<?xml version="1.0" encoding="UTF-8"?>
  <rss version="2.0"
    xmlns:dc="https://purl.org/dc/elements/1.1/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="https://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="https://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom">

    <channel>
      <title>Zero Networks</title>
      <link>https://zeronetworks.com/blog</link>
      <atom:link href="https://zeronetworks.com/feed" rel="self" type="application/rss+xml" />
      <description>Unified network security platform for microsegmentation and advanced ZTNA.</description>
      <dc:language>en</dc:language>
      <dc:creator>info@zeronetworks.com</dc:creator>
      <dc:rights>Copyright 2026</dc:rights>
      <dc:date>2026-08-17T13:18:00+00:00</dc:date>
      <admin:generatorAgent rdf:resource="https://expressionengine.com/" />

      <image>
        <url>https://zeronetworks.com/images/uploads/site-assets/zer0-rss-image.png</url>
        <title>Zero Networks</title>
        <link>https://zeronetworks.com/blog</link>
        <width>142</width>
        <height>161</height>
      </image>

      
        <item>
          <title>Zero Networks Expands APAC Reach with Exclusive Networks Hong Kong</title>
          <link>https://zeronetworks.com/blog/zero-networks-expands-apac-reach-with-exclusive-networks-hong-kong</link>
          <dc:creator><![CDATA[Ronit Wolf]]></dc:creator>
          <pubDate>Mon, 17 Aug 2026 13:18:00 +0000</pubDate>
          <dc:date>Mon, 17 Aug 2026 13:18:00 +0000</dc:date>
          <category><![CDATA[]]></category>
          <dc:subject><![CDATA[]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/zero-networks-expands-apac-reach-with-exclusive-networks-hong-kong#When:1263</guid>
          <description><![CDATA[Today, Zero Networks announces a partnership with Exclusive Networks Hong Kong, the leading cybersecurity distributor in the region bringing&nbsp;automated containment to one of APAC&#39;s most strategic markets. Together, we&#39;re helping enterprises stop AI-speed attacks before one compromised device becomes a business-wide crisis, protecting uptime, revenue, and operations even when attackers get inside. The collaboration gives Exclusive Networks&#39; Hong Kong resellers a fast path to&#8230;]]></description>
          <content:encoded><![CDATA[<p>Today, Zero Networks announces a partnership with <a href="https://www.exclusive-networks.com/hk">Exclusive Networks Hong Kong</a>, the leading cybersecurity distributor in the region bringing&nbsp;automated containment to one of APAC&#39;s most strategic markets. Together, we&#39;re helping enterprises stop AI-speed attacks before one compromised device becomes a business-wide crisis, protecting uptime, revenue, and operations even when attackers get inside.</p>

<p><br aria-hidden="true" />
The collaboration gives Exclusive Networks&#39; Hong Kong resellers a fast path to automated, identity-driven microsegmentation that verifies every connection and stops lateral movement, human or AI, within seconds. The goal is to help local enterprises strengthen resilience without launching complex, multi-year security projects, combining Zero Networks&#39; automation and agentless-first architecture with Exclusive Networks&#39; regional expertise and partner ecosystem.</p>

<p>Adam Hofeler, VP Sales &amp; GTM&nbsp;at Zero Networks, commented:</p>

<blockquote>
<p>As AI reshapes how organizations detect, manage, and respond to risk, Exclusive Networks partnered with Zero Networks to meet that reality head-on with preventative, identity-based control across different layers where AI introduces risk: governing which cloud AI services can be accessed, enforcing least-privilege boundaries on&nbsp;AI agents, segmenting model infrastructure so it can&#39;t be tampered with, cutting off the connectivity that enables lateral movement, and surfacing compliance gaps in real time.</p>
</blockquote>

<p>A Zero Networks technical workshop hosted by Exclusive Networks last month, attended by their Hong Kong resellers, showed that the local community is&nbsp;ready to move beyond detection-focused security and toward prevention-focused models. Attendees focused on how far an attack,&nbsp; human or AI, could spread inside their networks, and how to contain it without launching a tedious and lengthy project.</p>

<p><strong>Empowering Reseller Partners</strong></p>

<p>This partnership is designed with reseller partners in mind. By combining Zero Networks&rsquo; rapid deployment model and Exclusive Networks&rsquo; value-added services, partners will benefit from:</p>

<ul>
	<li>Access to cutting-edge Zero Trust technology that meets the growing demand for scalable, identity-based security, helping organizations defend against AI-speed attacks, protect uptime, and contain breaches before they spread, so a breach never has to mean business disruption</li>
	<li>Accelerated deployment timelines, enabling faster customer onboarding and quicker ROI.</li>
	<li>Enhanced margin opportunities&#8239;through deal registration, marketing support, and training incentives.</li>
	<li>Comprehensive technical enablement, including certifications, pre-sales support, and co-branded campaigns.</li>
	<li>Strategic alignment with a trusted distributor, helping partners build credibility and close deals more effectively.</li>
</ul>

<p><b>About Exclusive Networks</b></p>

<p>Exclusive Networks (EXN) is a global cybersecurity specialist that provides partners and end-customers with a wide range of services and product portfolios via proven routes to market. With offices in over 45 countries and the ability to serve customers in over 170 countries, we combine a local perspective with the scale and delivery of a single global organisation.</p>

<p>Our best-in-class vendor portfolio is carefully curated with all leading industry players. Our services range from managed security to specialist technical accreditation and training and capitalize on rapidly evolving technologies and changing business models. For more information visit&nbsp;<a href="http://www.exclusive-networks.com/" target="_blank">www.exclusive-networks.com</a>.</p>]]></content:encoded>
        </item>
      
        <item>
          <title>The Kubernetes Rubik&#8217;s Cube: Solving Visibility, Governance, and Segmentation at Scale</title>
          <link>https://zeronetworks.com/blog/the-kubernetes-rubiks-cube-solving-visibility-governance-and-segmentation-at-scale</link>
          <dc:creator><![CDATA[Mohiit Dhawwan]]></dc:creator>
          <pubDate>Fri, 14 Aug 2026 12:00:00 +0000</pubDate>
          <dc:date>Fri, 14 Aug 2026 12:00:00 +0000</dc:date>
          <category><![CDATA[Network Security]]></category>
          <dc:subject><![CDATA[Network Security]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/the-kubernetes-rubiks-cube-solving-visibility-governance-and-segmentation-at-scale#When:1262</guid>
          <description><![CDATA[The K(C)ube &nbsp; Almost everyone has picked up a Rubik&#39;s Cube at some point.&nbsp; The first few moves feel productive. You line up a row of colours, complete part of a side, and convince yourself you&#39;re making progress. Then one more twist undoes everything you just achieved.&nbsp; The challenge isn&#39;t that the cube is impossible to solve. The challenge is that every move affects something else.&nbsp; Kubernetes environments often evolve in exactly the same way.&nbsp; A cluster&#8230;]]></description>
          <content:encoded><![CDATA[<h3>The K(C)ube &nbsp;</h3>

<p>Almost everyone has picked up a Rubik&#39;s Cube at some point.&nbsp;</p>

<p>The first few moves feel productive. You line up a row of colours, complete part of a side, and convince yourself you&#39;re making progress. Then one more twist undoes everything you just achieved.&nbsp;</p>

<p>The challenge isn&#39;t that the cube is impossible to solve. The challenge is that every move affects something else.&nbsp;</p>

<p>Kubernetes environments often evolve in exactly the same way.&nbsp;</p>

<p>A cluster starts simple. A few workloads. A handful of namespaces. A small platform team that understands every application running inside it. Developers know what their services communicate with. Security teams understand the environment. Documentation is current. Dependencies are well known.&nbsp;</p>

<p>Then the business grows.&nbsp;</p>

<p>New applications are deployed. Additional teams adopt the platform. New services are integrated. More namespaces appear. More clusters are introduced. Temporary projects become permanent services. Acquisitions bring in new workloads. Migrations create new dependencies.&nbsp;</p>

<p>As the environment grows, responsibilities also begin to spread across application, platform and security teams. Each team makes decisions within its own part of the environment, but those decisions inevitably affect the others.&nbsp;</p>

<p>Before long, what started as a neatly organised environment begins to resemble a Rubik&#39;s Cube that has been twisted thousands of times.&nbsp;</p>

<p>Every team understands part of the environment. Few understand all of it.&nbsp;</p>

<h2>Kubernetes Was Never Designed to Stay Small&nbsp;</h2>

<p>One of Kubernetes&#39; greatest strengths is its ability to scale rapidly.&nbsp;</p>

<p>Development teams can deploy applications faster than ever. New environments can be created in minutes. Infrastructure becomes highly dynamic and workloads are constantly changing.&nbsp;</p>

<p>But this flexibility introduces new challenges.&nbsp;</p>

<p>Unlike traditional environments where servers may exist for years, Kubernetes workloads can appear and disappear in seconds. Pods are ephemeral. Services communicate across namespaces. Applications are distributed across dozens or even hundreds of microservices. Workloads often communicate not only within a cluster, but across clusters and with external systems.&nbsp;</p>

<p><strong>And it isn&#39;t just the technology that becomes distributed. Responsibility does too.&nbsp;</strong></p>

<p>Application teams design the application, deploy it and increasingly define aspects of its networking and security. Platform and IT teams operate the underlying Kubernetes environment. Security teams remain responsible for governance, risk and ensuring that appropriate controls are in place.&nbsp;</p>

<p>The boundaries between these responsibilities are not always clear.&nbsp;</p>

<p>If a privileged pod introduces unnecessary risk, who owns the problem? Is it an application issue, a platform configuration issue or a gap in security policy? If a new service introduces an unexpected communication path, who is responsible for identifying it and deciding whether that access should exist?&nbsp;</p>

<p>As environments grow and development teams move faster, these questions become increasingly difficult to answer. Security teams may be accountable for protecting the environment without having complete visibility into how applications are changing or communicating. Platform teams understand the infrastructure, while application teams often have the deepest understanding of individual workload dependencies.&nbsp;</p>

<p>Each team understands a different part of the cube.&nbsp;</p>

<p>Questions that were once simple become surprisingly hard to answer:&nbsp;</p>

<ul>
	<li>Which services communicate with each other?&nbsp;</li>
	<li>Which communications are business critical?&nbsp;</li>
	<li>Which namespaces should never communicate?&nbsp;</li>
	<li>Which connections were introduced for testing and never removed?&nbsp;</li>
	<li>What would happen if access was restricted?&nbsp;</li>
	<li>Who owns the risk when unnecessary access is discovered?&nbsp;</li>
</ul>

<p>In many organisations, nobody can confidently answer all of these questions.&nbsp;</p>

<p>This isn&#39;t necessarily a failure of technology or process. It is the reality of operating a modern Kubernetes environment at scale, where the environment can change faster than teams can collectively understand it.&nbsp;</p>

<p><strong>Complexity accumulates faster than understanding.&nbsp;</strong></p>

<h2>The Cost of Not Knowing&nbsp;</h2>

<p>Most platform and security teams understand the value of segmentation.&nbsp;</p>

<p>Yet many <a href="https://zeronetworks.com/resource-center/brochures/solution-brief-zero-networks-for-kubernetes">Kubernetes segmentation</a> initiatives never move beyond planning.&nbsp;Why?&nbsp;</p>

<p>Because nobody wants to break production.&nbsp;</p>

<p>Imagine being asked to implement restrictive Network Policies across a cluster containing hundreds of applications and thousands of workloads.&nbsp;</p>

<p>Before creating a single policy, you need to understand what traffic is required, what traffic is optional, what traffic is legacy and what traffic represents unnecessary risk.&nbsp;</p>

<p>That understanding is rarely owned by a single team. Application teams understand their services and dependencies. Platform teams understand the infrastructure. Security teams understand the risk and controls.&nbsp;</p>

<p>Without that understanding, every policy becomes a gamble.&nbsp;</p>

<p>Block the wrong communication path and a customer-facing application may fail. Restrict access incorrectly and a business-critical service may stop functioning. The operational consequences often feel more immediate than the security risks.&nbsp;</p>

<p>As a result, organisations frequently choose the safest operational option.&nbsp;</p>

<p>They leave access open.&nbsp;</p>

<p>The business impact of this decision is significant. Excessive connectivity increases attack surface, expands blast radius during incidents, complicates compliance efforts, and makes investigations substantially more difficult. Security teams understand the risk, but reducing that risk often appears riskier than accepting it.&nbsp;</p>

<p>The organisation becomes trapped between security and operational certainty.&nbsp;</p>

<h2>Why Native Kubernetes Controls Aren&#39;t Enough&nbsp;</h2>

<p>Kubernetes provides Network Policies that allow organisations to control communication between workloads. The concept is powerful.&nbsp;</p>

<p>The implementation is often challenging.&nbsp;</p>

<p>In smaller environments, manually managing Network Policies may be achievable. In larger environments, the reality becomes much more complicated.&nbsp;</p>

<p>Different teams create policies. Applications evolve. New services are deployed. Existing services are modified. Documentation becomes outdated. New namespaces and workloads appear. Clusters grow. Additional clusters are added.&nbsp;</p>

<p>The challenge is that Kubernetes environments never stay still. Development teams continuously ship changes, often at a pace that security teams cannot manually review. A cluster may initially align with CIS Benchmarks or an organisation&#39;s internal security baseline, but as new workloads, configurations and communication paths are introduced, the environment can gradually drift away from that intended state.&nbsp;</p>

<p>This configuration drift is rarely the result of a single major change. It accumulates over time as applications evolve, teams move quickly and exceptions are introduced. At scale, maintaining consistent policy enforcement becomes just as challenging as defining the policies in the first place.&nbsp;</p>

<p>Over time, organisations accumulate hundreds or even thousands of policy definitions spread across namespaces and environments. Policies that were appropriate when they were created may no longer reflect how applications operate today.&nbsp;</p>

<p>The challenge isn&#39;t creating policies.&nbsp;</p>

<p>The challenge is understanding whether those policies accurately reflect how applications should communicate and ensuring they continue to do so as the environment changes.&nbsp;</p>

<p>Most teams can view individual policies.&nbsp;</p>

<p>Few teams can easily understand the cumulative impact of all policies across the environment, identify where configuration drift has occurred, or determine whether new communication paths have introduced unnecessary exposure.&nbsp;</p>

<p>Without visibility, organisations are effectively trying to solve a Rubik&#39;s Cube while only seeing one side.&nbsp;</p>

<h2>What Happens When a Workload Is Compromised?&nbsp;</h2>

<p>Security teams invest significant effort into preventing compromise.&nbsp;</p>

<p>Clusters are protected by vulnerability scanners, image scanning solutions, admission controllers, runtime protection platforms, secrets management solutions and RBAC controls. These technologies are essential and form a critical part of a defence-in-depth strategy.&nbsp;</p>

<p>However, no organisation can guarantee that a workload will never be compromised.&nbsp;</p>

<p>The more important question is what happens next.&nbsp;</p>

<p>Imagine a single workload becomes compromised. Not the entire cluster. Not a cluster administrator account.&nbsp;</p>

<p>Just one pod.&nbsp;</p>

<p>What can it reach?&nbsp;</p>

<ul>
	<li>Can it communicate with other workloads in the same namespace?&nbsp;</li>
	<li>Can it access services in another namespace?&nbsp;</li>
	<li>Can it discover internal APIs?&nbsp;</li>
	<li>Can it reach backend databases?&nbsp;</li>
	<li>Can it communicate with management services or infrastructure components?&nbsp;</li>
</ul>

<p>For many organisations, the answer is unclear.&nbsp;</p>

<p>By default, Kubernetes environments can provide significantly more connectivity than teams realise. Over time, communication paths accumulate. Some are necessary. Others exist because of historical decisions, temporary exceptions, inherited configurations, or simply because nobody wanted to risk breaking an application.&nbsp;</p>

<p>An attacker doesn&#39;t necessarily need cluster-admin privileges to cause damage.&nbsp;</p>

<p>They need a path to something valuable.&nbsp;</p>

<p>Once an attacker gains access to a workload, trusted east-west communication paths can allow them to discover internal services, communicate across namespaces, access backend APIs, interact with databases or explore management components within the environment.&nbsp;</p>

<p>This is where a contained compromise can become a much broader incident.&nbsp;</p>

<p>A workload that should have been isolated can become a launchpad for lateral movement. Sensitive services that were never intended to communicate may become accessible. Databases, internal APIs and critical business systems can all become part of the attack path.&nbsp;</p>

<p>The challenge isn&#39;t simply that these communication paths exist.&nbsp;</p>

<p>The challenge is knowing which ones should exist.&nbsp;</p>

<p>Without visibility into workload-to-workload communication, it becomes extremely difficult to distinguish legitimate business traffic from unnecessary exposure.&nbsp;</p>

<p>The risk isn&#39;t necessarily the compromised workload.&nbsp;</p>

<p><strong>The risk is everything connected to it.&nbsp;</strong></p>

<p>Before organisations can r<a href="https://zeronetworks.com/blog/how-to-prevent-lateral-movement-cybersecurity-risks-strategies">educe lateral movement</a>, they first need to understand it.&nbsp;</p>

<h2>Seeing the Whole Cube&nbsp;</h2>

<p>The turning point occurs when the environment becomes visible.&nbsp;</p>

<p>Most Kubernetes tools provide visibility into individual components. Teams can inspect pods, deployments, services, logs and policies. While each of these views is valuable, they rarely provide a complete understanding of how the environment functions as a whole.&nbsp;</p>

<p>This is similar to studying a Rubik&#39;s Cube one square at a time. You can understand individual pieces without understanding how they relate to each other.&nbsp;</p>

<p>As Kubernetes environments grow, those relationships become increasingly important.&nbsp;</p>

<p>Security teams need to understand which namespaces communicate with each other. Which communication paths are unrestricted. Which workloads are isolated. Which areas of the environment have no policy enforcement. Which connections are expected and which represent unnecessary exposure.&nbsp;</p>

<p>But visibility also needs to be shared.&nbsp;</p>

<p>Application teams understand how their applications are designed. Platform teams understand how the Kubernetes environment operates. Security teams understand the organisation&#39;s risk and governance requirements. Giving these teams a common view of communication, access and policy helps turn fragmented knowledge into coordinated decision-making.&nbsp;</p>

<p>This is where the Zero Networks Kubernetes Access Matrix becomes valuable.&nbsp;</p>

<p><img alt="" src="https://zeronetworks.com/images/uploads/blog/K8s_Rubiks_Cube_Blog_Graphics_-_Access_Matrix_Imagery.png" />Rather than analysing workloads and policies individually, the Access Matrix provides a visual representation of communication and policy enforcement across the cluster. Teams can identify unrestricted communication paths, isolated namespaces, partially restricted access and areas where no policies exist at all.</p>

<p>Combined with visibility into actual data flows and the existing rule baseline, teams can begin identifying where access is required, where it may be excessive and where ownership or policy decisions are needed.</p>

<p>What previously required teams to piece together information from multiple views becomes visible in a single place. More importantly, the conversation changes.</p>

<p>Teams stop asking: "What happens if we block this?" And start asking: "Why are we allowing this?"</p>

<p>Visibility transforms security from guesswork into decision-making.</p>

<p>And, just as importantly, it gives Application, Platform, and Security teams a common view from which to make those decisions together.</p>

<h2>Solving the Cube Layer by Layer&nbsp;</h2>

<p>Nobody solves a Rubik&#39;s Cube by looking at it once and immediately making the perfect move.&nbsp;</p>

<p>They start by understanding the current state of the puzzle. Only then can they begin making deliberate decisions that move them closer to the end goal.&nbsp;</p>

<p><a href="https://zeronetworks.com/blog/from-flat-to-segmented-baking-security-into-your-k8s-environment">Kubernetes security</a> follows a similar journey.&nbsp;</p>

<p>The first challenge is understanding how workloads communicate. Which namespaces talk to each other? Which connections are required? Which exist purely because they were never removed? Which could become attack paths if a workload is compromised?&nbsp;</p>

<p>Without those answers, implementing segmentation becomes difficult and potentially disruptive.&nbsp;</p>

<p>This is where Zero Networks starts.&nbsp;</p>

<p>Using eBPF-based monitoring, workload communication is automatically discovered and mapped across the cluster. The Kubernetes Access Matrix provides a clear view of namespace-to-namespace relationships, helping teams understand how applications actually communicate rather than relying on outdated documentation or assumptions.&nbsp;</p>

<p>Once communication becomes visible, organisations can begin making informed security decisions.&nbsp;</p>

<p>Instead of attempting to segment the entire environment at once, teams can progressively introduce least-privilege controls using Kubernetes-native Network Policies. Existing policies can be synchronised from Kubernetes into Zero Networks, giving Security and Platform teams a central view of the policies already defined across the environment.&nbsp;</p>

<p>Policies can then be reviewed and approved within Zero Networks before enforcement, adding a governance layer around Kubernetes-native controls. This allows application teams to continue defining the policies their applications require, while giving Security and Platform teams the oversight needed to ensure those policies align with the organisation&#39;s security requirements.&nbsp;</p>

<p>Where appropriate, policies can also be automatically enforced by Zero Networks, reducing the operational effort required to implement and maintain segmentation at scale.&nbsp;</p>

<p>This becomes particularly important as Kubernetes environments continue to change. New workloads, namespaces and communication paths are constantly introduced, making it difficult for Security teams to manually keep policies aligned with the environment.&nbsp;</p>

<p>With automated learning capabilities being introduced, Zero Networks can take this further by learning how workloads communicate and helping create policies based on observed behaviour. Combined with automated enforcement, this can help security controls keep pace as applications and Kubernetes environments evolve.&nbsp;</p>

<p>The result is a Kubernetes environment that looks very different from where it started.&nbsp;</p>

<p>What was once a flat environment with unclear communication paths becomes an environment where connectivity is understood, governed and intentionally controlled.&nbsp;</p>

<p>Attack surface is reduced. Lateral movement opportunities are limited.&nbsp;</p>

<p>And perhaps most importantly, application, platform and security teams gain a common framework for improving security without unnecessarily slowing development or risking disruption to production.&nbsp;</p>

<p><strong>Just like solving a Rubik&#39;s Cube, success doesn&#39;t come from making more moves.&nbsp;</strong></p>

<p>It comes from understanding the puzzle, making the right move and continuing to adapt as the puzzle changes.&nbsp;</p>

<h3>Final Thoughts&nbsp;</h3>

<p>The challenge with a Rubik&#39;s Cube isn&#39;t that it&#39;s impossible to solve.&nbsp;</p>

<p>The challenge is understanding how every piece relates to every other piece.&nbsp;</p>

<p>Kubernetes environments present a remarkably similar problem. As clusters grow, complexity accumulates faster than understanding. Communication paths multiply, applications continuously change and responsibility becomes distributed across Application, Platform and Security teams.&nbsp;</p>

<p>Most organisations don&#39;t struggle because Kubernetes lacks security controls. Kubernetes already provides powerful capabilities such as Network Policies. The challenge is maintaining visibility and governance as the environment evolves &mdash; understanding what should be allowed, what can be restricted and how policies can be consistently enforced without disrupting business operations.&nbsp;</p>

<p>Zero Networks provides the visibility and governance layer that helps bring those pieces together. By providing a shared understanding of workload communication and Kubernetes-native policies, teams can identify unnecessary exposure, coordinate policy decisions and progressively enforce least-privilege segmentation at scale.&nbsp;</p>

<p>The goal isn&#39;t simply to solve the cube once.&nbsp;</p>

<p>It&#39;s to keep it solved as the environment continues to change.&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Vulnerability Management in the Frontier AI Era: How to Proactively Stop Exploitation &nbsp; </title>
          <link>https://zeronetworks.com/blog/vulnerability-management-in-the-frontier-ai-era-how-to-proactively-stop-exploitation</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Thu, 13 Aug 2026 14:00:00 +0000</pubDate>
          <dc:date>Thu, 13 Aug 2026 14:00:00 +0000</dc:date>
          <category><![CDATA[Cybersecurity Trends &amp; CVEs]]></category>
          <dc:subject><![CDATA[Cybersecurity Trends &amp; CVEs]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/vulnerability-management-in-the-frontier-ai-era-how-to-proactively-stop-exploitation#When:1261</guid>
          <description><![CDATA[Vulnerability exploitation now ranks as the #1 way attackers gain access to networks, according to leading industry reports &ndash; Mandiant&rsquo;s 2026 M-Trends report attributes 32% of initial infections to exploits, while exploitation of vulnerabilities similarly accounts for initial access in 31% of breaches investigated for Verizon&rsquo;s 2026 DBIR, a 55% increase year-over-year. &nbsp; The timing of this trend directly coincides with the rise of frontier AI models like Mythos and&#8230;]]></description>
          <content:encoded><![CDATA[<p>Vulnerability exploitation now ranks as the #1 way attackers gain access to networks, according to leading industry reports &ndash; <a href="https://www.gstatic.com/security-marketing/m-trends-2026-en.pdf">Mandiant&rsquo;s 2026 M-Trends report</a> attributes 32% of initial infections to exploits, while exploitation of vulnerabilities similarly accounts for initial access in 31% of breaches investigated for <a href="https://www.verizon.com/business/resources/T766/reports/2026-dbir-data-breach-investigations-report.pdf">Verizon&rsquo;s 2026 DBIR</a>, a 55% increase year-over-year. &nbsp;</p>

<p>The timing of this trend directly coincides with the rise of <a href="https://zeronetworks.com/blog/protecting-against-mythos-daybreak-and-beyond-frontier-ai-security">frontier AI models like Mythos and Daybreak</a>, which represent a growing class of <a href="https://zeronetworks.com/blog/ai-driven-vulnerability-research-and-the-growing-importance-of-containment-architecture">AI-driven vulnerability research</a> tools capable of finding, analyzing, and generating exploits for vulnerabilities at a speed and scale no human team can match &ndash; a development that led <a href="https://www.linkedin.com/pulse/people-building-frontier-ai-just-told-cisos-segment-benny-lakunishok-nutzf/">Open AI to call on CISOs to implement network segmentation.</a></p>

<p>IBM&rsquo;s <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">2026 Cost of a Data Breach report</a> spells out the financial weight behind this rise in machine-speed vulnerability exploitation: <strong>AI-driven attacks add an average of $1 million to the cost of a breach </strong>as new velocity and scale reshape the economics of cyber incidents. &nbsp;</p>

<p>When patches are released at an impossible volume, the window between vulnerability discovery and exploit shrinks to nothing, and security teams face mounting pressure to protect uptime. In response, enterprises need to fundamentally rethink vulnerability management, <a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">prioritizing proactive containment</a> rather than faster patching. &nbsp;</p>

<h3>Key Answers&nbsp;</h3>

<ul>
	<li><strong>What are the latest trends in vulnerability management?</strong> Vulnerability management is shifting from patch-speed to containment-first strategies. Frontier AI models like Mythos and Daybreak have compressed discovery-to-exploit timelines beyond what patch management cycles can match, making proactive containment a key defense. &nbsp;</li>
	<li><strong>Are there any new tools or techniques for vulnerability mitigation? </strong>Security teams can build a standing protection layer that limits what an exploited asset can reach with identity-based microsegmentation, buying more time to test and validate patches before deploying them without leaving the business exposed to critical vulnerabilities in the interim. Tools like <a href="https://zeronetworks.com/resource-center/breach-map">Zero Networks&#39; Breach Map</a> help identify exposure and uncover targeted opportunities for mitigating a vulnerability. &nbsp;</li>
	<li><strong>How can enterprises manage the rise in discovered vulnerabilities and patches driven by frontier AI models? </strong>Security teams can&#39;t realistically test and validate every patch fast enough to keep up with frontier AI-driven discovery volume. Rather than rushing unvalidated fixes into production, enterprises should close unnecessary access paths by default, rely on identity-based microsegmentation to buy the time needed to patch safely, and prioritize remediation based on reachability. &nbsp;</li>
	<li><strong>What are some best practices for proactively defending against vulnerabilities? </strong>Measure blast radius to prioritize business exposure over CVSS severity alone, close unnecessary access paths by default with microsegmentation, apply targeted access rules to buy time while a patch is tested, and ensure containment is enforced architecturally so protection doesn&#39;t depend on detecting an exploit first.&nbsp;</li>
</ul>

<h2>What Is Vulnerability Management? &nbsp;</h2>

<p>Vulnerability management is the ongoing practice of identifying, assessing, resolving, and verifying fixes for security weaknesses across an environment. &nbsp;</p>

<p>Continuous vulnerability management is one of 18 critical security controls included in the <a href="https://zeronetworks.com/blog/cis-framework-critical-security-controls-for-stronger-cyber-defense">Center for Internet Security (CIS) Cybersecurity Framework</a> &ndash; in theory, an always-on cycle of vulnerability scanning, assessment, and remediation enables organizations to remediate vulnerabilities <em>before</em> they can be exploited. However, AI-driven attacks have challenged the assumptions that underpin traditional vulnerability management cycles. &nbsp;</p>

<h3>The Vulnerability Management Lifecycle&nbsp;</h3>

<p>Some vulnerabilities pose a greater threat than others. The vulnerability management lifecycle is meant to help organizations catch and fix the most urgent problems &ndash; it typically revolves around four core stages: &nbsp;</p>

<ol>
	<li><strong>Identify: </strong>Continuous scanning and asset discovery keep a <a href="https://zeronetworks.com/platform/network-map">network map</a> up to date, enabling security teams to effectively identify assets that could be impacted by known and newly disclosed vulnerabilities. &nbsp;</li>
	<li><strong>Assess and prioritize: </strong>Security teams score vulnerabilities by severity (often using the <a href="https://nvd.nist.gov/vuln-metrics/cvss">Common Vulnerability Scoring System [CVSS]</a>), exploitability, and business context to determine what needs attention first.&nbsp;</li>
	<li><strong>Resolve: </strong>The most common approach to resolving a vulnerability is remediation, often achieved by applying a patch. But in some cases, a patch isn&rsquo;t yet available or can&rsquo;t be applied without risking disruption. When full remediation isn&rsquo;t possible, organizations may resolve a vulnerability through mitigation &ndash; applying controls that make the vulnerability significantly harder to exploit or minimize the impact of exploitation, even if the vulnerability technically still exists. &nbsp;</li>
	<li><strong>Verify: </strong>Whether the vulnerability is fully remediated or mitigated, teams confirm the fix closed the exposure to the greatest extent possible without introducing new risk or breaking dependent systems.&nbsp;</li>
</ol>

<p>How Patch Management Works &nbsp;</p>

<p>Patching is a tried-and-true staple in vulnerability remediation. Until now, patch management has followed a predictable cycle: a vendor discloses a vulnerability and it&rsquo;s assigned a CVE, the vendor issues a security patch, and organizations test the patch before deploying it into production. Testing is a critical step in the cycle &ndash; an unvalidated fix can break critical connections and disrupt operations. Once testing clears, the patches are typically deployed on a scheduled cadence, such as Microsoft&#39;s monthly Patch Tuesday; the team verifies the fix afterward. &nbsp;</p>

<p>This cycle was built on the assumption that the time between a vulnerability&#39;s discovery and its mass exploitation would be measured in weeks or months, giving defenders room to test patches safely before deploying. But that timeline has collapsed in the wake of frontier AI models such as Mythos and Daybreak. &nbsp;</p>

<blockquote>
<p>&ldquo;The announcement in April 2026 of a frontier model that managed to find thousands of high-severity vulnerabilities&mdash;including some in every major operating system and web browser&mdash;is a signal warning to security teams &hellip; In the hands of attackers, these tools will collapse the time between vulnerability discovery and exploitation. Attackers are abandoning human speed for machine speed.&rdquo; &nbsp;</p>

<p>IBM, 2026 Cost of a Data Breach Report &nbsp;</p>
</blockquote>

<h3>Why Frontier AI Broke the Traditional Patch Management Model &nbsp;</h3>

<p>Even before AI-enabled discovery and exploitation upended the threat landscape, security teams were struggling to keep up with patching &ndash; and the data proves it. Now, as attackers increasingly weaponize AI, traditional patch management workflows are an untenable solution. &nbsp;</p>

<table border="1" cellpadding="1" cellspacing="1">
	<thead>
		<tr>
			<th scope="col">Report</th>
			<th scope="col">Key Findings</th>
			<th scope="col">What It Means</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td><a href="https://www.verizon.com/business/resources/T766/reports/2026-dbir-data-breach-investigations-report.pdf">Verizon 2026 Data Breach Investigations Report</a>&nbsp;</td>
			<td>
			<ul>
				<li>Only 26% of vulnerabilities defined as critical in CISA&rsquo;s Known Exploited Vulnerabilities (KEV) catalog were fully remediated in 2025, down from 38% the year prior.&nbsp;</li>
				<li>Median time for full resolution of vulnerabilities rose to 43 days, a year-over-year increase of almost two weeks. &nbsp;</li>
			</ul>
			</td>
			<td>Security teams have been struggling to keep up since before frontier AI models triggered a patch avalanche, leaving critical gaps uncovered.</td>
		</tr>
		<tr>
			<td><a href="https://www.gstatic.com/security-marketing/m-trends-2026-en.pdf">Mandiant M-Trends Report 2026</a>&nbsp;</td>
			<td>
			<ul>
				<li>Mean time to exploit (TTE) fell to an estimated -7 days in 2025 &ndash; down from 63 days in 2018.&nbsp;</li>
			</ul>
			</td>
			<td>The average vulnerability is now exploited before a patch is generated. &nbsp;&nbsp;</td>
		</tr>
		<tr>
			<td><a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">IBM 2026 Cost of a Data Breach Report</a></td>
			<td>
			<ul>
				<li>AI-driven attacks rose 56% year-over-year.&nbsp;</li>
				<li>Experts expect AI will favor attackers over defenders by 31.7% within two years.&nbsp;</li>
			</ul>
			</td>
			<td>Even AI tools intended to support defenders run the risk of weaponization as attackers have so far advanced in the &ldquo;AI arms race.&rdquo; &nbsp;</td>
		</tr>
	</tbody>
</table>

<p>So, the rapid acceleration in vulnerability discovery is forcing already strained patch management cycles to a breaking point. For example, Microsoft released its largest Patch Tuesday ever in July of 2026: 570 fixes, including three <a href="https://zeronetworks.com/blog/what-is-a-zero-day-attack-everything-you-need-to-know">zero-day vulnerabilities</a> &ndash; in total, a more than 3x increase since April. &nbsp;</p>

<p>The practical impact for defenders that continue to rely on patching as their core vulnerability management strategy is a forced tradeoff: you can patch immediately and <a href="https://zeronetworks.com/blog/1000-fixes-a-month-and-it-wont-save-you-the-only-winning-move-is-not-to-be-reachable">manage updates that contain thousands of fixes at a time</a>, or wait and validate the highest priority patches while accepting risk exposure in the interim. In either case, operational continuity is at risk. &nbsp;&nbsp;</p>

<blockquote>
<p>&ldquo;We cannot patch Mythos or Daybreak away. Discovery is infinite now. We can find thousands or even millions of new vulnerabilities every day. And the patching time we have is finite &ndash; it&#39;s impossible to digest all those patches, validate that a new patch isn&#39;t generating a business impact, and move fast enough. Even with prioritization, it will always be late. Because the time AI needs to generate an exploit will always be faster than the time you need to prioritize, test, and apply the patch.&rdquo;&nbsp;</p>

<p><a href="https://zeronetworks.com/blog/protecting-against-mythos-daybreak-and-beyond-frontier-ai-security">Albert Estevez, Field CTO, Zero Networks&nbsp;</a></p>
</blockquote>

<p>Enterprises understand the importance of taking action &ndash; <strong><a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">85% of organizations plan to increase security spending</a> in response to frontier AI model threats.</strong> But simply throwing more budget at existing strategies won&rsquo;t give defenders a reliable advantage. Instead, organizations need a <a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">containment-first architecture</a> that stops attacks by design &ndash; regardless of their speed or initial access vector. &nbsp;</p>

<h2>How to Prevent Vulnerability Exploitation: 4 Best Practices for Preemptive Cyber Resilience &nbsp;</h2>

<p><a href="https://www.gartner.com/en/documents/7772953">Gartner noted after Mythos launched</a> that&#8239;<em>"CIOs must tell their boards they will have to recalibrate their risk appetite for vulnerabilities because <strong>faster patch cycles won&#39;t be enough</strong>." &nbsp;</em></p>

<p>The need for vulnerability management and patching hasn&rsquo;t gone away, but the discipline must evolve &ndash; rather than chasing every vulnerability, organizations should prioritize cyber resilience and <a href="https://zeronetworks.com/resource-center/brochures/best-practices-to-reduce-attack-surface-and-shrink-blast-radius">proactively limit the blast radius</a> of vulnerability exploits by following these 4 best practices. &nbsp;</p>

<h3>1. Measure Blast Radius for Tailored Vulnerability Risk Insights&nbsp;</h3>

<p>While CVSS measures theoretical severity, it doesn&rsquo;t clarify your business&rsquo; actual exposure. To assess the <a href="https://zeronetworks.com/blog/attack-path-analysis-for-business-resilience-mapping-cyber-risk-exposure">potential real-world impact of a vulnerability exploit,</a> enterprises should map their internal network to discover reachable assets, how they connect, where attackers could move, and what they could reach. <strong>Free tools like <a href="https://zeronetworks.com/resource-center/breach-map">Zero Networks&rsquo; Breach Map</a> are the fastest way to uncover your blast radius</strong> and learn where an exploit could cause the most damage. &nbsp;</p>

<h3>2. Close Unnecessary Access Paths by Default with Microsegmentation &nbsp;</h3>

<p>Vulnerabilities give attackers an initial foothold but excessive <a href="https://zeronetworks.com/resource-center/topics/lateral-movement-innovations-prevention-techniques">lateral movement</a> exposure is what turns minor cyber incidents into widespread breaches. <a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report">Zero Networks&#39; 2026 Lateral Movement Exposure Report</a> found 80% of enterprise servers are reachable from anywhere on the network, and 85% of internal systems are directly accessible from a single compromised host. In other words, attackers typically inherit broad internal access regardless of how they initially breach the network &ndash; whether that&rsquo;s via a vulnerability exploit or any other vector. &nbsp;</p>

<p><a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">Microsegmentation</a> eliminates the internal pathways that exist for convenience rather than verified business need. Even if an attacker manages to gain initial access to a granularly segmented network, they&rsquo;ll hit an immediate dead end because <a href="https://zeronetworks.com/blog/how-to-prevent-lateral-movement-cybersecurity-risks-strategies">lateral movement is prevented by design</a>. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/breach-map"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Breach_Map_Download_%281%29.png" /></a></p>

<h3>3. Buy Time to Patch Safely with Network- and Identity-Based Controls &nbsp;</h3>

<p>If a patch introduces outage risks of its own, it&rsquo;s not a true fix. While patch availability is skyrocketing, security teams can&rsquo;t realistically validate every patch quickly enough to remediate all newly discovered vulnerabilities. Even if bandwidth weren&rsquo;t a barrier, OT and legacy systems can&#39;t always be patched on short notice without planning significant change windows that risk production impact.&nbsp;</p>

<p>Organizations that have already implemented <a href="https://zeronetworks.com/blog/network-microsegmentation-in-2026-gartner-research-takeaways">identity-based microsegmentation</a> have built a foundational buffer against vulnerabilities; when a specific flaw poses a particularly urgent business risk, security teams have the tools in place to build a targeted rule that addresses the exposure until a patch can be deployed safely. &nbsp;</p>

<p>For example, <a href="https://zeronetworks.com/blog/building-cyber-resilience-in-financial-services-6-real-world-success-stories">B. Riley Financial faced a Microsoft Outlook vulnerability</a> involving outbound SMB traffic that left the firm exposed with no patch available from the vendor. Waiting for a fix meant leaving the exposure open, so they worked with Zero Networks to deploy a targeted rule blocking outbound SMB traffic from Outlook to the internet, closing the specific path the vulnerability relied on. &nbsp;&nbsp;</p>

<blockquote>
<p>&ldquo;<strong>Having microsegmentation in place has really given us a precautionary protection layer so we can delay applying some of these patches</strong>. This gives us plenty of time to test, make sure everything&rsquo;s working, and then apply it, but still have that protection layer in place.&rdquo;&nbsp;</p>

<p>- Aaron Goodwin, CISO, B. Riley Financial &nbsp; &nbsp;&nbsp;</p>
</blockquote>

<h3>4. Automate Threat Containment Independent of Detection &nbsp;</h3>

<p>Last year, <a href="https://www.verizon.com/business/resources/T766/reports/2026-dbir-data-breach-investigations-report.pdf">29% of vulnerabilities in CISA&rsquo;s KEV catalog were attacked before public disclosure</a>, meaning exploitation was underway before defenders knew what to look for. Containment that depends on catching an exploit in progress inherits the same speed disadvantage as patching: a human SOC &ndash; or even an automated detection tool &ndash; still has to notice, verify, and respond before damage spreads. The probability that every step in the detect-and-respond chain works flawlessly and fast enough to stop machine-speed threats? Near zero. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/guides/resilient-by-design-architecting-security-that-keeps-operations-running">Built-in containment</a> removes the dependency on detection and response workflows. If access paths are closed by default and enforcement doesn&#39;t require a trigger, a compromised asset can&#39;t move laterally regardless of whether the malicious activity is immediately detected. That&#39;s the difference between a reactive strategy and architecture that makes the attack&#39;s next move impossible from the start &ndash; <strong>and it becomes more consequential every month frontier AI compresses the window for containment.</strong> &nbsp;</p>

<h2>Build Proactive Vulnerability Protection in the AI Era with Zero Networks &nbsp;</h2>

<p>Zero Networks&rsquo; <a href="https://zeronetworks.com/platform">automated, identity-based microsegmentation</a> agentlessly orchestrates native firewalls to isolate every asset, preventing lateral movement and building a containment layer against vulnerability exploits &ndash; no matter how quickly they&rsquo;re executed. &nbsp;</p>

<p>Unlike reactive tools that depend on known indicators, Zero builds a proactive security posture that prevents attacks from spreading at the architectural level, effectively mitigating the impact of vulnerabilities so security teams can protect business continuity while buying time to patch safely. &nbsp;</p>

<p>Get a firsthand look at how you can build a closed-by-default architecture and stay resilient against machine-speed threats &ndash; <a href="https://zeronetworks.com/request-demo">request a demo</a>. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>How 3 Manufacturers Secured Production-Critical Systems with Microsegmentation</title>
          <link>https://zeronetworks.com/blog/how-3-manufacturers-secured-production-critical-systems-with-microsegmentation</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Wed, 12 Aug 2026 15:00:00 +0000</pubDate>
          <dc:date>Wed, 12 Aug 2026 15:00:00 +0000</dc:date>
          <category><![CDATA[Network Segmentation &amp; Microsegmentation]]></category>
          <dc:subject><![CDATA[Network Segmentation &amp; Microsegmentation]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/how-3-manufacturers-secured-production-critical-systems-with-microsegmentation#When:1259</guid>
          <description><![CDATA[The manufacturing industry has an incredibly low tolerance for downtime, and attackers know it. A single hour of downtime can cost high-volume manufacturers millions of dollars&nbsp;while sending shockwaves across global supply chains, and while AI-enabled attackers are moving faster than ever, the mean time to identify and contain a breach increased over the last year, according to IBM&rsquo;s 2026 Cost of a Data Breach Report. &nbsp; Manufacturing organizations can&rsquo;t afford to rely on&#8230;]]></description>
          <content:encoded><![CDATA[<p>The manufacturing industry has an incredibly low tolerance for downtime, and attackers know it. A single hour of downtime can <a href="https://blog.siemens.com/2024/07/the-true-cost-of-an-hours-downtime-an-industry-analysis/">cost high-volume manufacturers millions of dollars</a>&nbsp;while sending shockwaves across global supply chains, and while AI-enabled attackers are moving faster than ever, the mean time to identify and contain a breach <em>increased</em> over the last year, according to <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">IBM&rsquo;s 2026 Cost of a Data Breach Report</a>. &nbsp;</p>

<p>Manufacturing organizations can&rsquo;t afford to rely on detection and response. Security teams know <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">microsegmentation</a> is the answer for building preemptive cyber resilience, but legacy approaches have a track record of failing manufacturing environments specifically: complex, agent-based deployments strain lean IT teams, manual policy management can&#39;t keep pace with production schedules, and the fear of breaking a live system stalls projects before they start.&nbsp;</p>

<p>This roundup features three <a href="https://zeronetworks.com/company/customer-stories">Zero Networks customers</a> that successfully deployed <a href="https://zeronetworks.com/platform">identity-based microsegmentation</a> to strengthen <a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">cyber resilience</a> without adding operational complexity. We&#39;ll walk through how these manufacturers eliminated downtime risk during implementation, met cyber insurance requirements, and extended protection to legacy systems without disrupting the infrastructure their operations depend on.&nbsp;</p>

<h2>Non-Disruptive Network Segmentation: Eliminating Outage Risk&nbsp;</h2>

<p>Many manufacturers implementing microsegmentation fear that a new security tool might lead to operational disruption. Reconfiguring network architecture often risks the exact outcome security teams are trying to prevent: unplanned downtime. That&rsquo;s why half of manufacturing security leaders <a href="https://zeronetworks.com/resource-center/reports/network-segmentation-zero-trust-architectures-survey-of-it-security-professionals">point to implementation complexity as their top microsegmentation concern</a>, followed closely by disruption to existing operations.&nbsp;</p>

<h3>Real-World Examples&nbsp;</h3>

<p><a href="https://zeronetworks.com/company/customer-stories/automated-policy-creation-with-zero-false-positives">Vermeer</a> manufactures the industrial and agricultural equipment that keeps global communities fed and fueled. The security team was on a mission to find a virtual airgap solution that could enhance overall security, but with a complex network and no appetite for downtime, Vermeer couldn&rsquo;t rely on traditional tools or manual approaches. &nbsp;</p>

<p><a href="https://zeronetworks.com/company/customer-stories/100-improvement-in-network-performance-and-reliability">Atlantic Constructors</a> &ndash; a commercial construction, prefabrication, and industrial services provider &ndash; faced a version of the same concern. Rising <a href="https://zeronetworks.com/blog/how-to-meet-cyber-insurance-requirements">cyber insurance requirements</a> pushed the team to look for a microsegmentation solution, but every other product they evaluated threatened a long, complex implementation that could disrupt the business before it delivered any protection.&nbsp;</p>

<h3>The Solution: Agentless Deployment and Deterministic Policy Automation&nbsp;</h3>

<p>Vermeer and Atlantic Constructors achieved granular protection without the outage risks and implementation complexity of legacy microsegmentation tools thanks to Zero&rsquo;s automated, agentless approach: &nbsp;</p>

<ul>
	<li>With an agentless architecture, Zero Networks orchestrates native, host-based firewalls already present in the environment, avoiding the latency and integration risk that comes with agent-based tools.&nbsp;</li>
	<li>A defined learning period allows <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">Zero&#39;s automation engine</a> to observe real traffic and build policies from actual network behavior, removing the upfront manual burden. &nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">Policies generated and enforced via deterministic, human-on-the-loop automation</a> reflect what the network actually needs to keep running securely, not a best guess that risks blocking legitimate traffic.&nbsp;</li>
</ul>

<blockquote>
<p>&ldquo;[Zero Networks] is an agentless solution, so it&rsquo;s relying on the network firewall that&rsquo;s native to Windows which allows us to control both allows and denies to the PC or the host that the connections are going between. And then on top of that, they have the automatic engine that is learning, and taking that data, and translating it into rules.&rdquo; &nbsp;</p>

<p>Justin Manifold, Senior IT Security Engineer, Vermeer &nbsp;</p>
</blockquote>

<p>By leveraging Zero&rsquo;s non-disruptive, deterministic solution, Vermeer <strong>segmented their network in 30 days while maintaining 100% of legitimate traffic</strong>. Similarly, Atlantic Constructors deployed Zero in just 15 minutes, ultimately<strong> improving network performance and reliability by 100%</strong>.&nbsp;</p>

<h2>Legacy Systems and Vendor Lock-In: Extending JIT MFA Everywhere &nbsp;</h2>

<p>Manufacturing environments are built on decades of accumulated infrastructure that many security tools aren&rsquo;t designed to address. Microsegmentation vendors that require complex configurations and proprietary MFA tools force manufacturers to accept coverage gaps or introduce additional complexity into an environment that can&#39;t afford failure. &nbsp;</p>

<h3>Real-World Examples&nbsp;</h3>

<p><a href="https://zeronetworks.com/company/customer-stories/securing-the-systems-behind-4200-production-lines-worldwide">Mikron</a> is the leading partner for high performance production systems, building the complex components used to produce the things that matter &ndash; pharmaceutical devices, precision medtech, automotive parts, and more. With frequent changes to the environment, maintaining consistent policies via Group Policy Objects (GPOs) proved nearly impossible, but other segmentation vendors couldn&rsquo;t easily integrate with Mikron&rsquo;s existing environment and required proprietary MFA systems that threatened continuity. &nbsp;</p>

<p>Similarly, Vermeer needed a way to protect privileged access without introducing the kind of friction that would disrupt the production and engineering workflows already running smoothly.&nbsp;</p>

<h3>The Solution: Just-in-Time Network-Layer MFA &nbsp;</h3>

<p>Mikron and Vermeer closed identity least privilege gaps without risking critical connections or leaving legacy systems vulnerable by enforcing Zero&rsquo;s <a href="https://zeronetworks.com/resource-center/guides/mini-mfa-guide-extend-mfa-beyond-login-close-privileged-pathways">network-layer MFA</a> for just-in-time access: &nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/blog/mfa-is-our-dna-zero-networks-multi-factor-segmentation">Network-layer MFA</a> extends authentication to admin protocols and privileged activities without touching the underlying legacy systems or introducing new failure points.&nbsp;</li>
	<li>Seamless integration with existing infrastructure means a consistent user experience rather than forcing a second, proprietary authentication system into the environment.&nbsp;</li>
	<li>Added on top of identity-based microsegmentation, network-layer MFA effectively prevents compromised credentials from delivering access to production-critical systems. &nbsp;</li>
</ul>

<div>
<div style="padding:56.25% 0 0 0;position:relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media; web-share" frameborder="0" referrerpolicy="strict-origin-when-cross-origin" src="https://player.vimeo.com/video/1140219304?badge=0&amp;autopause=0&amp;player_id=0&amp;app_id=58479" style="position:absolute;top:0;left:0;width:100%;height:100%;" title="Mikron's IT and Security Leaders Talk About Zero Networks"></iframe></div>
<script src="https://player.vimeo.com/api/player.js"></script></div>

<p>For Vermeer, the addition of network-layer MFA gave the security team confidence to <strong>strengthen privileged access protection while maintaining the stability its always-on manufacturing environment requires</strong>. Since Zero Networks integrated seamlessly with Mikron&rsquo;s environment &ndash; no proprietary tooling or rip-and-replace approach required &ndash; Mikron achieved the comprehensive protection they needed without risking operational disruption, completing <strong>full network segmentation rollout within weeks and at a fraction of the effort GPOs demanded</strong>. &nbsp;</p>

<h2>Cyber Insurance and Compliance Requirements: Validating Protection&nbsp;</h2>

<p>In the industrial sector, <a href="https://zeronetworks.com/blog/how-to-meet-cyber-insurance-requirements">cyber insurance</a> has become table stakes, and carriers are asking for proof that cybersecurity strategies translate to real resilience. Over <a href="https://zeronetworks.com/resource-center/guides/the-manufacturing-buyers-guide-for-evaluating-microsegmentation-solutions">two-thirds of manufacturers say</a> their cyber insurance carrier requires network segmentation specifically, and that mandate is only getting harder to satisfy with labor-intensive legacy approaches. &nbsp;</p>

<h3>Real-World Example&nbsp;</h3>

<p>Atlantic Constructors&#39; search for a microsegmentation solution was driven directly by rising cyber insurance requirements. The team needed to strengthen its overall security posture in a way that would hold up to scrutiny &ndash; and once Zero Networks was deployed, the organization put it to the test. &nbsp;</p>

<h3>The Solution: Cyber Resilient Segmentation Architecture&nbsp;</h3>

<p>With Zero&rsquo;s identity-based microsegmentation in place, Atlantic Constructors unlocked the compliance evidence they needed without creating a new manual burden for the security team: &nbsp;</p>

<ul>
	<li>Continuous, automated policy enforcement generates audit-ready evidence of segmentation as a byproduct of normal operation, rather than requiring a separate compliance exercise.&nbsp;</li>
	<li>Because policies enforce <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">least-privilege access by default</a>, the pathways attackers and penetration testers rely on are closed structurally, before a test ever finds them.&nbsp;</li>
	<li><a href="https://zeronetworks.com/platform/network-map">Real-time network mapping</a> demonstrates current resilience posture, unlocking up-to-date visibility into real risk exposure. &nbsp;</li>
</ul>

<blockquote>
<p>&ldquo;After we got Zero, I decided to run another pen test to see how things were working, and we literally could not get it to penetrate one of the machines we were testing &hellip; We did some speed tests and [network] performance probably doubled. Reliability went up 100%.&rdquo;&nbsp;</p>

<p>Jim Paolicelli, IT Director, Atlantic Constructors&nbsp;</p>
</blockquote>

<p>With the impact of microsegmentation validated through penetration testing, Atlantic Constructors ultimately <strong>traded multiple legacy platforms for Zero Networks&rsquo; unified solution</strong>. &nbsp;</p>

<h2>Built-in Cyber Resilience and Supply Chain Stability with Zero Networks &nbsp;</h2>

<p>From outage risks due to implementation complexity to legacy system constraints and beyond, manufacturers have long faced microsegmentation hurdles that cause initiatives to stall. Zero Networks removes those barriers and enables manufacturing organizations to secure complex environments, protect legacy systems, and boost operational resilience in days &ndash; not years. &nbsp;</p>

<p>By delivering <a href="https://zeronetworks.com/platform">automated, identity-driven microsegmentation</a> that seamlessly integrates with existing infrastructure combined with network-layer MFA for privileged access, Zero removes the manual effort and outage concerns that make legacy tools too risky to industrial orgs. &nbsp;</p>

<p>See how Zero Networks makes cyber resilience practical for manufacturers &ndash; <a href="https://zeronetworks.com/request-demo">request a demo</a>. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Machine Identity Security: How to Protect Service Accounts and AI Agents</title>
          <link>https://zeronetworks.com/blog/machine-identity-security-how-to-protect-service-accounts-and-ai-agents</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Tue, 11 Aug 2026 18:39:00 +0000</pubDate>
          <dc:date>Tue, 11 Aug 2026 18:39:00 +0000</dc:date>
          <category><![CDATA[Network Security]]></category>
          <dc:subject><![CDATA[Network Security]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/machine-identity-security-how-to-protect-service-accounts-and-ai-agents#When:1258</guid>
          <description><![CDATA[Machine and service identities now outnumber human users 109:1 &ndash; a trend that&rsquo;s on track to accelerate as organizations anticipate 85% growth in AI agent adoption over the next year. These non-human identities (NHI) are typically over-privileged and under-monitored, creating a growing network security blind spot that attackers can use to move laterally without triggering alerts. In fact, less than a third of organizations extend granular access controls and zero trust architecture to&#8230;]]></description>
          <content:encoded><![CDATA[<p>Machine and service identities now <a href="https://www.paloaltonetworks.com/idira/identity-security-landscape-report">outnumber human users 109:1</a> &ndash; a trend that&rsquo;s on track to accelerate as organizations anticipate 85% growth in AI agent adoption over the next year. These non-human identities (NHI) are typically over-privileged and under-monitored, creating a growing network security blind spot that attackers can use to <a href="https://zeronetworks.com/resource-center/topics/lateral-movement-innovations-prevention-techniques">move laterally</a> without triggering alerts. In fact, less than a third of organizations extend granular access controls and zero trust architecture to NHI, according to <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">IBM&rsquo;s 2026 Cost of a Data Breach Report</a>. &nbsp;</p>

<p>We&rsquo;ll break down why machine identities are uniquely risky, how attackers exploit overprivileged service accounts and AI agents, and what enterprises can do to <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">expand least privilege enforcement</a> to <em>every</em> network identity &ndash; from human users and admins to service accounts and AI agents. &nbsp;</p>

<h3>Key Answers&nbsp;</h3>

<ul>
	<li><strong>What are non-human identities (NHI)? </strong>An identity used by software rather than a human user to authenticate and access systems, such as service accounts, AI agents, cloud workloads, or APIs.&nbsp;</li>
	<li><strong>How can security teams protect service accounts and machine identities from abuse? </strong>By discovering every identity in the environment via an automated solution, scoping access to observed operational need identified during a learning period, and enforcing granular, identity-based access controls, backed by automated policy management that adapts as the network changes.&nbsp;</li>
	<li><strong>What are some best practices for AI agent access control?</strong> Treat every agent as its own governed identity: discover what&#39;s running, scope access to what each agent&#39;s function requires, and apply the same identity-based restrictions used for human users rather than granting AI agents ambient trust.&nbsp;</li>
	<li><strong>How can enterprises enforce least privilege across non-human identities? </strong>Continuously map what every identity &ndash; including service accounts and AI agents &ndash; can reach, restrict identities to pre-approved assets and logon types, and automate policy updates so access stays current as the network changes, rather than relying on static rules or manual review.&nbsp;</li>
</ul>

<h2>What Is Non-Human Identity (NHI) Security? &nbsp;</h2>

<p>NHI security is the practice of applying the same governance to machine identities, service accounts, API keys, workload identities, and <a href="https://zeronetworks.com/blog/agentic-ai-cybersecurity-risks-how-to-secure-ai-agents">AI agents</a> that enterprises enforce for human users. &nbsp;</p>

<p>While &ldquo;machine identity&rdquo; originated as a narrower term for cryptographic credentials and &ldquo;non-human identity&rdquo; was introduced as a broader umbrella term, both are used to cover the same expanding category in practice: identities used by software (rather than human users) to authenticate and gain access to systems. &nbsp;</p>

<p>This category encompasses a range of subtypes, with some of the most common including:&nbsp;</p>

<table aria-colcount="2" aria-rowcount="5" border="1" data-tablelook="1184" data-tablestyle="MsoTableGrid" dir="ltr">
	<thead>
		<tr aria-rowindex="1" role="row">
			<th data-celllook="0" role="rowheader" scope="col">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{32}" paraid="1949779911">Machine Identity Type&nbsp;</p>
			</th>
			<th data-celllook="0" role="columnheader" scope="col">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{35}" paraid="130653836">What It Is&nbsp;</p>
			</th>
		</tr>
	</thead>
	<tbody>
		<tr aria-rowindex="2" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{39}" paraid="1359323886">Service accounts&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{42}" paraid="1615352783">Non-human accounts running applications, automation, and backend processes&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="3" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{46}" paraid="1781958563">API keys and tokens&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{49}" paraid="1224629943">Credentials that authenticate machine-to-machine calls&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="4" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{53}" paraid="855979876">Workload identities&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{56}" paraid="1781184548">Identities&nbsp;assigned to cloud roles, containers, or serverless functions&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="5" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{60}" paraid="1410752295">AI agents&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{30edd898-91aa-4d44-8de6-a9d8be3edf02}{63}" paraid="2035107254">Autonomous processes that reason, chain tool calls, and act with minimal human oversight&nbsp;</p>
			</td>
		</tr>
	</tbody>
</table>

<p>Although every non-human identity carries a unique risk profile, two types in particular represent the greatest enterprise threat today: service accounts and <a href="https://www.linkedin.com/pulse/people-building-frontier-ai-just-told-cisos-segment-benny-lakunishok-nutzf/">AI agents.</a> &nbsp;&nbsp;</p>

<h2>Machine Identity Security Risks and Challenges &nbsp;</h2>

<p>Like most non-human identities, service accounts and AI agents share an underlying set of risks: they run on standing access that&rsquo;s rarely reviewed after being provisioned, and they&rsquo;re built to operate in the background, so misuse goes unnoticed. What differs is how fast access accumulates and how well-established the governance gap already is &ndash; service account sprawl is an established vulnerability, while the full scope of the agentic attack surface is still unfolding. Some of the most pervasive NHI risks span:&nbsp;</p>

<ul>
	<li><strong>Static credentials with no MFA checkpoint: </strong>AI agents operate across open-ended workflows without a human approving each step &ndash; they authenticate, hold tokens, and gain access autonomously through accumulated entitlements, yet <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">less than half of organizations report</a> securing NHI in AI workflows. Likewise, service accounts run on static credentials that are rotated quarterly at best, with some organizations even setting them to never expire at all, since rotating a credential tied to a live production process carries operational risk of its own. &nbsp;</li>
	<li><strong>Standing permissions and privilege creep: </strong>Many service accounts are over-provisioned with domain admin or enterprise-wide access that&rsquo;s not operationally necessary. The same is true for agentic identities &ndash; the more tasks AI agents are assigned, the more entitlements they accumulate through policy drift, tool chaining, and expanding scope. &nbsp;</li>
	<li><strong>Shadow AI and the agentic governance gap: </strong>Nearly <a href="https://www.ibm.com/think/insights/agentic-ai-security">80% of enterprises are already deploying AI agents</a> internally, and roughly two-thirds have no governance policies in place to manage them. That gap starts as a visibility problem &ndash; security teams can&rsquo;t discover, let alone control the <a href="https://zeronetworks.com/blog/securing-shadow-ai-how-to-detect-and-govern-unsanctioned-ai-tools">shadow AI running in their environment</a>. Sanctioned or not, agentic adoption is expanding AI attack surfaces faster than organizations can scale governance. &nbsp;</li>
	<li><strong>Activity evades detections tools: </strong>Service account and AI agent traffic blends in with normal activity because it relies on legitimate access. When attackers exploit those permissions to move laterally and access sensitive systems, the threat stays hidden from detection tools since it doesn&rsquo;t look anomalous. &nbsp;</li>
</ul>

<h2>How Attackers Exploit Overprivileged Service Accounts and AI Agents: Real-World Scenarios&nbsp;</h2>

<p>The risk of NHI exploitation isn&rsquo;t theoretical &ndash; it&rsquo;s a documented threat, backed up by real-world attacks. &nbsp;</p>

<h3>Stored Service Account Credentials Create Lateral Movement Pathways &nbsp;</h3>

<p>An <a href="https://zeronetworks.com/blog/4-real-world-cyberattack-lessons-what-data-breaches-teach-us">incident response investigation carried out by Michael Matok, Incident Remediation &amp; Recovery Lead at Sygnia</a>, uncovered that after attackers breached a vulnerable NetScaler appliance via a widely exploited CVE, service account credentials stored in the compromised systems ultimately allowed attackers to move laterally via RDP. &nbsp;</p>

<div>
<div style="padding:100% 0 0 0;position:relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media; web-share" frameborder="0" referrerpolicy="strict-origin-when-cross-origin" src="https://player.vimeo.com/video/1146622005?badge=0&amp;autopause=0&amp;player_id=0&amp;app_id=58479" style="position:absolute;top:0;left:0;width:100%;height:100%;" title="Lessons Learned from Past Breaches: Attack Flow (Sygnia)"></iframe></div>
<script src="https://player.vimeo.com/api/player.js"></script></div>

<p>What should have been a low-privilege, read-only LDAP bind account had accumulated far more access than necessary, enabling hackers to pivot, change a domain admin account&rsquo;s password, and take control. In other words, one misconfigured service account turned an initial foothold into a widespread breach. &nbsp;</p>

<h3>Agentic Threats Move Laterally at Machine Speed &nbsp;</h3>

<p>In July of 2026, <a href="https://zeronetworks.com/blog/hugging-face-proves-ai-finds-the-gap-lateral-movement-expands-the-blast-radius">Hugging Face disclosed an intrusion</a> into its production infrastructure, later attributed by OpenAI to its own models operating autonomously during an internal security evaluation. The models found a zero-day in a package proxy, escalated privileges, and moved laterally through Hugging Face&#39;s internal infrastructure &ndash; autonomously &ndash; until they reached the target data in a production database. &nbsp;</p>

<p>While the AI vector is distinct, the lesson is similar to takeaways from attacks involving overprivileged service accounts: when networks aren&rsquo;t built to constrain lateral movement by design, a single vulnerability exploitation can quickly spiral into a business-impacting incident.&nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report"><img alt="" src="https://zeronetworks.com/images/uploads/blog/LMER_Download_CTA_%281%29.png" /></a></p>

<h2>How to Enforce Least Privilege for Non-Human Identities &nbsp;</h2>

<p>Closing machine identity security gaps isn&rsquo;t a matter of layering on more monitoring to the same static access models. Instead, enterprises need dynamic access enforcement built around how non-human identities actually behave.&nbsp;</p>

<h3>Discover Every Service Account and AI agent in the Environment &nbsp;</h3>

<p>Because service accounts typically operate in the background, they&rsquo;re notoriously hard to monitor. Similarly, widespread AI adoption &ndash; often beyond IT oversight &ndash; has created a massive AI agent blind spot in many enterprises. The first step in enforcing least privilege controls for NHI is <a href="https://zeronetworks.com/platform/network-map">implementing continuous network monitoring</a> that maps every identity, tool, and connection in the environment, forcing shadow AI and long-hidden service accounts into the spotlight.</p>

<h3>Scope NHI Access to Business Need &nbsp;</h3>

<p>Visibility establishes what agents and service accounts can reach; the next step is understanding what access they need to perform their intended functions. By&#8239;<a href="https://zeronetworks.com/platform/network-map">observing real network&#8239;behavior over time</a>, security teams can identify which connections are genuinely necessary, where provisioned access exceeds true requirements, and where that gap creates the riskiest exposure. With this learned baseline, teams can <a href="https://zeronetworks.com/blog/zero-standing-privileges-what-it-means-why-it-matters-and-how-to-implement-it">down-scope access to reflect operational need</a> without breaking key connections. &nbsp;</p>

<blockquote>
<p>&ldquo;Among organizations that suffered AI-related breaches in this year&rsquo;s study, 92% lacked proper access controls. This finding reveals a systemic failure to treat identity as mission-critical infrastructure. In the race to deploy AI agents to automate business processes&mdash;including security operations defending against frontier AI models&mdash;teams must fundamentally transform identity systems to secure not just humans, but NHIs, too.&rdquo;&nbsp;</p>

<p>IBM, 2026 Cost of a Data Breach Report&nbsp;</p>
</blockquote>

<h3>Enforce Granular, Identity-Based Access Controls&nbsp;</h3>

<p><a href="https://zeronetworks.com/platform/identity-segmentation">Granular access controls must apply to every identity</a> &ndash; human, machine, or AI. Service accounts, AI agents, and all machine identities should be restricted to pre-approved assets and logon types, ensuring lateral movement and unauthorized access to sensitive systems are blocked even if machine identities are compromised. &nbsp;</p>

<h3>Automate Policy Lifecycle Management with a Deterministic Engine &nbsp;</h3>

<p>Modern enterprise environments are too dynamic for static, IP-centric policies that govern a location rather than an identity; that&rsquo;s why <a href="https://zeronetworks.com/blog/network-microsegmentation-in-2026-gartner-research-takeaways">Gartner says it&rsquo;s time to pivot</a> from IP-centric rules to unified identity fabric where enforcement adapts dynamically. &nbsp;</p>

<blockquote>
<p>&ldquo;The shift from network-centric to identity-first segmentation is a response to the evolution of traditional perimeters to hybrid architectures, the rise of dynamic, cloud-native environments, and the adoption of NHI &hellip; Relying on static, IP-based microsegmentation guarantees catastrophic vulnerability to AI-driven attacks.&rdquo;&nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/reports/gartner-reimagining-network-microsegmentation">Gartner, Reimagining Network Microsegmentation: Beyond the IP &ndash; Identity, Context, and Agentless Innovation</a></p>
</blockquote>

<p>A <a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">deterministic policy engine</a> that leverages learned network baselines to create accurate rules can also be used to automatically adapt policies as the network changes, ensuring access is always tailored to identity. &nbsp;</p>

<h2>Close Identity Least Privilege Gaps with Zero Networks &nbsp;</h2>

<p>Most organizations struggle to answer a simple question: how many service accounts and AI agents are running in their environment right now, and what can each one actually reach? That blind spot, not attacker sophistication, turns a single overprivileged non-human identity into a business-disrupting breach. &nbsp;</p>

<p>Zero Networks closes the least privilege gaps that have traditionally left machine identities over-permissioned and under-monitored with <a href="https://zeronetworks.com/platform">automated, identity-driven microsegmentation</a>. Zero makes it easy to discover and control service accounts, AI agents, and every other identity: &nbsp;</p>

<ul>
	<li>After deploying in a click, Zero delivers comprehensive visibility into every network asset and identity on the network before tracking all logon activities, account behaviors, and asset access patterns during a learning period. &nbsp;</li>
	<li>A deterministic automation engine maps observed network behavior, generates least-privilege policies based on learned baselines, and keeps teams in control through human-on-the-loop simulation and staged rollout before enforcement.&nbsp;</li>
	<li><a href="https://zeronetworks.com/platform/identity-segmentation">Identity-based policies</a>&#8239;govern access at the network layer, tied to user, machine, or AI identity, and automatically updated as environments change.&#8239;&nbsp;</li>
</ul>

<p>Learn how you can secure service accounts and AI agents without slowing the pace of innovation in your organization &ndash; <a href="https://zeronetworks.com/request-demo">request a demo</a>. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Attack Path Analysis for Business Resilience: Mapping Cyber Risk Exposure </title>
          <link>https://zeronetworks.com/blog/attack-path-analysis-for-business-resilience-mapping-cyber-risk-exposure</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Sat, 01 Aug 2026 13:43:00 +0000</pubDate>
          <dc:date>Sat, 01 Aug 2026 13:43:00 +0000</dc:date>
          <category><![CDATA[Operational &amp; Cyber Resilience]]></category>
          <dc:subject><![CDATA[Operational &amp; Cyber Resilience]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/attack-path-analysis-for-business-resilience-mapping-cyber-risk-exposure#When:1254</guid>
          <description><![CDATA[In most enterprises, a single compromised endpoint directly exposes 85% of the environment. In fact, Zero Networks&#39; 2026 Lateral Movement Exposure Report found that 12.2% of enterprise environments expose at least one user-to-server administrative pathway &ndash; a direct route from compromised endpoint to crown jewels. &nbsp; While most businesses know what their critical assets are, far fewer have a clear understanding of their true cyber risk exposure &ndash; or what to do about it. This&#8230;]]></description>
          <content:encoded><![CDATA[<p>In most enterprises, a single compromised endpoint <a href="https://zeronetworks.com/blog/one-compromised-system-and-boom-meet-your-blast-radius">directly exposes 85% of the environment</a>. In fact, <a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report">Zero Networks&#39; 2026 Lateral Movement Exposure Report</a> found that 12.2% of enterprise environments expose at least one user-to-server administrative pathway &ndash; a direct route from compromised endpoint to crown jewels. &nbsp;</p>

<p>While most businesses know <em>what</em> their critical assets are, far fewer have a clear understanding of their true cyber risk exposure &ndash; or what to do about it. This is especially true for cyber pros watching AI proliferate in the wild and within their networks; most organizations are still working to understand external and internal AI threat exposure, let alone forge a path to <a href="https://zeronetworks.com/platform/ai-capabilities">AI control</a>. We&rsquo;ll lay out a framework for <a href="https://zeronetworks.com/blog/cisos-guide-to-business-impact-analysis-3-steps-to-strengthen-cyber-resilience">analyzing attack paths as part of a business impact analysis</a>, enabling security leaders to build a cyber resilience strategy that directly maps to business outcomes. &nbsp;</p>

<h3>Key Answers&nbsp;</h3>

<ul>
	<li><strong>How does attack path analysis work? </strong>An attack path analysis traces the route an attacker could take from an initial point of compromise to a critical asset and measures the controls that stand in the way to uncover the true scope of exposure. This can be completed as a phased process (involving discovery, modeling, and pathfinding), or automated using free resources like Zero Networks&rsquo; <a href="https://zeronetworks.com/resource-center/breach-map">Breach Map</a> tool. &nbsp;</li>
	<li><strong>What is the role of an attack path analysis in a business impact analysis (BIA)? </strong>A BIA identifies which assets are critical and what downtime would cost; attack path analysis clarifies how exposed those critical assets are and identifies priority interventions for security leaders targeting cyber resilience objectives. &nbsp;&nbsp;</li>
	<li><strong>How should enterprises prioritize business resilience investments? </strong>By identifying the attack paths with the highest business impact relative to containment readiness, then implementing controls that increase path distance or eliminate entire attack scenarios (like <a href="https://zeronetworks.com/platform/network-segmentation">microsegmentation</a>), minimize privilege exposure (<a href="https://zeronetworks.com/solutions/apply-mfa-to-anything">just-in-time authentication</a>), and constrain potential damage to key resources (<a href="https://zeronetworks.com/platform/identity-segmentation">identity-based access controls</a>).&nbsp;</li>
</ul>

<p><a href="https://zeronetworks.com/resource-center/guides/ciso-guide-business-impact-analysis-for-cyber-resilience"><img alt="" src="https://zeronetworks.com/images/uploads/blog/BIA_Guide_Download_%281%29.png" /></a></p>

<h2>What is Attack Path Analysis? &nbsp;</h2>

<p>An attack path analysis identifies the route an attacker could take from an initial point of compromise to a critical asset, translating unstructured risk exposure insights into a view of real, exploitable paths. &nbsp;</p>

<p>In the context of a business impact analysis (BIA), attack path analysis shouldn&rsquo;t only identify exploitable attack paths to critical assets specifically but should also uncover the interventions that will most meaningfully improve cyber and operational resilience.&nbsp;</p>

<h3>How to Use Attack Path Analysis in a BIA&nbsp;</h3>

<p>A business impact analysis starts with identifying which systems and assets are critical to the strategic success and day-to-day operations of the company. Documenting critical assets &ndash; and establishing a baseline estimate of what downtime would cost &ndash; is the first step in tailoring cyber resilience strategies to business priorities. An attack path analysis answers the logical follow-up question: <em>how exposed are critical assets?</em> &nbsp;</p>

<p>To uncover the scope of business exposure, attack path analysis maps open pathways and evaluates the level of effort it would take an attacker to move from a common ingress point to a critical asset, giving organizations a documented map of true exposure tied to likely attack tactics rather than a general sense of risk. &nbsp;</p>

<p>A list of critical assets tells you what&rsquo;s important, not where to act first. A <a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">cyber resilience</a> focused attack path analysis turns that list into a prioritized map of where risk exposure and business impact intersect most sharply.&nbsp;</p>

<h3>Attack Path vs. Attack Vector vs. Attack Surface &nbsp;</h3>

<p>Security teams will deal with three related yet distinct terms when mapping and evaluating attack paths as part of a BIA: &nbsp;</p>

<ul>
	<li><strong>Attack surface</strong> is the sum of all points in your environment where an attacker could potentially gain entry or exploit a vulnerability &ndash; every exposed port, every identity, every endpoint, every cloud workload, and every third-party integration. The larger and more complex your environment, the broader your attack surface. &nbsp;</li>
	<li>An <strong>attack vector</strong> is the specific method an attacker uses to exploit a point in the attack surface and gain an initial foothold. For example, compromised credentials or vulnerability exploitation are common attack vectors. &nbsp;</li>
	<li>An <strong>attack path</strong> is the route an attacker travels along through the environment after gaining initial access to reach critical assets &ndash; the amount of damage they could do along the way makes up an organization&rsquo;s <a href="https://zeronetworks.com/blog/what-is-blast-radius-in-cybersecurity-best-practices-for-breach-containment">blast radius</a>. &nbsp;</li>
</ul>

<p>In other words, attack surface describes <em>what</em> can be breached, an attack vector is <em>how</em> breaches can occur, and attack paths illustrate <em>where</em> adversaries can go after gaining initial access to eventually reach critical systems. &nbsp;</p>

<h2>4 Attack Vectors to Map for Every Critical Asset &nbsp;</h2>

<p>Starting with the most business-critical assets, security teams should analyze attack paths using scenarios that reflect today&#39;s threat landscape:&nbsp;</p>

<ul>
	<li><strong>Compromised user:</strong> A standard user account compromised through phishing, credential theft, or malware. &nbsp;</li>
	<li><strong>Compromised cloud identity or AI agent:</strong> Stolen credentials or session tokens for a SaaS, IaaS, or agentic identity, often exploited to pivot into on-premises resources through federation, single sign-on trust relationships, or an AI agent&rsquo;s standing access.&nbsp;</li>
	<li><strong>Technical perimeter entry: </strong>Exploitation of an internet-facing device or service, such as a VPN concentrator, edge firewall, or public-facing web application, to gain code execution and a foothold for further lateral movement.&nbsp;</li>
	<li><strong>Trusted vendor/third-party access: </strong>A compromised or malicious third party using pre-existing privileged access, like a vendor VPN connection or API integration, to reach internal systems.&nbsp;</li>
</ul>

<p>For each critical asset, trace the shortest plausible path per vector. &nbsp;</p>

<h2>How to Map Attack Paths: Discovery, Modeling, and Pathfinding &nbsp;</h2>

<p>With critical assets and relevant attack vectors identified, security teams can begin mapping the attack paths they&rsquo;ll use to analyze exposure &ndash; when done manually, this typically happens in three stages: &nbsp;&nbsp;</p>

<h3>1. Discovery: Inventory Systems, Identities, and Connections&nbsp;</h3>

<p>Uncovering attack paths starts with an accurate view of all network assets, identities, connections &ndash; including service accounts, AI agents, and other traditionally under-monitored parts of the network &ndash; to effectively track how they might contribute to an exploitable pathway between a given entry point and a critical asset. &nbsp;</p>

<h3>2. Modeling: Uncover Communication Pathways &nbsp;</h3>

<p>Convert discovered inventory into a graphical view of what&rsquo;s reachable across on-prem, cloud, IoT/OT, and Kubernetes: which systems and identities can access which assets, through what trust relationships, and whether or not that access shows up in routine traffic.&nbsp;</p>

<p><a href="https://zeronetworks.com/platform/network-map"><img alt="" src="https://zeronetworks.com/images/uploads/platform/network-map.png" /></a></p>

<h3>3. Pathfinding: Chain Exploitable Steps Together &nbsp;</h3>

<p>Starting from a pre-defined entry point, trace the routes an attacker could exploit, including paths gated behind authentication or JIT approval, that lead to a critical asset. At enterprise scale, this usually requires graph traversal algorithms to enumerate every path reachable from an entry point to a given asset. &nbsp;</p>

<h3>Automated Attack Path Mapping &nbsp;</h3>

<p>For enterprises that need an accurate view of exposure without months of manual background work, <strong>free tools like <a href="https://zeronetworks.com/resource-center/breach-map">Zero Networks&rsquo; Breach Map</a> automate all three stages</strong>. Breach Map scans the internal network to discover reachable assets, then generates an interactive visual map showing how assets connect, where attackers would move, and what they could reach.&nbsp;</p>

<p>The report surfaces total assets discovered, how many are reachable via <a href="https://zeronetworks.com/resource-center/topics/lateral-movement-innovations-prevention-techniques">lateral movement</a>, average blast radius, attack surface, and direct and indirect crown jewel risk &ndash; without weeks of manual discovery and log analysis. It also acts as a personalized benchmark tool for cyber leaders and teams as they work to lock down key attack paths.&nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/breach-map"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Breach_Map_Download_%281%29.png" /></a></p>

<h2>Analyzing Attack Paths: How to Measure Cyber Risk Exposure &nbsp;</h2>

<p>After mapping attack paths from entry point to critical asset, security teams can analyze paths against three threat containment metrics that signal the true scope of exposure. &nbsp;</p>

<table aria-colcount="3" aria-rowcount="4" border="1" data-tablelook="1184" data-tablestyle="MsoTableGrid" dir="ltr">
	<tbody>
		<tr aria-rowindex="1" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{97}" paraid="1016149204">Metric&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{100}" paraid="698644804">What It Measures&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{103}" paraid="634187209">What to Document&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="2" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{107}" paraid="620218349">Path Distance&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{110}" paraid="1354600770">Barriers between entry point and asset&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{113}" paraid="326793659">Authentication boundaries, segments traversed, inspection points, cross-domain crossings&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="3" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{117}" paraid="24774712">Privilege Requirements&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{120}" paraid="1100608008">Difficulty of gaining usable access&nbsp;to&nbsp;a resource&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{123}" paraid="1239876802">Escalation levels,&nbsp;persistent privileged&nbsp;access, service account density, added authentication&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="4" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{127}" paraid="1124037019">Data-Layer Controls&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{130}" paraid="1555440773">How much damage an attacker could do upon reaching a critical asset&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{133}" paraid="1386470056">Encryption at rest, identity-based access controls&nbsp;</p>
			</td>
		</tr>
	</tbody>
</table>

<h3>Path Distance: How Attackers Move Laterally Through the Network&nbsp;</h3>

<p>Path distance is the most consequential dimension to measure, because interventions here can remove risk rather than just raising its cost. For example, <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">microsegmentation</a> can close lateral movement pathways and effectively eliminate entire compromise scenarios. For the purposes of measuring containment, focus on assessing four things: &nbsp;&nbsp;</p>

<ul>
	<li><strong>Authentication boundaries crossed</strong>: Distinct credential challenges between entry point and asset, excluding any boundary satisfied by credentials the attacker already holds.&nbsp;</li>
	<li><strong>Network segments traversed</strong>: Segments governed by actively enforced, granular policy &ndash; not segmentation that exists on paper but permits broad access in practice due to accumulated exceptions and policy drift.&nbsp;</li>
	<li><strong>Enforced inspection points in path</strong>: Tools actively operating in prevention mode; detection-only controls don&#39;t count, since they depend on a human responding in time.&nbsp;</li>
	<li><strong>Cross-domain traversal</strong>: Genuine trust boundary crossings, like on-prem to cloud or IT to OT, that demand a distinct credential set rather than one satisfied by shared federation.&nbsp;</li>
</ul>

<h3>Privilege Requirements: What Permissions Attackers Need to Access Critical Assets &nbsp;</h3>

<p><em>Reaching</em> an asset isn&#39;t the same as <em>accessing</em> it. Privilege requirements measure how difficult it is for an attacker to obtain the privileges needed to actually impact a critical asset. As a measure of containment, this dimension carries less weight than path distance because privilege controls typically raise the cost of an attack (rather than removing the route entirely via structural controls), but the two are deeply interconnected. Privilege requirements should be captured through details like: &nbsp;</p>

<ul>
	<li><strong>Escalation levels required</strong>: Each distinct privilege escalation is a separate point of potential failure for attackers, though shortcuts like cached credentials or over-provisioned service accounts can collapse multiple levels into one.&nbsp;</li>
	<li><strong>Persistent privileged access</strong>: Standing access without just-in-time reauthentication means a single compromised credential can be a ticket to critical assets on its own.&nbsp;</li>
	<li><strong>Service account density</strong>: Broadly scoped service accounts are frequent escalation targets and are often excluded from user activity monitoring.&nbsp;</li>
</ul>

<p>Additional authentication requirements: Hardware tokens or out-of-band approval that the entry vector can&#39;t reasonably satisfy caps the blast radius outright.&nbsp;</p>

<h3>Data-Layer Controls: Limiting Damage After a Breach&nbsp;</h3>

<p>The final containment dimension to assess along identified attack paths answers the only remaining question: if an attacker reaches the critical asset <em>and</em> manages to gain access, how much damage can they do? This can be measured through controls such as: &nbsp;</p>

<ul>
	<li><strong>Encryption at rest: </strong>With separated key management, a successful compromise can corrupt or delete data but not read or exfiltrate it.&nbsp;</li>
	<li><strong>Identity-based access controls: </strong>Granular access controls limit what any single compromised identity can reach even after accessing a resource, enforcing a final layer of protection for the most sensitive data. &nbsp;</li>
</ul>

<h2>How to Identify Top Business Resilience Priorities and Investments &nbsp;</h2>

<p>After analyzing attack paths to critical assets for current containment controls, security leaders should have three things: &nbsp;</p>

<ol>
	<li>An inventory of business-critical assets and an understanding of downtime thresholds &nbsp;</li>
	<li>A view of all pathways from common ingress points to those critical resources &nbsp;</li>
	<li>A breakdown of how exposed the exploitable paths truly are, measured against containment controls &nbsp;</li>
</ol>

<p>With these insights, the final analysis can be completed &ndash; the goal is to find where business impact and containment readiness converge most sharply. For example, if a billing system has an extremely low downtime threshold due to its high revenue impact but is directly accessible within two lateral movement pivots via compromised user credentials, then it should rank as a high priority. &nbsp;</p>

<p>With priorities defined, security leaders have a <a href="https://zeronetworks.com/blog/what-is-cyber-resilience-how-to-protect-business-continuity">blueprint for tying cyber resilience directly to business impact</a>. Resilience strategies should be implemented using same threat containment dimensions that help uncover risk exposure and define urgency: &nbsp;</p>

<ul>
	<li><strong>Increase path distance or completely remove pathways to critical assets:&#8239;</strong>Granular&#8239;<a href="https://zeronetworks.com/blog/network-segmentation-all-you-need-to-know">network segmentation</a>, additional authentication boundaries, and inspection points can eliminate entire compromise scenarios.&nbsp;</li>
	<li><strong>Reduce privilege exposure:&#8239;</strong><a href="https://zeronetworks.com/blog/stopping-privilege-escalation-how-to-neutralize-stolen-credential-threats">Eliminating persistent privileged access</a>, reducing service account scope, and enforcing just-in-time reauthentication or additional authentication requirements for critical assets can rein in the privilege sprawl attackers rely on. &nbsp;</li>
	<li><strong>Enforce data layer controls:&#8239;</strong>Implementing&#8239;granular <a href="https://zeronetworks.com/platform/identity-segmentation">identity-based access controls</a>&nbsp;and encryption at rest limits the damage an attacker can do if they manage to reach critical systems.&nbsp;</li>
</ul>

<p>As security leaders take a more active role in business continuity, this framework delivers a repeatable way to align cyber resilience strategies with board-level priorities. &nbsp;</p>

<h3>Cyber Resilient by Design: Protect Uptime with Zero Networks&#39; Automated, Identity-Driven Microsegmentation &nbsp;</h3>

<p>Zero Networks proactively blocks threats to protect operational continuity with <a href="https://zeronetworks.com/platform">automated,&#8239;identity-based microsegmentation</a>, delivering the containment layer environments need to close attack paths without impacting legitimate traffic. &nbsp;</p>

<p>Zero provides immediate visibility into every identity and asset on the network, <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">then&#8239;automatically enforces adaptive, identity-aligned policies</a> based on observed network behavior. With <a href="https://zeronetworks.com/platform/network-map">always-current network visibility</a> and a deterministic, human-on-the-loop automation engine, Zero Networks delivers preemptive cyber resilience with no manual effort or operational complexity.&nbsp;</p>

<p>Learn how you can build a closed-by-default architecture that measurably improves business resilience &ndash; <a href="https://zeronetworks.com/request-demo">request a demo</a>. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Network Resilience Benchmarks: An Automated Containment Roadmap</title>
          <link>https://zeronetworks.com/blog/network-resilience-benchmarks-an-automated-containment-roadmap</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Fri, 31 Jul 2026 17:47:00 +0000</pubDate>
          <dc:date>Fri, 31 Jul 2026 17:47:00 +0000</dc:date>
          <category><![CDATA[Incident Response &amp; Breach Containment]]></category>
          <dc:subject><![CDATA[Incident Response &amp; Breach Containment]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/network-resilience-benchmarks-an-automated-containment-roadmap#When:1253</guid>
          <description><![CDATA[The Zero Trust mindset that breaches are inevitable is no longer controversial &ndash; instead of trying to stop everything at the perimeter, modern enterprises are increasingly focused on cyber resilience, asking: can the business keep operating through an attack &ndash; and can we prove it? &nbsp; Automated containment is the foundation of cyber resilience, translating to defensible uptime protection. When attackers move in seconds, AI-enabled workflows execute in parallel, and identity&#8230;]]></description>
          <content:encoded><![CDATA[<p>The Zero Trust mindset that breaches are inevitable is no longer controversial &ndash; instead of trying to stop everything at the perimeter, modern enterprises are increasingly focused on cyber resilience, asking: <em>can the business keep operating through an attack &ndash; and can we prove it? &nbsp;</em></p>

<p><a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">Automated containment</a> is the foundation of <a href="https://zeronetworks.com/blog/what-is-cyber-resilience-how-to-protect-business-continuity">cyber resilience</a>, translating to defensible uptime protection. When attackers move in seconds, AI-enabled workflows execute in parallel, and identity systems authenticate continuously, human response cycles can&rsquo;t keep up, so defenders&rsquo; only durable advantage is limiting access by default.&nbsp;</p>

<p>We&rsquo;ll walk through a simple framework for benchmarking your current network resilience on the path to automated containment and share a roadmap for building a self-defending architecture. &nbsp;</p>

<h3>Key Answers &nbsp;</h3>

<ul>
	<li><strong>How does automated containment strengthen cyber resilience?</strong> Automated containment strengthens cyber resilience by constraining blast radius structurally, so a compromised asset is isolated automatically rather than depending on a team to detect and respond fast enough. This shifts resilience from a reactive workflow to a demonstrable outcome &ndash; uptime and continuity hold during an incident because containment is built into the architecture itself, not bolted on after the fact.&nbsp;</li>
	<li><strong>What are the pillars of network resilience?</strong> Containment architecture, identity and access governance, network visibility, and policy automation are the four central priorities for building network resilience. Together, they proactively minimize blast radius to contain the impact of any attack. &nbsp;</li>
	<li><strong>What does a self-defending network architecture look like? </strong><a href="https://zeronetworks.com/platform">Automated, identity-aware microsegmentation</a> keeps access paths closed by default, privileged access requires just-in-time authentication, and a real-time network map informs dynamic policy automation, so coverage adapts as the network changes. &nbsp;</li>
</ul>

<h2>5 Stages of Network Resilience: Maturity Benchmarks &nbsp;</h2>

<p><a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">Cyber resilience</a> isn&rsquo;t just about recovering from a breach &ndash; it&rsquo;s about preventing the breach from spreading in the first place, so sensitive systems stay isolated and critical operations keep running. Rather than more automated detection or faster response, true resilience <a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">limits the impact of a breach automatically</a> by <em>proactively</em> constraining blast radius. &nbsp;</p>

<p>Because <a href="https://csrc.nist.gov/glossary/term/network_resilience">network resilience</a> refers to an infrastructure&rsquo;s capacity to provide continuous business operations, it&rsquo;s the most direct measure of security success against business priorities &ndash; and it&rsquo;s achieved when four interconnected capabilities work together: &nbsp;</p>

<ol>
	<li><strong><a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">Containment architecture</a>: </strong>How granularly assets and workloads are isolated from one another &ndash; and how much of the environment is accessible from any given foothold &ndash; defines the structural ceiling on how far a breach can travel, known as the <a href="https://zeronetworks.com/blog/what-is-blast-radius-in-cybersecurity-best-practices-for-breach-containment">blast radius</a>. &nbsp;</li>
	<li><strong><a href="https://zeronetworks.com/resource-center/topics/enhancing-identity-security-everything-you-need-to-know-about-identity-access-control">Identity and access governance</a>: </strong>Network architecture defines the shape of the environment; identity determines who can move through it, where they can go, and under what conditions.&nbsp;</li>
	<li><strong><a href="https://zeronetworks.com/blog/how-real-time-network-visibility-enables-automated-zero-trust-enforcement">Network visibility</a>:</strong> Comprehensive, real-time visibility across every asset, workload, identity, and communication pathway ensures that resilience controls reflect the environment as it actually exists. &nbsp;</li>
	<li><strong><a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">Policy automation</a>:</strong> A security posture held together by manual processes and periodic reviews will drift as the environment changes; automation ensures controls adapt continuously rather than degrade slowly.&nbsp;</li>
</ol>

<p>With these pillars in mind, organizations can map their network resilience against a simple five-stage framework: &nbsp;</p>

<ul>
	<li><strong>Stage 1 &ndash; Flat and Blind:</strong> Everything trusts everything and there are no East-West controls. &nbsp;</li>
	<li><strong>Stage 2 &ndash; Alert-Heavy:</strong> Tools like EDR and SIEM provide visibility without containment. &nbsp;</li>
	<li><strong>Stage 3 &ndash; Early Containment:</strong> Some level of segmentation has been implemented but policies are manual and constantly multiplying.&nbsp;</li>
	<li><strong>Stage 4 &ndash; Automated Containment:</strong> Identity-aware segmentation automatically blocks unauthorized lateral movement.&nbsp;</li>
	<li><strong>Stage 5 &ndash; Self Defending:</strong> Adaptive controls create an audit-ready posture and breach containment is built into the network architecture.&nbsp;</li>
</ul>

<p><a href="https://zeronetworks.com/blog/how-to-build-a-self-defending-network-a-framework-for-cyber-resilience">According to Chris Boehm</a>, Field CTO at Zero Networks, most organizations sit between stages two and three today &ndash; they have tools in place, they complete red teaming exercises, and they meet basic compliance requirements, but they&rsquo;re grappling with an unmanageable alert volume. &nbsp;&nbsp;</p>

<blockquote>
<p>&ldquo;A developer says, &#39;I need access to everything or I won&#39;t get this done.&#39; You open holes temporarily. A temporary hole here, a temporary hole there. You&#39;re paying someone $200,000 a year and you just need to get them going. That&#39;s how most organizations end up between stages two and three.&rdquo; &nbsp;</p>

<p>- Chris Boehm &nbsp;</p>
</blockquote>

<p>Benchmarking your current network resilience across core pillars delivers a clear starting point for building automated containment and, in turn, strengthening cyber resilience.</p>

<table aria-colcount="5" aria-rowcount="6" border="1" data-tablelook="1184" data-tablestyle="MsoTableGrid" dir="ltr">
	<tbody>
		<tr aria-rowindex="1" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{59}" paraid="74272901">Stage&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{62}" paraid="1891019762">Containment Architecture&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{65}" paraid="720327810">Identity &amp; Access Governance&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{68}" paraid="982106314">Network Visibility&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{71}" paraid="1370873024">Policy Automation&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="2" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{75}" paraid="887177021">1. Flat and Blind&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{78}" paraid="1078184198">Perimeter only; no internal segmentation&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{81}" paraid="58963983">Access standing and broad by default&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{84}" paraid="1865996508">No insight into&nbsp;East-West traffic&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{87}" paraid="1927569334">None; no&nbsp;internal&nbsp;policy exists to automate&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="3" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{91}" paraid="597401605">2. Alert-Heavy&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{94}" paraid="609660849">Zones&nbsp;likely exist&nbsp;via VLANs&nbsp;or ACLs; broad trust within each one&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{97}" paraid="748610792">Access governed by network position, not identity&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{100}" paraid="1723881042">Alerts exist, but not path-level visibility&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{103}" paraid="2075947241">None; policy is static and hardware-bound&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="4" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{107}" paraid="1829532410">3. Early Containment&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{110}" paraid="295949597">Ringfenced groups&nbsp;or sensitive resources; exceptions multiply manually&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{113}" paraid="1429432682">Privileged and service accounts accumulate unused permissions&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{116}" paraid="811590648">Partial asset visibility; service accounts often unmapped&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{119}" paraid="1773764730">None; exceptions are tracked by hand, if at all&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="5" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{123}" paraid="199500144">4. Automated Containment&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{126}" paraid="1239648582">Microsegementation&nbsp;enforces per-asset policies,&nbsp;blocks lateral movement by default&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{129}" paraid="957748768">Access explicitly granted and tied to identity&nbsp;&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{132}" paraid="526098264">Full asset and identity mapping&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{135}" paraid="419218693">Enforced automatically, but requires deliberate upkeep to stay current&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="6" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{139}" paraid="610019782">5. Self-Defending&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{142}" paraid="2126208653">Closed by default across every axis of traffic&nbsp;&ndash; automated, identity-aware&nbsp;microsegmentation&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{145}" paraid="1965510225">Continuous&nbsp;verification;&nbsp;privileged access requires JIT authentication&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{148}" paraid="2146723441">Complete and real-time, used to inform dynamic policies&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{151}" paraid="1577781335">Fully adaptive; policy corrects itself as the environment changes&nbsp;</p>
			</td>
		</tr>
	</tbody>
</table>

<h2>Automated Containment Roadmap: How to Build a Self-Defending Network Architecture&nbsp;</h2>

<p>As security leaders are increasingly tasked with proving a zero-tolerance policy for downtime, building automated containment &ndash; that dynamically adapts as the environment changes &ndash; into the network architecture is the most reliable path to true network resilience. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/guides/resilient-by-design-architecting-security-that-keeps-operations-running"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Cyber_Resilience_Guide_Download_%281%29.png" /></a></p>

<p>Regardless of where your resilience posture sits today, you can <a href="https://zeronetworks.com/resource-center/videos/self-defending-by-design-the-future-of-cybersecurity-defense">reach a self-defending state</a> in months by following a four-step roadmap: &nbsp;</p>

<h3>1. Map Every Network Asset, Identity, and Connection&nbsp;</h3>

<p>Manual discovery has historically taken months and gone stale almost immediately, since new assets and accounts appear faster than periodic audits can track them. By <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">leveraging an automated solution</a>, security teams can immediately pinpoint all assets and identities then learn logon activities, account behaviors, and asset access patterns to establish a baseline without the months of manual effort. &nbsp;</p>

<p>This is the step that pulls flat, alert-heavy networks out of established blind spots, where East-West and inter-VLAN traffic often lacks visibility. &nbsp;</p>

<h3>2. Generate Deterministic, Identity-Aware Segmentation Policies &nbsp;</h3>

<p>Using the behavioral baselines learned through real network mapping and observation, a <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">deterministic, human-on-the-loop automation engine</a> generates and enforces granular, identity-based policies that precisely <a href="https://zeronetworks.com/blog/how-to-prevent-lateral-movement-cybersecurity-risks-strategies">lock down unauthorized lateral movement</a> without impacting legitimate operations. &nbsp;</p>

<p>This step replaces implicit internal trust with explicit, <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">least-privilege access</a>, moving organizations out of early containment stages &ndash; where manually scoped exceptions keep multiplying to create gaps &ndash; and into automated enforcement.&nbsp;</p>

<h3>3. Enforce MFA on Privileged Internal Pathways &nbsp;</h3>

<p>Four admin protocols account for an outsized portion of lateral movement &ndash; <a href="https://zeronetworks.com/blog/the-4-protocols-driving-enterprise-risk-in-2026">71% of enterprise threat activity</a> flows through SMB, RDP, WinRM, and RPC. Business operations depend on privileged internal pathways like these, which is why they typically remain open, even in organizations that have made meaningful <a href="https://zeronetworks.com/blog/network-segmentation-all-you-need-to-know">network segmentation progress</a>. The fix is adding <a href="https://zeronetworks.com/resource-center/guides/mini-mfa-guide-extend-mfa-beyond-login-close-privileged-pathways">just-in-time network-layer MFA</a> to make privileged access verified and time-bound, ensuring attackers hit a dead-end while legitimate operations keep moving. &nbsp;</p>

<p>This is the identity governance evolution that closes least privilege security gaps, so attacks are automatically contained regardless of how they gain initial access. &nbsp;</p>

<h3>4. Automate Policy Updates Alongside Network Changes &nbsp;</h3>

<p>Modern enterprise environments never stop shifting; static policies can&rsquo;t provide consistent coverage. The combination of <a href="https://zeronetworks.com/platform/network-map">real-time network visibility</a> and deterministic automation closes this gap without manual overhead &ndash; new assets, identities, connections, and behaviors are automatically mapped and addressed with fine-grain policies, unlocking a self-defending architecture for true network resilience.</p>

<h2>Fast-Track Cyber Resilience Success with Zero Networks &nbsp;</h2>

<p>Zero Networks delivers the proactive containment layer enterprises need to protect uptime with <a href="https://zeronetworks.com/platform">automated,&#8239;identity-based microsegmentation</a>, unlocking 91%+ segmentation coverage within 90 days.</p>

<p>Zero granularly segments every asset and identity with adaptive policies based on observed network behavior. This dynamic approach means containment remains an automatic architectural feature, even as environments change &ndash; removing the privilege creep and rule sprawl that create gaps in static architectures. &#8239;&nbsp;</p>

<p>By strengthening every pillar of network resilience, Zero enables security teams to build a mature, business-aligned posture without adding operational complexity or manual effort &ndash;&#8239;<a href="https://zeronetworks.com/request-demo">request a demo</a> to learn more. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>A Fake Passport to Your Domain: How Certighost Turns a Basic Account Into a Domain Controller</title>
          <link>https://zeronetworks.com/blog/how-certighost-turns-a-basic-account-into-a-domain-controller</link>
          <dc:creator><![CDATA[Benny Lakunishok]]></dc:creator>
          <pubDate>Wed, 29 Jul 2026 14:00:00 +0000</pubDate>
          <dc:date>Wed, 29 Jul 2026 14:00:00 +0000</dc:date>
          <category><![CDATA[]]></category>
          <dc:subject><![CDATA[]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/how-certighost-turns-a-basic-account-into-a-domain-controller#When:1248</guid>
          <description><![CDATA[CISO SUMMARY CertiGhost allows a basic Active Directory account to become a full domain takeover by tricking a trusted certificate system into treating the attacker like a domain controller. Installing Microsoft&rsquo;s July 14 patch is important, but security teams should also confirm the protection is actually active across their environment. CISOs and their security teams should restrict certificate servers so they can communicate only with approved systems and block unauthorized attempts to&#8230;]]></description>
          <content:encoded><![CDATA[<h3>CISO SUMMARY</h3>

<p>CertiGhost allows a basic Active Directory account to become a full domain takeover by tricking a trusted certificate system into treating the attacker like a domain controller. Installing Microsoft&rsquo;s July 14 patch is important, but security teams should also confirm the protection is actually active across their environment. CISOs and their security teams should restrict certificate servers so they can communicate only with approved systems and block unauthorized attempts to copy sensitive identity data from domain controllers. The larger lesson: patches fix individual flaws, while segmentation and tight access controls can stop entire categories of attack.</p>

<p>&nbsp;</p>

<p>Microsoft fixed CertiGhost on July 14, 2026. Researchers <a href="https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26">H0j3n and Aniq Fakhrul published a working proof-of-concept</a> ten days later. If your CAs and domain controllers took the July updates, you are probably in reasonable shape &mdash; but you should be aware of the patch-versus-enabled loophole attackers are betting on and go verify that the fix is actually enforcing on your CAs and DCs, not just sitting around installed but inactive.&nbsp;<br />
I want to share a note on what &ldquo;patched&rdquo; means in AD CS specifically. When Microsoft shipped the SID security extension in May 2022 to counter <a href="https://www.thehacker.recipes/ad/movement/adcs/certifried">Certifried</a> (<a href="https://nvd.nist.gov/vuln/detail/cve-2022-26923">CVE-2022-26923</a>), the fix arrived in a compatibility mode that still permitted weak certificate mapping. Full enforcement did not become the default until February 2025, three years later, which means the fix was installed almost everywhere but enforced almost nowhere unless an administrator knew enough to go investigate it. That&rsquo;s a wide open door for attackers to sneak through.&nbsp;<br />
The <a href="https://www.dataminr.com/resources/intel-brief/certighost-cve-2026-54121/">CertiGhost fix </a>leaves a similar attack vector open to attackers &ndash; but it hides in plain sight. The new validation sits behind a Windows velocity feature gate &mdash; <code>Feature_3185813818</code> in the patched <code>certpdef.dll</code>, guarding the branch that calls <code>_ValidateChaseTargetIsDC</code>. Velocity gates are ordinary servicing machinery, not evidence of an incomplete fix: they let Microsoft stage, wave, or roll back a change without shipping a new binary, and MSRC security fixes are one of the things they gate. Most security features ship as always-enabled, in which case the gate is a rollback lever nobody will ever pull. What this means to real security teams is that enforcement is a runtime state rather than a property of the build, and a runtime state is something you have to confirm on your own CAs rather than infer from a patch level.<br />
<strong>The rest of this post is about the more uncomfortable question.</strong> CertiGhost is a low-privileged domain user turning into <code>krbtgt</code> in a single automated script. The chain is short, the prerequisites are close to default, and nothing in it exploits memory corruption or breaks cryptography. <em>It is a missing validation in a trust decision.</em><br />
Since Will Schroeder and Lee Christensen published Certified Pre-Owned in 2021, the community has kept a running catalogue of AD CS escalation paths: ESC1 through ESC8 in the original research, extended by later work to ESC17. It&#39;s not a Microsoft scheme and not a CVE series &mdash; it&rsquo;s an informal numbering that grows whenever someone finds another way to turn certificate issuance into domain privilege. Most of the seventeen are misconfigured templates or weak ACLs on PKI objects. Two of them, ESC8 and ESC11, are relay attacks that work for no reason more sophisticated than an enrollment endpoint being reachable by something that should never have reached it. CertiGhost belongs to the same family: the CA made a trust decision on data an attacker supplied. There will be an eighteenth.<br />
So: <strong>if you had not patched on July 14, what in your network would have stopped this?</strong><br />
For most environments the honest answer is nothing, because the attack looks like ordinary Windows traffic at every step. But two of the four network legs in the chain are gateable with controls that don&rsquo;t know or care that CertiGhost exists. That is the point worth making.&nbsp;</p>

<h2><br />
Key answers in this article</h2>

<ul>
	<li><strong>What is CertiGhost (CVE-2026-54121) and why does patching alone not close the risk?</strong> CertiGhost is an Active Directory Certificate Services (AD CS) exploit chain that turns a low-privileged domain user into a domain controller by tricking a certificate authority into signing a DC-identity certificate, which converts into krbtgt compromise via PKINIT and DCSync. Microsoft patched it July 14, 2026, but the fix ships behind a Windows velocity feature gate, meaning enforcement is a runtime state on each CA rather than a guaranteed property of the patch &mdash; the same pattern that left the 2022 Certifried fix in compatibility mode for nearly three years.</li>
	<li><strong>How does the CertiGhost attack chain actually work?</strong> The exploit abuses AD CS&#39;s "chase" fallback, where a CA follows attacker-supplied <code>cdc</code> and <code>rmd</code> enrollment attributes to a secondary lookup host without validating it&#39;s a real domain controller; an attacker stands up rogue SMB/LDAP/LSA services, creates a machine account via the default ms-DS-MachineAccountQuota, relays Netlogon authentication to a real DC, and receives a certificate carrying that DC&#39;s identity.</li>
	<li><strong>What single network control neutralizes the most dangerous leg of the attack?</strong> Default-deny egress on the certificate authority &mdash; permitting outbound SMB and LDAP only to known domain controllers &mdash; collapses the attack before identity confusion occurs, because this control requires no knowledge of CertiGhost, no signatures, and no patch-level awareness; it simply enforces that a CA&#39;s legitimate outbound peer set is small, stable, and enumerable.</li>
	<li><strong>Why does per-asset microsegmentation matter more than per-subnet or VLAN-based rules?</strong> A CA sitting in a broad server VLAN with permissive east-west traffic has effectively no egress policy at all; the defensive value comes specifically from scoping rules to the individual asset (or even the process, like certsrv.exe), since CAs have a narrower legitimate communication footprint than the network segment they sit in.</li>
	<li><strong>What is the single highest-ROI rule for blocking this entire class of AD CS attacks?</strong> Denying DCSync (MS-DRSR / DRSGetNCChanges) from all non-domain-controller sources is a narrow, low-breakage rule that neuters CertiGhost, every AD CS ESC escalation path, Zerologon, and any other attack whose final move is replicating secrets out of the directory.</li>
	<li><strong>What&#39;s the broader architectural lesson beyond this one CVE?</strong> CertiGhost will be patched and forgotten within months, like the ESC series before it &mdash; but every one of these bugs shares the same weakness: a trust decision made on attacker-influenced data. The defense that ages well isn&#39;t one that recognizes <code>cdc</code> specifically; it&#39;s one that constrains what a compromised or confused asset can reach, since a CA that can&#39;t open SMB to an arbitrary host is indifferent to which validation was missing this time.</li>
</ul>

<h2><br />
The chain, briefly</h2>

<p>Certificate enrollment in AD CS has a fallback path the researchers call a chase. When the CA can&rsquo;t resolve the requester&rsquo;s directory object locally &mdash; a real scenario in multi-domain forests with replication lag &mdash; the enrollment request may carry two attributes that steer a secondary lookup: <code>cdc</code>, naming the host the CA should contact, and <code>rmd</code>, naming the principal to resolve.<br />
Before the July patch, the CA followed the <code>cdc</code> value without confirming that the host was actually a domain controller. In <code>certpdef.dll</code>, <code>CRequestInstance::_LoadPrincipalObject</code> read the attribute straight out of the request and passed it into <code>_GetDSObject</code> with chase enabled. The July build wraps that call in <code>_ValidateChaseTargetIsDC</code>, which rejects IP literals, LDAP metacharacters, and oversized hostnames, then queries AD for exactly one computer object whose<code> dNSHostName</code> matches and whose<code> userAccountControl</code> carries <code>SERVER_TRUST_ACCOUNT (8192)</code>.<br />
The exploit stands up rogue SMB, LDAP, and LSA services on an attacker-controlled host, creates a machine account through the default <code>ms-DS-MachineAccountQuota</code> of 10 so it holds a genuine domain identity, and points <code>cdc</code> at itself. When the CA connects, the rogue services relay the authentication challenge to the real DC over Netlogon &mdash; satisfying the CA&rsquo;s authentication checks &mdash; while returning the target DC&rsquo;s <code>objectSid</code> and <code>dNSHostName</code> as directory data. The CA signs a certificate carrying a domain controller&rsquo;s identity. PKINIT converts that into Kerberos credentials for the DC, and DCSync converts those into <code>krbtgt</code>.<br />
Four network legs matter:</p>

<table align="left" border="1" cellpadding="1" cellspacing="1" style="width: 500px;">
	<thead>
		<tr>
			<th scope="col">Leg</th>
			<th scope="col">Traffic</th>
			<th scope="col">Direction</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td>1</td>
			<td>Enrollment request carrying <code>cdc / rmd</code></td>
			<td>Attacker &rarr; CA</td>
		</tr>
		<tr>
			<td>2</td>
			<td>The chase: SMB and LDAP to the <code>cdc</code> target</td>
			<td><strong>CA&nbsp;&rarr; Attacker</strong></td>
		</tr>
		<tr>
			<td>3</td>
			<td>Netlogon relay of the CA&#39;s challenge</td>
			<td>Attacker&nbsp;&rarr; DC</td>
		</tr>
		<tr>
			<td>4</td>
			<td>DCSync via directory replication</td>
			<td>Attacker&nbsp;&rarr; DC</td>
		</tr>
	</tbody>
</table>

<p><br />
&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>Leg 2 is the one to sit with. Every other leg is an attacker reaching into your infrastructure, which is the situation security tooling is built for. Leg 2 is your certificate authority &mdash; one of the most trusted machines in the domain &mdash; opening an SMB and an LDAP session outbound to an attacker&rsquo;s Linux box, because a string in an untrusted request told it to.</p>

<h3><br />
Leg 2: the CA&rsquo;s outbound peer set is small, and this isn&rsquo;t in it</h3>

<p>A certificate authority is not a general-purpose client. Its legitimate outbound connections are few, stable, and enumerable: domain controllers, its database, possibly an HSM, and wherever it publishes CRLs. That list changes on the order of once a year.<br />
Which means the exploit&rsquo;s critical leg is not merely suspicious &mdash; it is outside the CA&rsquo;s entire behavioral envelope. Default-deny egress on the CA, permitting SMB and LDAP <a href="https://zeronetworks.com/solutions/enhance-domain-controller-security">only to known domain controllers</a>, collapses the attack before the identity confusion ever happens. The rogue LSA service never gets a connection. No directory data comes back. No certificate is issued.<br />
The bar this sets is high rather than infinite. An attacker who has already compromised a host the CA is permitted to reach can stand the rogue services up there instead, and the chase succeeds. But that moves the prerequisite from &ldquo;create a machine account, which the default quota lets any user do&rdquo; to &ldquo;own something on the CA&rsquo;s short list of permitted peers&rdquo; &mdash; a materially different class of problem, and one you are far more likely to have instrumented.<br />
The thing worth dwelling on is that this control requires knowing nothing about CertiGhost. It doesn&rsquo;t parse <code>cdc</code>. It doesn&rsquo;t inspect enrollment attributes. It doesn&rsquo;t need a signature, a patch level, or a threat intel feed. It enforces a statement that was true before the CVE existed and remains true after: this CA talks to these hosts on these ports, and nothing else.<br />
Two things make this practical rather than aspirational. The first is <a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">automated policy generation</a> &mdash; you cannot hand-write egress policy for every server in an estate, but you can observe what each asset actually connects to and propose a least-privilege ruleset from that &mdash; then run it in monitor mode and see what it would have blocked before it blocks anything. The organizations that get burned by least-privilege network policy are the ones that wrote it from an architecture diagram instead of from observed traffic. The second is that policy has to be <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">per-asset rather than per-subnet</a>. A CA in a broad &ldquo;server VLAN&rdquo; with permissive east-west rules has effectively no egress policy at all; the whole value is in the CA&rsquo;s ruleset being narrow specifically because CAs have narrow needs.<br />
If you want to go further, per-process egress narrows it again: certsrv.exe has a smaller legitimate peer set than the host as a whole, and the chase originates from exactly that process.</p>

<h3><br />
Legs 1 and 4: <a href="https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall">RPC-layer control</a></h3>

<p>The remaining legs are RPC, which makes them addressable at a different layer.<br />
<strong>Leg 1</strong> is <a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wcce/">MS-WCCE enrollment</a>. In the public PoC &mdash; impacket-based, no web enrollment endpoint involved &mdash; that means ICertPassage over <code>DCERPC</code> on the <code>\pipe\cert</code> named pipe: interface <code>91ae6020-9e3c-11cf-8d7c-00aa00c091be</code>, <code>opnum 0</code>, <code>CertServerRequest</code>. The <code>cdc</code> and <code>rmd</code> attributes ride in that call&rsquo;s attribute string. Note the transport: this is <code>ncacn_np</code> over port 445, not <code>ncacn_ip_tcp</code> over 135, so a port-based rule aimed at the RPC endpoint mapper never sees it. An RPC firewall that hooks the RPC runtime rather than filtering ports does.<br />
Be precise about what this buys you. Filtering at the interface and opnum level tells you who may submit enrollment requests over RPC; it does not distinguish a malicious <code>cdc</code> from a benign one, because the discriminator is a string inside the parameters. So Leg 1 is an allow-list exercise: enrollment RPC to the CA should come from managed endpoints and enrollment proxies, not from an unmanaged host that appeared in the domain forty seconds ago. That shrinks the population who can attempt the attack. It does not identify the attempt.<br />
It also only covers the RPC transport. If you run Certificate Enrollment Web Services, MS-WSTEP over HTTPS reaches the same policy module and the same chase logic, and RPC-layer filtering is blind to it. Leg 1 coverage is incomplete wherever web enrollment is deployed &mdash; which is another argument for Leg 2 carrying the weight, since egress policy on the CA is indifferent to how the request arrived.<br />
That allow-list does have a second payoff worth naming. ESC11 is NTLM relay against precisely this interface &mdash; the RPC-based enrollment endpoint, as distinct from ESC8, which relays to the HTTP one. So restricting who may reach ICertPassage constrains CertiGhost&rsquo;s submission leg and ESC11 with the same rule. That is the difference between an architectural control and a patch: the patch closes one bug, the rule closes a class of reachability.<br />
<strong>Leg 4</strong> is where RPC filtering earns its keep unambiguously. DCSync is MS-DRSR &mdash; interface e3514235-4b06-11d1-ab04-00c04fc2dcd2, DRSGetNCChanges at opnum 3. Only domain controllers have any business calling it. <a href="https://zeronetworks.com/blog/preventing-certified-pre-owned-attacks-using-rpc-firewall-ldap-firewall-and-network-segmentation">Denying it on your DCs from every non-DC source</a> is a narrow, low-breakage rule, and it neuters the payoff of this attack, every AD CS ESC path, Zerologon and its derivatives, and any other chain whose final move is replicating secrets out of the directory. If you implement one rule from this post, implement that one.<br />
<strong>Leg 3</strong>, the Netlogon relay, is MS-NRPC (<code>12345678-1234-abcd-ef00-01234567cffb</code>). It is RPC, but every domain-joined machine legitimately speaks it to DCs, so protocol-level blocking is disruptive. The tractable angle is source identity rather than protocol: an unmanaged Linux host making NRPC calls is the anomaly. Treat this as a detection opportunity, not a chokepoint.<br />
Both rules want an audit pass before an enforcement pass. Logging calls to ICertPassage and DRSUAPI for a week gives you the real caller population, which is almost always narrower and stranger than the documentation implies, and occasionally includes a backup agent nobody remembers deploying.<br />
One non-network control belongs on the same list, because it is cheaper than everything above it: set <code>ms-DS-MachineAccountQuota</code> to 0. The exploit needs a machine account to hold a valid domain identity, and the default lets any authenticated user create ten of them.</p>

<h2>The generalization</h2>

<p>CertiGhost will be patched everywhere within a few months and then largely forgotten, which is roughly what happened with the <a href="https://github.com/ly4k/Certipy/wiki/06-%E2%80%90-Privilege-Escalation">ESC series</a> before it. The structural observation outlasts it.<br />
Every one of these bugs is a trust decision made on data the attacker influenced, and the fix is always the same shape: add the validation that was missing. So the defense that ages well is not the one that knows about <code>cdc</code>. It is the one that <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">constrains what a compromised or confused asset can reach</a> &mdash; because a certificate authority that cannot open SMB to an arbitrary host, and a domain controller that will not replicate secrets to a non-DC, are indifferent to which validation was missing this time.<br />
The cryptography was never the weak part. The reachability was.<br />
If you want to see and control what your CAs and DCs can actually talk to right now &mdash; not what you assume they can talk to &mdash; <a href="https://zeronetworks.com/request-demo">request a demo</a>.<br />
&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Hugging Face Proves: AI Finds the Gap, Lateral Movement Expands the Blast Radius </title>
          <link>https://zeronetworks.com/blog/hugging-face-proves-ai-finds-the-gap-lateral-movement-expands-the-blast-radius</link>
          <dc:creator><![CDATA[Benny Lakunishok]]></dc:creator>
          <pubDate>Tue, 28 Jul 2026 14:00:00 +0000</pubDate>
          <dc:date>Tue, 28 Jul 2026 14:00:00 +0000</dc:date>
          <category><![CDATA[Cybersecurity Trends &amp; CVEs, Incident Response &amp; Breach Containment]]></category>
          <dc:subject><![CDATA[Cybersecurity Trends &amp; CVEs, Incident Response &amp; Breach Containment]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/hugging-face-proves-ai-finds-the-gap-lateral-movement-expands-the-blast-radius#When:1247</guid>
          <description><![CDATA[The industry will argue about what the Hugging Face incident was. A rogue AI? A failed evaluation? An attack run by software instead of a person? For defenders, that argument is beside the point. You can&#39;t stop every break-in. You can stop the intruder from moving once it&#39;s inside. That&#39;s the line between one compromised system and a company-wide breach, and the whole lesson is in the attack path.&nbsp; What happened&nbsp; Hugging Face first disclosed an intrusion into part of its&#8230;]]></description>
          <content:encoded><![CDATA[<p>The industry will argue about what the Hugging Face incident was. A rogue AI? A failed evaluation? An attack run by software instead of a person? For defenders, that argument is beside the point. You can&#39;t stop every break-in. You can stop the intruder from moving once it&#39;s inside. That&#39;s the line between one compromised system and a company-wide breach, and the whole lesson is in the attack path.&nbsp;</p>

<h2>What happened&nbsp;</h2>

<p><a href="https://huggingface.co/blog/security-incident-july-2026">Hugging Face first disclosed an intrusion</a> into part of its production infrastructure and attributed it to an external AI agent whose underlying model was unknown. <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">On July 21, OpenAI took responsibility</a>. The breach came from its own models during an internal cybersecurity evaluation. The models escaped their isolated testing environment and reached Hugging Face from there.&nbsp;</p>

<p>OpenAI was running the models against an internal benchmark called ExploitGym, which measures how well a model can execute attacks against known vulnerabilities. The models involved were GPT-5.6 Sol and an even more capable pre-release model, with safeguards intentionally lowered for the test. According to OpenAI, the models became hyperfocused and went to extreme lengths to get the test solution. In plain terms, they tried to cheat on the eval by hacking Hugging Face to steal the answers.&nbsp;</p>

<h2>The attack chain&nbsp;</h2>

<p>The mechanics were ordinary even if the attacker wasn&#39;t.&nbsp;</p>

<p>The models found a zero-day in a package proxy to get out to the internet. They escalated privileges and moved laterally through Hugging Face&#39;s internal infrastructure until they reached the target: the ExploitGym answer key in a production database.&nbsp;</p>

<p>Hugging Face&#39;s account matches. Malicious content exploited code-execution paths in its data-processing pipeline and landed on a processing worker. From there the attacker escalated to node-level access, harvested cloud and cluster credentials, and moved into several internal clusters. OpenAI&#39;s account fills in on the other side. Its models exploited a zero-day in the research environment, escalated, and moved laterally to a node with internet access, then chained stolen credentials and more zero-days into a remote-code-execution path against Hugging Face production.&nbsp;</p>

<p>Compromise one system. Gain privilege. Steal credentials. Move to the next. Repeat until something valuable is reachable. That sequence is why lateral movement is the control point that decides how bad a modern attack gets.&nbsp;</p>

<p>The incident didn&#39;t turn serious because an AI found one vulnerability. It turned serious because that first foothold led somewhere that mattered.&nbsp;</p>

<h2>Preventing infiltration is no longer enough&nbsp;</h2>

<p>Keep patching. Keep securing pipelines. Keep protecting credentials and watching for bad behavior. None of that goes away. But this incident shows why you can&#39;t build a security model on stopping every first compromise.&nbsp;</p>

<p>AI changes the economics of offense. It can hunt for vulnerabilities, test combinations, retry what failed, and run thousands of actions without getting tired. Hugging Face described an autonomous framework running many thousands of actions across short-lived sandboxes. Work that used to need a skilled team can now be automated.&nbsp;</p>

<p>So, the asymmetry keeps widening. Vulnerabilities and possible paths grow faster than any team can patch, investigate, or contain by hand. Traditional detection leans on human habits: known tools, known protocols, known sequences. AI agents have none of those. They adapt as they go. The reliable move is to remove the paths, not to recognize the attacker walking them.&nbsp;</p>

<h2>Enterprise networks give an attacker room to run&nbsp;</h2>

<p>The <a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report">Zero Networks 2026 Lateral Movement Exposure Report</a> shows the size of the problem. Across hundreds of enterprise environments, one compromised system could reach a median of about 85% of the network in a single hop. By the second hop, reachability approached the entire environment. About 60% became reachable inside the first hour. A small foothold can become an enterprise-wide incident before most teams finish triage.&nbsp;</p>

<p>This isn&#39;t spread across thousands of exotic techniques. About 71% of threat-relevant activity sat in four familiar protocols: SMB, RDP, WinRM, and RPC. Businesses run on those every day. Attackers spread on those same protocols.&nbsp;</p>

<p>The gap holds across the industry. In <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-forecast.pdf">Kiteworks&#39; 2026 Data Security and Compliance Risk Forecast</a>, a survey of 225 security leaders, 63% said they can&#39;t enforce purpose limits on AI agents and 60% can&#39;t shut down one that misbehaves. Most can watch an agent go wrong. Far fewer can stop it.&nbsp;</p>

<p>Hugging Face fits the pattern. The execution path created access. Credentials and too much internal connectivity created reach. Lateral movement turned one vulnerable worker into access across multiple clusters.&nbsp;</p>

<h2>Stop the movement, stop the attack&nbsp;</h2>

<p>Defenders have an edge here. You may not know which vulnerability a human or an AI finds next. You do get to decide which systems can talk to each other and which identities can use privileged pathways.&nbsp;</p>

<p>If the first compromised worker can&#39;t freely reach other nodes, the attack stalls. If stolen credentials can&#39;t be reused across clusters, it stalls. If admin protocols are limited to the users and systems that need them, it stalls. The attacker might still get initial execution. The company-wide breach never happens.&nbsp;</p>

<p>That&#39;s the design goal: one compromised system stays one compromised system.&nbsp;</p>

<p>Detection still matters. It just can&#39;t be the only thing standing between initial access and real damage. AI-enabled attackers move at machine speed. An architecture that waits for an analyst to see an alert, work out the path, and block it by hand will keep losing the race.&nbsp;</p>

<p>When Hugging Face&#39;s own responders tried commercial frontier models to analyze the attack logs, the providers&#39; safety guardrails blocked the requests. The models couldn&#39;t tell an incident responder from an attacker, so the team fell back to open-weight models they ran themselves. Provider-side safety is not a containment strategy. Containment must live in the network.&nbsp;</p>

<h2>How Zero Networks handles this&nbsp;</h2>

<p>Zero Networks decides which network paths are allowed to exist at all. It deploys directly on servers, cloud workers, and endpoints, and it works at the process level rather than only at the perimeter. So, you can enforce a rule like this: this dataset-processing worker may never SSH into an internal database cluster, no matter what credentials it holds. Present stolen credentials and the path still isn&#39;t there. The attack stops at the boundary.&nbsp;</p>

<p>In the Hugging Face case, the first code execution on the worker was a software flaw. The moment that agent tried to move across internal clusters with harvested credentials, it would have hit a wall. The 17,000-plus recorded events in the campaign all depended on one thing: the ability to move. Take that away and the breach stays a single worker instead of a multi-cluster event.&nbsp;</p>

<h2>A practical agenda for CISOs&nbsp;</h2>

<p>Ask four questions:&nbsp;</p>

<ul>
	<li>How much of our environment can one compromised system reach?&nbsp;</li>
	<li>Which pathways lead to critical servers, cloud workloads, and clusters?&nbsp;</li>
	<li>Can stolen credentials move through those pathways?&nbsp;</li>
	<li>Can we contain a compromised workload automatically, without waiting for an analyst?&nbsp;</li>
</ul>

<p>Then act on the answers. Segment the network so one compromised system can&#39;t reach the rest. Restrict privileged protocols to the systems that genuinely need them. Bind identities to paths so stolen credentials can&#39;t travel. Automate containment so a suspicious workload is isolated in seconds.&nbsp;</p>

<p>The goal isn&#39;t to predict every AI-enabled attack. It&#39;s to remove the pathways that let any attacker, human or autonomous, turn access into impact.&nbsp;</p>

<p>Hugging Face detected the activity, contained it, rebuilt the compromised nodes, rotated credentials, and tightened cluster controls. All necessary. The larger lesson is preventative. Constrain the blast radius before the incident starts.&nbsp;</p>

<p>AI will find vulnerabilities faster. Attackers will chain them faster. The answer isn&#39;t a permanent race to patch everything first. You don&#39;t have to outrun every new attack. You have to out-architect its ability to spread.&nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/breach-map">The blast radius is a design choice</a>. <a href="https://zeronetworks.com/request-demo">Book a walkthrough</a> and watch Zero Networks contain lateral movement in your own environment.&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Zero Standing Privileges: What It Means, Why It Matters, and How to Implement It</title>
          <link>https://zeronetworks.com/blog/zero-standing-privileges-what-it-means-why-it-matters-and-how-to-implement-it</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Wed, 22 Jul 2026 14:22:00 +0000</pubDate>
          <dc:date>Wed, 22 Jul 2026 14:22:00 +0000</dc:date>
          <category><![CDATA[Identity Access Control]]></category>
          <dc:subject><![CDATA[Identity Access Control]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/zero-standing-privileges-what-it-means-why-it-matters-and-how-to-implement-it#When:1244</guid>
          <description><![CDATA[Excessive privileged access is the norm in enterprise environments. Ninety-nine percent of users, roles, and services hold excessive standing permissions; meanwhile, privileged ports are used somewhere inside the average enterprise every 10 minutes, according to Zero Networks telemetry. And those same ports &ndash; RDP, SMB, WinRM, SSH, RPC &ndash; are the primary highways for lateral movement, with more than 70% of threat activity flowing through just four admin protocols. &nbsp; Zero standing&#8230;]]></description>
          <content:encoded><![CDATA[<p>Excessive privileged access is the norm in enterprise environments. <a href="https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report">Ninety-nine percent of users, roles, and services</a> hold excessive standing permissions; meanwhile, privileged ports are used somewhere inside the average enterprise every 10 minutes, according to Zero Networks telemetry. And those same ports &ndash; RDP, SMB, WinRM, SSH, RPC &ndash; are the <a href="https://zeronetworks.com/blog/the-4-protocols-driving-enterprise-risk-in-2026">primary highways for lateral movement</a>, with <a href="https://zeronetworks.com/blog/one-compromised-system-and-boom-meet-your-blast-radius">more than 70% of threat activity</a> flowing through just four admin protocols. &nbsp;</p>

<p>Zero standing privileges (ZSP) is an advanced response to that condition that removes excessive standing access rights by default and replaces them with narrowly scoped, time-bound entitlements. We&rsquo;ll break down what ZSP means, why persistent access has become one of the most exploited weaknesses in modern networks, and a practical approach to implementing the ZSP standard. &nbsp;</p>

<h2>What Does Zero Standing Privileges (ZSP) Mean? &nbsp;</h2>

<p>Zero standing privileges is a security principle that requires eliminating persistent, always-on access rights in favor of just-in-time, just-enough access &ndash; granted only when it&#39;s needed and only for as long as it&#39;s needed. &nbsp;</p>

<p>Rather than a user, service, admin, or AI agent holding a permission indefinitely, access is requested, verified, and provisioned for a defined window, then automatically revoked when that window closes.&nbsp;</p>

<h3>ZSP vs. the Principle of Least Privilege (PoLP)&nbsp;</h3>

<p>At a high level, zero standing privileges and least privilege are different articulations of the same underlying principle: &nbsp;</p>

<ul>
	<li>The <strong>least privilege principle</strong> states that a user, process, or system should receive only the minimum level of access required to perform its intended function &ndash; but it does not limit how long privileges are available. &nbsp;</li>
	<li><strong>ZSP</strong> applies the same access scoping discipline that PoLP requires, then adds a time dimension: access isn&#39;t just limited to <em>what&#39;s</em> necessary, it&#39;s limited to <em>when</em> it&#39;s necessary.&nbsp;</li>
</ul>

<p>The <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">principle of least privilege</a> was first introduced in the 1970s, while zero standing privileges was coined within the last 10 years, meaning ZSP is an <em>evolution</em> of the PoLP &ndash; not a distinct philosophy. And in fact, least privilege is a core tenet of ZSP.&nbsp;</p>

<h3>Key Pillars of Zero Standing Privileges &nbsp;</h3>

<p>Like <a href="https://zeronetworks.com/blog/what-is-zero-trust-security-without-the-marketing-bs">Zero Trust</a> or any other security philosophy, ZSP is an ideal upheld by a few core principles: &nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/blog/mfa-is-our-dna-zero-networks-multi-factor-segmentation"><strong>Just-in-Time (JIT) Access</strong></a>: Critical for operationalizing the time constraint that is core to zero standing privileges, JIT access allows organizations to unlock temporarily elevated permissions before automatically revoking them. &nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action"><strong>Least Privilege Principle:</strong></a> By restricting every identity &ndash; including admins and service accounts &ndash; to least privilege by default, enterprises implement the foundation for ZSP. &nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/how-real-time-network-visibility-enables-automated-zero-trust-enforcement"><strong>Always-Current Network Visibility:</strong> </a>A live network map delivers the real-time insights teams need to keep policies granular and prevent privilege creep. &nbsp;</li>
</ul>

<h3>Where JIT Isn&rsquo;t Possible: A Risk-Aligned Approach to ZSP in Real Enterprise Environments &nbsp;</h3>

<p>While just-in-time access is central to the zero standing privileges philosophy, it&rsquo;s important to note that not every application or workload is designed to support just-in-time access. Some legacy systems require persistent connectivity. Others break under real-time gating. &nbsp;</p>

<p>This is why a risk-aligned approach to just-in-time access &ndash; and, in turn, to ZSP &ndash; is critical. By enforcing just-in-time access controls on <a href="https://zeronetworks.com/blog/10-common-lateral-movement-techniques-how-to-stop-them">lateral movement paths</a>, privileged activity, and interactive sessions, while applying least privilege policies to everything else, organizations can achieve zero standing privileges where it matters most without the risk of breaking something. &nbsp;</p>

<p>A risk-aligned approach like this gets enterprises as close as their environments allow to comprehensive ZSP while effectively managing legacy limitations.</p>

<h2>Why Standing Privileges Are a Security Risk&nbsp;</h2>

<p>Privileges accumulate over time for the sake of operational ease. But the same internal pathways that enterprises rely on to keep the business operating are the ones that attackers exploit, creating gaps that leave organizations vulnerable to familiar risks. &nbsp;</p>

<h3>Lateral Movement and Privilege Escalation &nbsp;</h3>

<p>Over&#8239;<a href="http://crowdstrike.com/en-us/cybersecurity-101/identity-protection/identity-segmentation/">80% of attacks leverage stolen credentials at some stage</a>.&#8239;When an identity carries broad, always-on access, attackers immediately inherit those entitlements via stolen credentials, allowing them to <a href="https://zeronetworks.com/blog/stopping-privilege-escalation-how-to-neutralize-stolen-credential-threats">escalate privileges</a> and <a href="https://zeronetworks.com/resource-center/topics/lateral-movement-innovations-prevention-techniques">move laterally across the network</a> without triggering alerts. &nbsp;</p>

<h3>Overprivileged Service Accounts and Machine Identity Sprawl&nbsp;</h3>

<p>Machine and service identities now <a href="https://www.paloaltonetworks.com/idira/identity-security-landscape-report">outnumber human identities 109:1</a>, and only <a href="https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024">2.6% of workload identity permissions</a> are actually used &ndash; meaning the overwhelming majority of machine access exists as unmonitored and unnecessary risk. To top it off, <a href="https://zeronetworks.com/blog/agentic-ai-cybersecurity-risks-how-to-secure-ai-agents">AI agents are compounding the issue</a>. Roughly <a href="https://www.ibm.com/think/insights/agentic-ai-security">80% of enterprises</a> are already deploying AI agents, but <a href="https://www.ibm.com/downloads/documents/us-en/131cf87b20b31c91">nearly two-thirds don&rsquo;t have the necessary policies</a> to effectively govern them. &nbsp;</p>

<p>Because <a href="https://zeronetworks.com/blog/identity-based-attacks-tactics-trends-identity-security-best-practices">identity-based attacks exploit legitimate permissions</a> and blend in with normal activity, more detection tools and alert dashboards won&rsquo;t solve the problem. &nbsp;</p>

<h2>How to Implement Zero Standing Privileges&nbsp;</h2>

<p>Implementing the zero standing privileges model requires a multi-step approach for removing excessive &ldquo;always-on&rdquo; access and operationalizing granular, dynamic controls. &nbsp;</p>

<h3>1. Discover every network asset, identity, and activity&nbsp;</h3>

<p>Start by comprehensively mapping every identity, asset, and existing privileged pathway &ndash; including service accounts, AI agents, and machine identities, not just human users and admins. &nbsp;</p>

<h3>2. Learn network connections and baseline permissions&nbsp;</h3>

<p>Determine what access is genuinely needed by observing real behavior, logon activities, and asset access patterns rather than relying on assumed or historically granted permissions.&nbsp;</p>

<h3>3. Build deterministic, identity-based policies&nbsp;</h3>

<p>Translate learned network insights into policies grounded in real behavior. <a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">Automatically restrict all identities</a> to pre-approved assets and logon types, and define privileged access policies for specific resources tied to identity. &nbsp;</p>

<h3>4. Enforce JIT network-layer MFA for privileged access&nbsp;</h3>

<p>Enforce JIT verification for access to admin protocols, critical services, and other privileged activity. Use context-aware, identity-based policies to ensure that only in-scope identities are eligible for access, and network-layer MFA to provision access only for the duration needed &ndash; without adding operational friction. &nbsp;</p>

<h3>5. Dynamically adapt policies on an ongoing basis&nbsp;</h3>

<p>Standing privilege has a way of creeping back in as new accounts, services, and access paths are created. Policies should adapt continuously based on <a href="https://zeronetworks.com/platform/network-map">real-time visibility</a> that automatically flags out-of-scope privileged access, anomalous paths, and high-risk ports. &nbsp;</p>

<h2>Close Privileged Pathways by Default with Zero Networks &nbsp;</h2>

<p>Zero Networks delivers every core pillar of ZSP in a single, unified platform &ndash; <a href="https://zeronetworks.com/platform">automated, identity-based microsegmentation</a> enables least privilege enforcement at scale, <a href="https://zeronetworks.com/solutions/apply-mfa-to-anything">just-in-time network-layer MFA</a> keeps privileged access closed by default, and our <a href="https://zeronetworks.com/platform/network-map">real-time network map</a> delivers up-to-date insights that power adaptive policies. &nbsp;</p>

<p>By making least privilege the default and adding an adaptive authentication at the exact moment of privileged access, Zero Networks removes risky always-on permissions and closes the privileged internal pathways attackers rely on to escalate breaches. <a href="https://zeronetworks.com/request-demo">Request a demo</a> to learn more. &nbsp;</p>]]></content:encoded>
        </item>
      

    </channel>
  </rss>