes ... if you're here, you got to venture to the Black Hat. Well, it's a couple of months only now.
That's right. Yep. We have a series of user conferences coming up later this year, starting in the UK in June, and then- Oh, very cool ...
we'll announce some future dates coming up. But yeah. Hey, man.
Another year. It's good to see you. See you as well.
I come to RSA to see my friends. I know. Honestly, I could do this anywhere.
But it's good to see you, Jody. You as well. It's been a minute.
We're live here at RSAC. We'll be back in a minute. You're watching Techstrong TV.