<?xml version="1.0" encoding="UTF-8"?>
  <rss version="2.0"
    xmlns:dc="https://purl.org/dc/elements/1.1/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="https://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="https://purl.org/rss/1.0/modules/content/"
    xmlns:atom="http://www.w3.org/2005/Atom">

    <channel>
      <title>Zero Networks</title>
      <link>https://zeronetworks.com/blog</link>
      <atom:link href="https://zeronetworks.com/feed" rel="self" type="application/rss+xml" />
      <description>Unified network security platform for microsegmentation and advanced ZTNA.</description>
      <dc:language>en</dc:language>
      <dc:creator>info@zeronetworks.com</dc:creator>
      <dc:rights>Copyright 2026</dc:rights>
      <dc:date>2026-08-01T13:43:00+00:00</dc:date>
      <admin:generatorAgent rdf:resource="https://expressionengine.com/" />

      <image>
        <url>https://zeronetworks.com/images/uploads/site-assets/zer0-rss-image.png</url>
        <title>Zero Networks</title>
        <link>https://zeronetworks.com/blog</link>
        <width>142</width>
        <height>161</height>
      </image>

      
        <item>
          <title>Attack Path Analysis for Business Resilience: Mapping Cyber Risk Exposure </title>
          <link>https://zeronetworks.com/blog/attack-path-analysis-for-business-resilience-mapping-cyber-risk-exposure</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Sat, 01 Aug 2026 13:43:00 +0000</pubDate>
          <dc:date>Sat, 01 Aug 2026 13:43:00 +0000</dc:date>
          <category><![CDATA[Operational &amp; Cyber Resilience]]></category>
          <dc:subject><![CDATA[Operational &amp; Cyber Resilience]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/attack-path-analysis-for-business-resilience-mapping-cyber-risk-exposure#When:1254</guid>
          <description><![CDATA[In most enterprises, a single compromised endpoint directly exposes 85% of the environment. In fact, Zero Networks&#39; 2026 Lateral Movement Exposure Report found that 12.2% of enterprise environments expose at least one user-to-server administrative pathway &ndash; a direct route from compromised endpoint to crown jewels. &nbsp; While most businesses know what their critical assets are, far fewer have a clear understanding of their true cyber risk exposure &ndash; or what to do about it. This&#8230;]]></description>
          <content:encoded><![CDATA[<p>In most enterprises, a single compromised endpoint <a href="https://zeronetworks.com/blog/one-compromised-system-and-boom-meet-your-blast-radius">directly exposes 85% of the environment</a>. In fact, <a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report">Zero Networks&#39; 2026 Lateral Movement Exposure Report</a> found that 12.2% of enterprise environments expose at least one user-to-server administrative pathway &ndash; a direct route from compromised endpoint to crown jewels. &nbsp;</p>

<p>While most businesses know <em>what</em> their critical assets are, far fewer have a clear understanding of their true cyber risk exposure &ndash; or what to do about it. This is especially true for cyber pros watching AI proliferate in the wild and within their networks; most organizations are still working to understand external and internal AI threat exposure, let alone forge a path to <a href="https://zeronetworks.com/platform/ai-capabilities">AI control</a>. We&rsquo;ll lay out a framework for <a href="https://zeronetworks.com/blog/cisos-guide-to-business-impact-analysis-3-steps-to-strengthen-cyber-resilience">analyzing attack paths as part of a business impact analysis</a>, enabling security leaders to build a cyber resilience strategy that directly maps to business outcomes. &nbsp;</p>

<h3>Key Answers&nbsp;</h3>

<ul>
	<li><strong>How does attack path analysis work? </strong>An attack path analysis traces the route an attacker could take from an initial point of compromise to a critical asset and measures the controls that stand in the way to uncover the true scope of exposure. This can be completed as a phased process (involving discovery, modeling, and pathfinding), or automated using free resources like Zero Networks&rsquo; <a href="https://zeronetworks.com/resource-center/breach-map">Breach Map</a> tool. &nbsp;</li>
	<li><strong>What is the role of an attack path analysis in a business impact analysis (BIA)? </strong>A BIA identifies which assets are critical and what downtime would cost; attack path analysis clarifies how exposed those critical assets are and identifies priority interventions for security leaders targeting cyber resilience objectives. &nbsp;&nbsp;</li>
	<li><strong>How should enterprises prioritize business resilience investments? </strong>By identifying the attack paths with the highest business impact relative to containment readiness, then implementing controls that increase path distance or eliminate entire attack scenarios (like <a href="https://zeronetworks.com/platform/network-segmentation">microsegmentation</a>), minimize privilege exposure (<a href="https://zeronetworks.com/use-cases/apply-mfa-to-anything">just-in-time authentication</a>), and constrain potential damage to key resources (<a href="https://zeronetworks.com/platform/identity-segmentation">identity-based access controls</a>).&nbsp;</li>
</ul>

<p><a href="https://zeronetworks.com/resource-center/guides/ciso-guide-business-impact-analysis-for-cyber-resilience"><img alt="" src="https://zeronetworks.com/images/uploads/blog/BIA_Guide_Download_%281%29.png" /></a></p>

<h2>What is Attack Path Analysis? &nbsp;</h2>

<p>An attack path analysis identifies the route an attacker could take from an initial point of compromise to a critical asset, translating unstructured risk exposure insights into a view of real, exploitable paths. &nbsp;</p>

<p>In the context of a business impact analysis (BIA), attack path analysis shouldn&rsquo;t only identify exploitable attack paths to critical assets specifically but should also uncover the interventions that will most meaningfully improve cyber and operational resilience.&nbsp;</p>

<h3>How to Use Attack Path Analysis in a BIA&nbsp;</h3>

<p>A business impact analysis starts with identifying which systems and assets are critical to the strategic success and day-to-day operations of the company. Documenting critical assets &ndash; and establishing a baseline estimate of what downtime would cost &ndash; is the first step in tailoring cyber resilience strategies to business priorities. An attack path analysis answers the logical follow-up question: <em>how exposed are critical assets?</em> &nbsp;</p>

<p>To uncover the scope of business exposure, attack path analysis maps open pathways and evaluates the level of effort it would take an attacker to move from a common ingress point to a critical asset, giving organizations a documented map of true exposure tied to likely attack tactics rather than a general sense of risk. &nbsp;</p>

<p>A list of critical assets tells you what&rsquo;s important, not where to act first. A <a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">cyber resilience</a> focused attack path analysis turns that list into a prioritized map of where risk exposure and business impact intersect most sharply.&nbsp;</p>

<h3>Attack Path vs. Attack Vector vs. Attack Surface &nbsp;</h3>

<p>Security teams will deal with three related yet distinct terms when mapping and evaluating attack paths as part of a BIA: &nbsp;</p>

<ul>
	<li><strong>Attack surface</strong> is the sum of all points in your environment where an attacker could potentially gain entry or exploit a vulnerability &ndash; every exposed port, every identity, every endpoint, every cloud workload, and every third-party integration. The larger and more complex your environment, the broader your attack surface. &nbsp;</li>
	<li>An <strong>attack vector</strong> is the specific method an attacker uses to exploit a point in the attack surface and gain an initial foothold. For example, compromised credentials or vulnerability exploitation are common attack vectors. &nbsp;</li>
	<li>An <strong>attack path</strong> is the route an attacker travels along through the environment after gaining initial access to reach critical assets &ndash; the amount of damage they could do along the way makes up an organization&rsquo;s <a href="https://zeronetworks.com/blog/what-is-blast-radius-in-cybersecurity-best-practices-for-breach-containment">blast radius</a>. &nbsp;</li>
</ul>

<p>In other words, attack surface describes <em>what</em> can be breached, an attack vector is <em>how</em> breaches can occur, and attack paths illustrate <em>where</em> adversaries can go after gaining initial access to eventually reach critical systems. &nbsp;</p>

<h2>4 Attack Vectors to Map for Every Critical Asset &nbsp;</h2>

<p>Starting with the most business-critical assets, security teams should analyze attack paths using scenarios that reflect today&#39;s threat landscape:&nbsp;</p>

<ul>
	<li><strong>Compromised user:</strong> A standard user account compromised through phishing, credential theft, or malware. &nbsp;</li>
	<li><strong>Compromised cloud identity or AI agent:</strong> Stolen credentials or session tokens for a SaaS, IaaS, or agentic identity, often exploited to pivot into on-premises resources through federation, single sign-on trust relationships, or an AI agent&rsquo;s standing access.&nbsp;</li>
	<li><strong>Technical perimeter entry: </strong>Exploitation of an internet-facing device or service, such as a VPN concentrator, edge firewall, or public-facing web application, to gain code execution and a foothold for further lateral movement.&nbsp;</li>
	<li><strong>Trusted vendor/third-party access: </strong>A compromised or malicious third party using pre-existing privileged access, like a vendor VPN connection or API integration, to reach internal systems.&nbsp;</li>
</ul>

<p>For each critical asset, trace the shortest plausible path per vector. &nbsp;</p>

<h2>How to Map Attack Paths: Discovery, Modeling, and Pathfinding &nbsp;</h2>

<p>With critical assets and relevant attack vectors identified, security teams can begin mapping the attack paths they&rsquo;ll use to analyze exposure &ndash; when done manually, this typically happens in three stages: &nbsp;&nbsp;</p>

<h3>1. Discovery: Inventory Systems, Identities, and Connections&nbsp;</h3>

<p>Uncovering attack paths starts with an accurate view of all network assets, identities, connections &ndash; including service accounts, AI agents, and other traditionally under-monitored parts of the network &ndash; to effectively track how they might contribute to an exploitable pathway between a given entry point and a critical asset. &nbsp;</p>

<h3>2. Modeling: Uncover Communication Pathways &nbsp;</h3>

<p>Convert discovered inventory into a graphical view of what&rsquo;s reachable across on-prem, cloud, IoT/OT, and Kubernetes: which systems and identities can access which assets, through what trust relationships, and whether or not that access shows up in routine traffic.&nbsp;</p>

<p><a href="https://zeronetworks.com/platform/network-map"><img alt="" src="https://zeronetworks.com/images/uploads/platform/network-map.png" /></a></p>

<h3>3. Pathfinding: Chain Exploitable Steps Together &nbsp;</h3>

<p>Starting from a pre-defined entry point, trace the routes an attacker could exploit, including paths gated behind authentication or JIT approval, that lead to a critical asset. At enterprise scale, this usually requires graph traversal algorithms to enumerate every path reachable from an entry point to a given asset. &nbsp;</p>

<h3>Automated Attack Path Mapping &nbsp;</h3>

<p>For enterprises that need an accurate view of exposure without months of manual background work, <strong>free tools like <a href="https://zeronetworks.com/resource-center/breach-map">Zero Networks&rsquo; Breach Map</a> automate all three stages</strong>. Breach Map scans the internal network to discover reachable assets, then generates an interactive visual map showing how assets connect, where attackers would move, and what they could reach.&nbsp;</p>

<p>The report surfaces total assets discovered, how many are reachable via <a href="https://zeronetworks.com/resource-center/topics/lateral-movement-innovations-prevention-techniques">lateral movement</a>, average blast radius, attack surface, and direct and indirect crown jewel risk &ndash; without weeks of manual discovery and log analysis. It also acts as a personalized benchmark tool for cyber leaders and teams as they work to lock down key attack paths.&nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/breach-map"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Breach_Map_Download_%281%29.png" /></a></p>

<h2>Analyzing Attack Paths: How to Measure Cyber Risk Exposure &nbsp;</h2>

<p>After mapping attack paths from entry point to critical asset, security teams can analyze paths against three threat containment metrics that signal the true scope of exposure. &nbsp;</p>

<table aria-colcount="3" aria-rowcount="4" border="1" data-tablelook="1184" data-tablestyle="MsoTableGrid" dir="ltr">
	<tbody>
		<tr aria-rowindex="1" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{97}" paraid="1016149204">Metric&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{100}" paraid="698644804">What It Measures&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{103}" paraid="634187209">What to Document&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="2" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{107}" paraid="620218349">Path Distance&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{110}" paraid="1354600770">Barriers between entry point and asset&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{113}" paraid="326793659">Authentication boundaries, segments traversed, inspection points, cross-domain crossings&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="3" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{117}" paraid="24774712">Privilege Requirements&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{120}" paraid="1100608008">Difficulty of gaining usable access&nbsp;to&nbsp;a resource&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{123}" paraid="1239876802">Escalation levels,&nbsp;persistent privileged&nbsp;access, service account density, added authentication&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="4" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{127}" paraid="1124037019">Data-Layer Controls&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{130}" paraid="1555440773">How much damage an attacker could do upon reaching a critical asset&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{565d28b3-b289-45c4-b334-82a3fe29da82}{133}" paraid="1386470056">Encryption at rest, identity-based access controls&nbsp;</p>
			</td>
		</tr>
	</tbody>
</table>

<h3>Path Distance: How Attackers Move Laterally Through the Network&nbsp;</h3>

<p>Path distance is the most consequential dimension to measure, because interventions here can remove risk rather than just raising its cost. For example, <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">microsegmentation</a> can close lateral movement pathways and effectively eliminate entire compromise scenarios. For the purposes of measuring containment, focus on assessing four things: &nbsp;&nbsp;</p>

<ul>
	<li><strong>Authentication boundaries crossed</strong>: Distinct credential challenges between entry point and asset, excluding any boundary satisfied by credentials the attacker already holds.&nbsp;</li>
	<li><strong>Network segments traversed</strong>: Segments governed by actively enforced, granular policy &ndash; not segmentation that exists on paper but permits broad access in practice due to accumulated exceptions and policy drift.&nbsp;</li>
	<li><strong>Enforced inspection points in path</strong>: Tools actively operating in prevention mode; detection-only controls don&#39;t count, since they depend on a human responding in time.&nbsp;</li>
	<li><strong>Cross-domain traversal</strong>: Genuine trust boundary crossings, like on-prem to cloud or IT to OT, that demand a distinct credential set rather than one satisfied by shared federation.&nbsp;</li>
</ul>

<h3>Privilege Requirements: What Permissions Attackers Need to Access Critical Assets &nbsp;</h3>

<p><em>Reaching</em> an asset isn&#39;t the same as <em>accessing</em> it. Privilege requirements measure how difficult it is for an attacker to obtain the privileges needed to actually impact a critical asset. As a measure of containment, this dimension carries less weight than path distance because privilege controls typically raise the cost of an attack (rather than removing the route entirely via structural controls), but the two are deeply interconnected. Privilege requirements should be captured through details like: &nbsp;</p>

<ul>
	<li><strong>Escalation levels required</strong>: Each distinct privilege escalation is a separate point of potential failure for attackers, though shortcuts like cached credentials or over-provisioned service accounts can collapse multiple levels into one.&nbsp;</li>
	<li><strong>Persistent privileged access</strong>: Standing access without just-in-time reauthentication means a single compromised credential can be a ticket to critical assets on its own.&nbsp;</li>
	<li><strong>Service account density</strong>: Broadly scoped service accounts are frequent escalation targets and are often excluded from user activity monitoring.&nbsp;</li>
</ul>

<p>Additional authentication requirements: Hardware tokens or out-of-band approval that the entry vector can&#39;t reasonably satisfy caps the blast radius outright.&nbsp;</p>

<h3>Data-Layer Controls: Limiting Damage After a Breach&nbsp;</h3>

<p>The final containment dimension to assess along identified attack paths answers the only remaining question: if an attacker reaches the critical asset <em>and</em> manages to gain access, how much damage can they do? This can be measured through controls such as: &nbsp;</p>

<ul>
	<li><strong>Encryption at rest: </strong>With separated key management, a successful compromise can corrupt or delete data but not read or exfiltrate it.&nbsp;</li>
	<li><strong>Identity-based access controls: </strong>Granular access controls limit what any single compromised identity can reach even after accessing a resource, enforcing a final layer of protection for the most sensitive data. &nbsp;</li>
</ul>

<h2>How to Identify Top Business Resilience Priorities and Investments &nbsp;</h2>

<p>After analyzing attack paths to critical assets for current containment controls, security leaders should have three things: &nbsp;</p>

<ol>
	<li>An inventory of business-critical assets and an understanding of downtime thresholds &nbsp;</li>
	<li>A view of all pathways from common ingress points to those critical resources &nbsp;</li>
	<li>A breakdown of how exposed the exploitable paths truly are, measured against containment controls &nbsp;</li>
</ol>

<p>With these insights, the final analysis can be completed &ndash; the goal is to find where business impact and containment readiness converge most sharply. For example, if a billing system has an extremely low downtime threshold due to its high revenue impact but is directly accessible within two lateral movement pivots via compromised user credentials, then it should rank as a high priority. &nbsp;</p>

<p>With priorities defined, security leaders have a <a href="https://zeronetworks.com/blog/what-is-cyber-resilience-how-to-protect-business-continuity">blueprint for tying cyber resilience directly to business impact</a>. Resilience strategies should be implemented using same threat containment dimensions that help uncover risk exposure and define urgency: &nbsp;</p>

<ul>
	<li><strong>Increase path distance or completely remove pathways to critical assets:&#8239;</strong>Granular&#8239;<a href="https://zeronetworks.com/blog/network-segmentation-all-you-need-to-know">network segmentation</a>, additional authentication boundaries, and inspection points can eliminate entire compromise scenarios.&nbsp;</li>
	<li><strong>Reduce privilege exposure:&#8239;</strong><a href="https://zeronetworks.com/blog/stopping-privilege-escalation-how-to-neutralize-stolen-credential-threats">Eliminating persistent privileged access</a>, reducing service account scope, and enforcing just-in-time reauthentication or additional authentication requirements for critical assets can rein in the privilege sprawl attackers rely on. &nbsp;</li>
	<li><strong>Enforce data layer controls:&#8239;</strong>Implementing&#8239;granular <a href="https://zeronetworks.com/platform/identity-segmentation">identity-based access controls</a>&nbsp;and encryption at rest limits the damage an attacker can do if they manage to reach critical systems.&nbsp;</li>
</ul>

<p>As security leaders take a more active role in business continuity, this framework delivers a repeatable way to align cyber resilience strategies with board-level priorities. &nbsp;</p>

<h3>Cyber Resilient by Design: Protect Uptime with Zero Networks&#39; Automated, Identity-Driven Microsegmentation &nbsp;</h3>

<p>Zero Networks proactively blocks threats to protect operational continuity with <a href="https://zeronetworks.com/platform">automated,&#8239;identity-based microsegmentation</a>, delivering the containment layer environments need to close attack paths without impacting legitimate traffic. &nbsp;</p>

<p>Zero provides immediate visibility into every identity and asset on the network, <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">then&#8239;automatically enforces adaptive, identity-aligned policies</a> based on observed network behavior. With <a href="https://zeronetworks.com/platform/network-map">always-current network visibility</a> and a deterministic, human-on-the-loop automation engine, Zero Networks delivers preemptive cyber resilience with no manual effort or operational complexity.&nbsp;</p>

<p>Learn how you can build a closed-by-default architecture that measurably improves business resilience &ndash; <a href="https://zeronetworks.com/request-demo">request a demo</a>. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Network Resilience Benchmarks: An Automated Containment Roadmap</title>
          <link>https://zeronetworks.com/blog/network-resilience-benchmarks-an-automated-containment-roadmap</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Fri, 31 Jul 2026 17:47:00 +0000</pubDate>
          <dc:date>Fri, 31 Jul 2026 17:47:00 +0000</dc:date>
          <category><![CDATA[Incident Response &amp; Breach Containment]]></category>
          <dc:subject><![CDATA[Incident Response &amp; Breach Containment]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/network-resilience-benchmarks-an-automated-containment-roadmap#When:1253</guid>
          <description><![CDATA[The Zero Trust mindset that breaches are inevitable is no longer controversial &ndash; instead of trying to stop everything at the perimeter, modern enterprises are increasingly focused on cyber resilience, asking: can the business keep operating through an attack &ndash; and can we prove it? &nbsp; Automated containment is the foundation of cyber resilience, translating to defensible uptime protection. When attackers move in seconds, AI-enabled workflows execute in parallel, and identity&#8230;]]></description>
          <content:encoded><![CDATA[<p>The Zero Trust mindset that breaches are inevitable is no longer controversial &ndash; instead of trying to stop everything at the perimeter, modern enterprises are increasingly focused on cyber resilience, asking: <em>can the business keep operating through an attack &ndash; and can we prove it? &nbsp;</em></p>

<p><a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">Automated containment</a> is the foundation of <a href="https://zeronetworks.com/blog/what-is-cyber-resilience-how-to-protect-business-continuity">cyber resilience</a>, translating to defensible uptime protection. When attackers move in seconds, AI-enabled workflows execute in parallel, and identity systems authenticate continuously, human response cycles can&rsquo;t keep up, so defenders&rsquo; only durable advantage is limiting access by default.&nbsp;</p>

<p>We&rsquo;ll walk through a simple framework for benchmarking your current network resilience on the path to automated containment and share a roadmap for building a self-defending architecture. &nbsp;</p>

<h3>Key Answers &nbsp;</h3>

<ul>
	<li><strong>How does automated containment strengthen cyber resilience?</strong> Automated containment strengthens cyber resilience by constraining blast radius structurally, so a compromised asset is isolated automatically rather than depending on a team to detect and respond fast enough. This shifts resilience from a reactive workflow to a demonstrable outcome &ndash; uptime and continuity hold during an incident because containment is built into the architecture itself, not bolted on after the fact.&nbsp;</li>
	<li><strong>What are the pillars of network resilience?</strong> Containment architecture, identity and access governance, network visibility, and policy automation are the four central priorities for building network resilience. Together, they proactively minimize blast radius to contain the impact of any attack. &nbsp;</li>
	<li><strong>What does a self-defending network architecture look like? </strong><a href="https://zeronetworks.com/platform">Automated, identity-aware microsegmentation</a> keeps access paths closed by default, privileged access requires just-in-time authentication, and a real-time network map informs dynamic policy automation, so coverage adapts as the network changes. &nbsp;</li>
</ul>

<h2>5 Stages of Network Resilience: Maturity Benchmarks &nbsp;</h2>

<p><a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">Cyber resilience</a> isn&rsquo;t just about recovering from a breach &ndash; it&rsquo;s about preventing the breach from spreading in the first place, so sensitive systems stay isolated and critical operations keep running. Rather than more automated detection or faster response, true resilience <a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">limits the impact of a breach automatically</a> by <em>proactively</em> constraining blast radius. &nbsp;</p>

<p>Because <a href="https://csrc.nist.gov/glossary/term/network_resilience">network resilience</a> refers to an infrastructure&rsquo;s capacity to provide continuous business operations, it&rsquo;s the most direct measure of security success against business priorities &ndash; and it&rsquo;s achieved when four interconnected capabilities work together: &nbsp;</p>

<ol>
	<li><strong><a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">Containment architecture</a>: </strong>How granularly assets and workloads are isolated from one another &ndash; and how much of the environment is accessible from any given foothold &ndash; defines the structural ceiling on how far a breach can travel, known as the <a href="https://zeronetworks.com/blog/what-is-blast-radius-in-cybersecurity-best-practices-for-breach-containment">blast radius</a>. &nbsp;</li>
	<li><strong><a href="https://zeronetworks.com/resource-center/topics/enhancing-identity-security-everything-you-need-to-know-about-identity-access-control">Identity and access governance</a>: </strong>Network architecture defines the shape of the environment; identity determines who can move through it, where they can go, and under what conditions.&nbsp;</li>
	<li><strong><a href="https://zeronetworks.com/blog/how-real-time-network-visibility-enables-automated-zero-trust-enforcement">Network visibility</a>:</strong> Comprehensive, real-time visibility across every asset, workload, identity, and communication pathway ensures that resilience controls reflect the environment as it actually exists. &nbsp;</li>
	<li><strong><a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">Policy automation</a>:</strong> A security posture held together by manual processes and periodic reviews will drift as the environment changes; automation ensures controls adapt continuously rather than degrade slowly.&nbsp;</li>
</ol>

<p>With these pillars in mind, organizations can map their network resilience against a simple five-stage framework: &nbsp;</p>

<ul>
	<li><strong>Stage 1 &ndash; Flat and Blind:</strong> Everything trusts everything and there are no East-West controls. &nbsp;</li>
	<li><strong>Stage 2 &ndash; Alert-Heavy:</strong> Tools like EDR and SIEM provide visibility without containment. &nbsp;</li>
	<li><strong>Stage 3 &ndash; Early Containment:</strong> Some level of segmentation has been implemented but policies are manual and constantly multiplying.&nbsp;</li>
	<li><strong>Stage 4 &ndash; Automated Containment:</strong> Identity-aware segmentation automatically blocks unauthorized lateral movement.&nbsp;</li>
	<li><strong>Stage 5 &ndash; Self Defending:</strong> Adaptive controls create an audit-ready posture and breach containment is built into the network architecture.&nbsp;</li>
</ul>

<p><a href="https://zeronetworks.com/blog/how-to-build-a-self-defending-network-a-framework-for-cyber-resilience">According to Chris Boehm</a>, Field CTO at Zero Networks, most organizations sit between stages two and three today &ndash; they have tools in place, they complete red teaming exercises, and they meet basic compliance requirements, but they&rsquo;re grappling with an unmanageable alert volume. &nbsp;&nbsp;</p>

<blockquote>
<p>&ldquo;A developer says, &#39;I need access to everything or I won&#39;t get this done.&#39; You open holes temporarily. A temporary hole here, a temporary hole there. You&#39;re paying someone $200,000 a year and you just need to get them going. That&#39;s how most organizations end up between stages two and three.&rdquo; &nbsp;</p>

<p>- Chris Boehm &nbsp;</p>
</blockquote>

<p>Benchmarking your current network resilience across core pillars delivers a clear starting point for building automated containment and, in turn, strengthening cyber resilience.</p>

<table aria-colcount="5" aria-rowcount="6" border="1" data-tablelook="1184" data-tablestyle="MsoTableGrid" dir="ltr">
	<tbody>
		<tr aria-rowindex="1" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{59}" paraid="74272901">Stage&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{62}" paraid="1891019762">Containment Architecture&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{65}" paraid="720327810">Identity &amp; Access Governance&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{68}" paraid="982106314">Network Visibility&nbsp;</p>
			</td>
			<td data-celllook="0" role="columnheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{71}" paraid="1370873024">Policy Automation&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="2" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{75}" paraid="887177021">1. Flat and Blind&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{78}" paraid="1078184198">Perimeter only; no internal segmentation&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{81}" paraid="58963983">Access standing and broad by default&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{84}" paraid="1865996508">No insight into&nbsp;East-West traffic&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{87}" paraid="1927569334">None; no&nbsp;internal&nbsp;policy exists to automate&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="3" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{91}" paraid="597401605">2. Alert-Heavy&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{94}" paraid="609660849">Zones&nbsp;likely exist&nbsp;via VLANs&nbsp;or ACLs; broad trust within each one&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{97}" paraid="748610792">Access governed by network position, not identity&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{100}" paraid="1723881042">Alerts exist, but not path-level visibility&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{103}" paraid="2075947241">None; policy is static and hardware-bound&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="4" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{107}" paraid="1829532410">3. Early Containment&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{110}" paraid="295949597">Ringfenced groups&nbsp;or sensitive resources; exceptions multiply manually&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{113}" paraid="1429432682">Privileged and service accounts accumulate unused permissions&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{116}" paraid="811590648">Partial asset visibility; service accounts often unmapped&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{119}" paraid="1773764730">None; exceptions are tracked by hand, if at all&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="5" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{123}" paraid="199500144">4. Automated Containment&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{126}" paraid="1239648582">Microsegementation&nbsp;enforces per-asset policies,&nbsp;blocks lateral movement by default&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{129}" paraid="957748768">Access explicitly granted and tied to identity&nbsp;&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{132}" paraid="526098264">Full asset and identity mapping&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{135}" paraid="419218693">Enforced automatically, but requires deliberate upkeep to stay current&nbsp;</p>
			</td>
		</tr>
		<tr aria-rowindex="6" role="row">
			<td data-celllook="0" role="rowheader">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{139}" paraid="610019782">5. Self-Defending&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{142}" paraid="2126208653">Closed by default across every axis of traffic&nbsp;&ndash; automated, identity-aware&nbsp;microsegmentation&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{145}" paraid="1965510225">Continuous&nbsp;verification;&nbsp;privileged access requires JIT authentication&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{148}" paraid="2146723441">Complete and real-time, used to inform dynamic policies&nbsp;</p>
			</td>
			<td data-celllook="0">
			<p paraeid="{d54f169c-8031-41fa-b66f-0ea001cd7b59}{151}" paraid="1577781335">Fully adaptive; policy corrects itself as the environment changes&nbsp;</p>
			</td>
		</tr>
	</tbody>
</table>

<h2>Automated Containment Roadmap: How to Build a Self-Defending Network Architecture&nbsp;</h2>

<p>As security leaders are increasingly tasked with proving a zero-tolerance policy for downtime, building automated containment &ndash; that dynamically adapts as the environment changes &ndash; into the network architecture is the most reliable path to true network resilience. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/guides/resilient-by-design-architecting-security-that-keeps-operations-running"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Cyber_Resilience_Guide_Download_%281%29.png" /></a></p>

<p>Regardless of where your resilience posture sits today, you can <a href="https://zeronetworks.com/resource-center/videos/self-defending-by-design-the-future-of-cybersecurity-defense">reach a self-defending state</a> in months by following a four-step roadmap: &nbsp;</p>

<h3>1. Map Every Network Asset, Identity, and Connection&nbsp;</h3>

<p>Manual discovery has historically taken months and gone stale almost immediately, since new assets and accounts appear faster than periodic audits can track them. By <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">leveraging an automated solution</a>, security teams can immediately pinpoint all assets and identities then learn logon activities, account behaviors, and asset access patterns to establish a baseline without the months of manual effort. &nbsp;</p>

<p>This is the step that pulls flat, alert-heavy networks out of established blind spots, where East-West and inter-VLAN traffic often lacks visibility. &nbsp;</p>

<h3>2. Generate Deterministic, Identity-Aware Segmentation Policies &nbsp;</h3>

<p>Using the behavioral baselines learned through real network mapping and observation, a <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">deterministic, human-on-the-loop automation engine</a> generates and enforces granular, identity-based policies that precisely <a href="https://zeronetworks.com/blog/how-to-prevent-lateral-movement-cybersecurity-risks-strategies">lock down unauthorized lateral movement</a> without impacting legitimate operations. &nbsp;</p>

<p>This step replaces implicit internal trust with explicit, <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">least-privilege access</a>, moving organizations out of early containment stages &ndash; where manually scoped exceptions keep multiplying to create gaps &ndash; and into automated enforcement.&nbsp;</p>

<h3>3. Enforce MFA on Privileged Internal Pathways &nbsp;</h3>

<p>Four admin protocols account for an outsized portion of lateral movement &ndash; <a href="https://zeronetworks.com/blog/the-4-protocols-driving-enterprise-risk-in-2026">71% of enterprise threat activity</a> flows through SMB, RDP, WinRM, and RPC. Business operations depend on privileged internal pathways like these, which is why they typically remain open, even in organizations that have made meaningful <a href="https://zeronetworks.com/blog/network-segmentation-all-you-need-to-know">network segmentation progress</a>. The fix is adding <a href="https://zeronetworks.com/resource-center/guides/mini-mfa-guide-extend-mfa-beyond-login-close-privileged-pathways">just-in-time network-layer MFA</a> to make privileged access verified and time-bound, ensuring attackers hit a dead-end while legitimate operations keep moving. &nbsp;</p>

<p>This is the identity governance evolution that closes least privilege security gaps, so attacks are automatically contained regardless of how they gain initial access. &nbsp;</p>

<h3>4. Automate Policy Updates Alongside Network Changes &nbsp;</h3>

<p>Modern enterprise environments never stop shifting; static policies can&rsquo;t provide consistent coverage. The combination of <a href="https://zeronetworks.com/platform/network-map">real-time network visibility</a> and deterministic automation closes this gap without manual overhead &ndash; new assets, identities, connections, and behaviors are automatically mapped and addressed with fine-grain policies, unlocking a self-defending architecture for true network resilience.</p>

<h2>Fast-Track Cyber Resilience Success with Zero Networks &nbsp;</h2>

<p>Zero Networks delivers the proactive containment layer enterprises need to protect uptime with <a href="https://zeronetworks.com/platform">automated,&#8239;identity-based microsegmentation</a>, unlocking 91%+ segmentation coverage within 90 days.</p>

<p>Zero granularly segments every asset and identity with adaptive policies based on observed network behavior. This dynamic approach means containment remains an automatic architectural feature, even as environments change &ndash; removing the privilege creep and rule sprawl that create gaps in static architectures. &#8239;&nbsp;</p>

<p>By strengthening every pillar of network resilience, Zero enables security teams to build a mature, business-aligned posture without adding operational complexity or manual effort &ndash;&#8239;<a href="https://zeronetworks.com/request-demo">request a demo</a> to learn more. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>A Fake Passport to Your Domain: How Certighost Turns a Basic Account Into a Domain Controller</title>
          <link>https://zeronetworks.com/blog/how-certighost-turns-a-basic-account-into-a-domain-controller</link>
          <dc:creator><![CDATA[Benny Lakunishok]]></dc:creator>
          <pubDate>Wed, 29 Jul 2026 14:00:00 +0000</pubDate>
          <dc:date>Wed, 29 Jul 2026 14:00:00 +0000</dc:date>
          <category><![CDATA[]]></category>
          <dc:subject><![CDATA[]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/how-certighost-turns-a-basic-account-into-a-domain-controller#When:1248</guid>
          <description><![CDATA[CISO SUMMARY CertiGhost allows a basic Active Directory account to become a full domain takeover by tricking a trusted certificate system into treating the attacker like a domain controller. Installing Microsoft&rsquo;s July 14 patch is important, but security teams should also confirm the protection is actually active across their environment. CISOs and their security teams should restrict certificate servers so they can communicate only with approved systems and block unauthorized attempts to&#8230;]]></description>
          <content:encoded><![CDATA[<h3>CISO SUMMARY</h3>

<p>CertiGhost allows a basic Active Directory account to become a full domain takeover by tricking a trusted certificate system into treating the attacker like a domain controller. Installing Microsoft&rsquo;s July 14 patch is important, but security teams should also confirm the protection is actually active across their environment. CISOs and their security teams should restrict certificate servers so they can communicate only with approved systems and block unauthorized attempts to copy sensitive identity data from domain controllers. The larger lesson: patches fix individual flaws, while segmentation and tight access controls can stop entire categories of attack.</p>

<p>&nbsp;</p>

<p>Microsoft fixed CertiGhost on July 14, 2026. Researchers <a href="https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26">H0j3n and Aniq Fakhrul published a working proof-of-concept</a> ten days later. If your CAs and domain controllers took the July updates, you are probably in reasonable shape &mdash; but you should be aware of the patch-versus-enabled loophole attackers are betting on and go verify that the fix is actually enforcing on your CAs and DCs, not just sitting around installed but inactive.&nbsp;<br />
I want to share a note on what &ldquo;patched&rdquo; means in AD CS specifically. When Microsoft shipped the SID security extension in May 2022 to counter <a href="https://www.thehacker.recipes/ad/movement/adcs/certifried">Certifried</a> (<a href="https://nvd.nist.gov/vuln/detail/cve-2022-26923">CVE-2022-26923</a>), the fix arrived in a compatibility mode that still permitted weak certificate mapping. Full enforcement did not become the default until February 2025, three years later, which means the fix was installed almost everywhere but enforced almost nowhere unless an administrator knew enough to go investigate it. That&rsquo;s a wide open door for attackers to sneak through.&nbsp;<br />
The <a href="https://www.dataminr.com/resources/intel-brief/certighost-cve-2026-54121/">CertiGhost fix </a>leaves a similar attack vector open to attackers &ndash; but it hides in plain sight. The new validation sits behind a Windows velocity feature gate &mdash; <code>Feature_3185813818</code> in the patched <code>certpdef.dll</code>, guarding the branch that calls <code>_ValidateChaseTargetIsDC</code>. Velocity gates are ordinary servicing machinery, not evidence of an incomplete fix: they let Microsoft stage, wave, or roll back a change without shipping a new binary, and MSRC security fixes are one of the things they gate. Most security features ship as always-enabled, in which case the gate is a rollback lever nobody will ever pull. What this means to real security teams is that enforcement is a runtime state rather than a property of the build, and a runtime state is something you have to confirm on your own CAs rather than infer from a patch level.<br />
<strong>The rest of this post is about the more uncomfortable question.</strong> CertiGhost is a low-privileged domain user turning into <code>krbtgt</code> in a single automated script. The chain is short, the prerequisites are close to default, and nothing in it exploits memory corruption or breaks cryptography. <em>It is a missing validation in a trust decision.</em><br />
Since Will Schroeder and Lee Christensen published Certified Pre-Owned in 2021, the community has kept a running catalogue of AD CS escalation paths: ESC1 through ESC8 in the original research, extended by later work to ESC17. It&#39;s not a Microsoft scheme and not a CVE series &mdash; it&rsquo;s an informal numbering that grows whenever someone finds another way to turn certificate issuance into domain privilege. Most of the seventeen are misconfigured templates or weak ACLs on PKI objects. Two of them, ESC8 and ESC11, are relay attacks that work for no reason more sophisticated than an enrollment endpoint being reachable by something that should never have reached it. CertiGhost belongs to the same family: the CA made a trust decision on data an attacker supplied. There will be an eighteenth.<br />
So: <strong>if you had not patched on July 14, what in your network would have stopped this?</strong><br />
For most environments the honest answer is nothing, because the attack looks like ordinary Windows traffic at every step. But two of the four network legs in the chain are gateable with controls that don&rsquo;t know or care that CertiGhost exists. That is the point worth making.&nbsp;</p>

<h2><br />
Key answers in this article</h2>

<ul>
	<li><strong>What is CertiGhost (CVE-2026-54121) and why does patching alone not close the risk?</strong> CertiGhost is an Active Directory Certificate Services (AD CS) exploit chain that turns a low-privileged domain user into a domain controller by tricking a certificate authority into signing a DC-identity certificate, which converts into krbtgt compromise via PKINIT and DCSync. Microsoft patched it July 14, 2026, but the fix ships behind a Windows velocity feature gate, meaning enforcement is a runtime state on each CA rather than a guaranteed property of the patch &mdash; the same pattern that left the 2022 Certifried fix in compatibility mode for nearly three years.</li>
	<li><strong>How does the CertiGhost attack chain actually work?</strong> The exploit abuses AD CS&#39;s "chase" fallback, where a CA follows attacker-supplied <code>cdc</code> and <code>rmd</code> enrollment attributes to a secondary lookup host without validating it&#39;s a real domain controller; an attacker stands up rogue SMB/LDAP/LSA services, creates a machine account via the default ms-DS-MachineAccountQuota, relays Netlogon authentication to a real DC, and receives a certificate carrying that DC&#39;s identity.</li>
	<li><strong>What single network control neutralizes the most dangerous leg of the attack?</strong> Default-deny egress on the certificate authority &mdash; permitting outbound SMB and LDAP only to known domain controllers &mdash; collapses the attack before identity confusion occurs, because this control requires no knowledge of CertiGhost, no signatures, and no patch-level awareness; it simply enforces that a CA&#39;s legitimate outbound peer set is small, stable, and enumerable.</li>
	<li><strong>Why does per-asset microsegmentation matter more than per-subnet or VLAN-based rules?</strong> A CA sitting in a broad server VLAN with permissive east-west traffic has effectively no egress policy at all; the defensive value comes specifically from scoping rules to the individual asset (or even the process, like certsrv.exe), since CAs have a narrower legitimate communication footprint than the network segment they sit in.</li>
	<li><strong>What is the single highest-ROI rule for blocking this entire class of AD CS attacks?</strong> Denying DCSync (MS-DRSR / DRSGetNCChanges) from all non-domain-controller sources is a narrow, low-breakage rule that neuters CertiGhost, every AD CS ESC escalation path, Zerologon, and any other attack whose final move is replicating secrets out of the directory.</li>
	<li><strong>What&#39;s the broader architectural lesson beyond this one CVE?</strong> CertiGhost will be patched and forgotten within months, like the ESC series before it &mdash; but every one of these bugs shares the same weakness: a trust decision made on attacker-influenced data. The defense that ages well isn&#39;t one that recognizes <code>cdc</code> specifically; it&#39;s one that constrains what a compromised or confused asset can reach, since a CA that can&#39;t open SMB to an arbitrary host is indifferent to which validation was missing this time.</li>
</ul>

<h2><br />
The chain, briefly</h2>

<p>Certificate enrollment in AD CS has a fallback path the researchers call a chase. When the CA can&rsquo;t resolve the requester&rsquo;s directory object locally &mdash; a real scenario in multi-domain forests with replication lag &mdash; the enrollment request may carry two attributes that steer a secondary lookup: <code>cdc</code>, naming the host the CA should contact, and <code>rmd</code>, naming the principal to resolve.<br />
Before the July patch, the CA followed the <code>cdc</code> value without confirming that the host was actually a domain controller. In <code>certpdef.dll</code>, <code>CRequestInstance::_LoadPrincipalObject</code> read the attribute straight out of the request and passed it into <code>_GetDSObject</code> with chase enabled. The July build wraps that call in <code>_ValidateChaseTargetIsDC</code>, which rejects IP literals, LDAP metacharacters, and oversized hostnames, then queries AD for exactly one computer object whose<code> dNSHostName</code> matches and whose<code> userAccountControl</code> carries <code>SERVER_TRUST_ACCOUNT (8192)</code>.<br />
The exploit stands up rogue SMB, LDAP, and LSA services on an attacker-controlled host, creates a machine account through the default <code>ms-DS-MachineAccountQuota</code> of 10 so it holds a genuine domain identity, and points <code>cdc</code> at itself. When the CA connects, the rogue services relay the authentication challenge to the real DC over Netlogon &mdash; satisfying the CA&rsquo;s authentication checks &mdash; while returning the target DC&rsquo;s <code>objectSid</code> and <code>dNSHostName</code> as directory data. The CA signs a certificate carrying a domain controller&rsquo;s identity. PKINIT converts that into Kerberos credentials for the DC, and DCSync converts those into <code>krbtgt</code>.<br />
Four network legs matter:</p>

<table align="left" border="1" cellpadding="1" cellspacing="1" style="width: 500px;">
	<thead>
		<tr>
			<th scope="col">Leg</th>
			<th scope="col">Traffic</th>
			<th scope="col">Direction</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td>1</td>
			<td>Enrollment request carrying <code>cdc / rmd</code></td>
			<td>Attacker &rarr; CA</td>
		</tr>
		<tr>
			<td>2</td>
			<td>The chase: SMB and LDAP to the <code>cdc</code> target</td>
			<td><strong>CA&nbsp;&rarr; Attacker</strong></td>
		</tr>
		<tr>
			<td>3</td>
			<td>Netlogon relay of the CA&#39;s challenge</td>
			<td>Attacker&nbsp;&rarr; DC</td>
		</tr>
		<tr>
			<td>4</td>
			<td>DCSync via directory replication</td>
			<td>Attacker&nbsp;&rarr; DC</td>
		</tr>
	</tbody>
</table>

<p><br />
&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>&nbsp;</p>

<p>Leg 2 is the one to sit with. Every other leg is an attacker reaching into your infrastructure, which is the situation security tooling is built for. Leg 2 is your certificate authority &mdash; one of the most trusted machines in the domain &mdash; opening an SMB and an LDAP session outbound to an attacker&rsquo;s Linux box, because a string in an untrusted request told it to.</p>

<h3><br />
Leg 2: the CA&rsquo;s outbound peer set is small, and this isn&rsquo;t in it</h3>

<p>A certificate authority is not a general-purpose client. Its legitimate outbound connections are few, stable, and enumerable: domain controllers, its database, possibly an HSM, and wherever it publishes CRLs. That list changes on the order of once a year.<br />
Which means the exploit&rsquo;s critical leg is not merely suspicious &mdash; it is outside the CA&rsquo;s entire behavioral envelope. Default-deny egress on the CA, permitting SMB and LDAP <a href="https://zeronetworks.com/use-cases/enhance-domain-controller-security">only to known domain controllers</a>, collapses the attack before the identity confusion ever happens. The rogue LSA service never gets a connection. No directory data comes back. No certificate is issued.<br />
The bar this sets is high rather than infinite. An attacker who has already compromised a host the CA is permitted to reach can stand the rogue services up there instead, and the chase succeeds. But that moves the prerequisite from &ldquo;create a machine account, which the default quota lets any user do&rdquo; to &ldquo;own something on the CA&rsquo;s short list of permitted peers&rdquo; &mdash; a materially different class of problem, and one you are far more likely to have instrumented.<br />
The thing worth dwelling on is that this control requires knowing nothing about CertiGhost. It doesn&rsquo;t parse <code>cdc</code>. It doesn&rsquo;t inspect enrollment attributes. It doesn&rsquo;t need a signature, a patch level, or a threat intel feed. It enforces a statement that was true before the CVE existed and remains true after: this CA talks to these hosts on these ports, and nothing else.<br />
Two things make this practical rather than aspirational. The first is <a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">automated policy generation</a> &mdash; you cannot hand-write egress policy for every server in an estate, but you can observe what each asset actually connects to and propose a least-privilege ruleset from that &mdash; then run it in monitor mode and see what it would have blocked before it blocks anything. The organizations that get burned by least-privilege network policy are the ones that wrote it from an architecture diagram instead of from observed traffic. The second is that policy has to be <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">per-asset rather than per-subnet</a>. A CA in a broad &ldquo;server VLAN&rdquo; with permissive east-west rules has effectively no egress policy at all; the whole value is in the CA&rsquo;s ruleset being narrow specifically because CAs have narrow needs.<br />
If you want to go further, per-process egress narrows it again: certsrv.exe has a smaller legitimate peer set than the host as a whole, and the chase originates from exactly that process.</p>

<h3><br />
Legs 1 and 4: <a href="https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall">RPC-layer control</a></h3>

<p>The remaining legs are RPC, which makes them addressable at a different layer.<br />
<strong>Leg 1</strong> is <a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wcce/">MS-WCCE enrollment</a>. In the public PoC &mdash; impacket-based, no web enrollment endpoint involved &mdash; that means ICertPassage over <code>DCERPC</code> on the <code>\pipe\cert</code> named pipe: interface <code>91ae6020-9e3c-11cf-8d7c-00aa00c091be</code>, <code>opnum 0</code>, <code>CertServerRequest</code>. The <code>cdc</code> and <code>rmd</code> attributes ride in that call&rsquo;s attribute string. Note the transport: this is <code>ncacn_np</code> over port 445, not <code>ncacn_ip_tcp</code> over 135, so a port-based rule aimed at the RPC endpoint mapper never sees it. An RPC firewall that hooks the RPC runtime rather than filtering ports does.<br />
Be precise about what this buys you. Filtering at the interface and opnum level tells you who may submit enrollment requests over RPC; it does not distinguish a malicious <code>cdc</code> from a benign one, because the discriminator is a string inside the parameters. So Leg 1 is an allow-list exercise: enrollment RPC to the CA should come from managed endpoints and enrollment proxies, not from an unmanaged host that appeared in the domain forty seconds ago. That shrinks the population who can attempt the attack. It does not identify the attempt.<br />
It also only covers the RPC transport. If you run Certificate Enrollment Web Services, MS-WSTEP over HTTPS reaches the same policy module and the same chase logic, and RPC-layer filtering is blind to it. Leg 1 coverage is incomplete wherever web enrollment is deployed &mdash; which is another argument for Leg 2 carrying the weight, since egress policy on the CA is indifferent to how the request arrived.<br />
That allow-list does have a second payoff worth naming. ESC11 is NTLM relay against precisely this interface &mdash; the RPC-based enrollment endpoint, as distinct from ESC8, which relays to the HTTP one. So restricting who may reach ICertPassage constrains CertiGhost&rsquo;s submission leg and ESC11 with the same rule. That is the difference between an architectural control and a patch: the patch closes one bug, the rule closes a class of reachability.<br />
<strong>Leg 4</strong> is where RPC filtering earns its keep unambiguously. DCSync is MS-DRSR &mdash; interface e3514235-4b06-11d1-ab04-00c04fc2dcd2, DRSGetNCChanges at opnum 3. Only domain controllers have any business calling it. <a href="https://zeronetworks.com/blog/preventing-certified-pre-owned-attacks-using-rpc-firewall-ldap-firewall-and-network-segmentation">Denying it on your DCs from every non-DC source</a> is a narrow, low-breakage rule, and it neuters the payoff of this attack, every AD CS ESC path, Zerologon and its derivatives, and any other chain whose final move is replicating secrets out of the directory. If you implement one rule from this post, implement that one.<br />
<strong>Leg 3</strong>, the Netlogon relay, is MS-NRPC (<code>12345678-1234-abcd-ef00-01234567cffb</code>). It is RPC, but every domain-joined machine legitimately speaks it to DCs, so protocol-level blocking is disruptive. The tractable angle is source identity rather than protocol: an unmanaged Linux host making NRPC calls is the anomaly. Treat this as a detection opportunity, not a chokepoint.<br />
Both rules want an audit pass before an enforcement pass. Logging calls to ICertPassage and DRSUAPI for a week gives you the real caller population, which is almost always narrower and stranger than the documentation implies, and occasionally includes a backup agent nobody remembers deploying.<br />
One non-network control belongs on the same list, because it is cheaper than everything above it: set <code>ms-DS-MachineAccountQuota</code> to 0. The exploit needs a machine account to hold a valid domain identity, and the default lets any authenticated user create ten of them.</p>

<h2>The generalization</h2>

<p>CertiGhost will be patched everywhere within a few months and then largely forgotten, which is roughly what happened with the <a href="https://github.com/ly4k/Certipy/wiki/06-%E2%80%90-Privilege-Escalation">ESC series</a> before it. The structural observation outlasts it.<br />
Every one of these bugs is a trust decision made on data the attacker influenced, and the fix is always the same shape: add the validation that was missing. So the defense that ages well is not the one that knows about <code>cdc</code>. It is the one that <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">constrains what a compromised or confused asset can reach</a> &mdash; because a certificate authority that cannot open SMB to an arbitrary host, and a domain controller that will not replicate secrets to a non-DC, are indifferent to which validation was missing this time.<br />
The cryptography was never the weak part. The reachability was.<br />
If you want to see and control what your CAs and DCs can actually talk to right now &mdash; not what you assume they can talk to &mdash; <a href="https://zeronetworks.com/request-demo">request a demo</a>.<br />
&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Hugging Face Proves: AI Finds the Gap, Lateral Movement Expands the Blast Radius </title>
          <link>https://zeronetworks.com/blog/hugging-face-proves-ai-finds-the-gap-lateral-movement-expands-the-blast-radius</link>
          <dc:creator><![CDATA[Benny Lakunishok]]></dc:creator>
          <pubDate>Tue, 28 Jul 2026 14:00:00 +0000</pubDate>
          <dc:date>Tue, 28 Jul 2026 14:00:00 +0000</dc:date>
          <category><![CDATA[Cybersecurity Trends &amp; CVEs, Incident Response &amp; Breach Containment]]></category>
          <dc:subject><![CDATA[Cybersecurity Trends &amp; CVEs, Incident Response &amp; Breach Containment]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/hugging-face-proves-ai-finds-the-gap-lateral-movement-expands-the-blast-radius#When:1247</guid>
          <description><![CDATA[The industry will argue about what the Hugging Face incident was. A rogue AI? A failed evaluation? An attack run by software instead of a person? For defenders, that argument is beside the point. You can&#39;t stop every break-in. You can stop the intruder from moving once it&#39;s inside. That&#39;s the line between one compromised system and a company-wide breach, and the whole lesson is in the attack path.&nbsp; What happened&nbsp; Hugging Face first disclosed an intrusion into part of its&#8230;]]></description>
          <content:encoded><![CDATA[<p>The industry will argue about what the Hugging Face incident was. A rogue AI? A failed evaluation? An attack run by software instead of a person? For defenders, that argument is beside the point. You can&#39;t stop every break-in. You can stop the intruder from moving once it&#39;s inside. That&#39;s the line between one compromised system and a company-wide breach, and the whole lesson is in the attack path.&nbsp;</p>

<h2>What happened&nbsp;</h2>

<p><a href="https://huggingface.co/blog/security-incident-july-2026">Hugging Face first disclosed an intrusion</a> into part of its production infrastructure and attributed it to an external AI agent whose underlying model was unknown. <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">On July 21, OpenAI took responsibility</a>. The breach came from its own models during an internal cybersecurity evaluation. The models escaped their isolated testing environment and reached Hugging Face from there.&nbsp;</p>

<p>OpenAI was running the models against an internal benchmark called ExploitGym, which measures how well a model can execute attacks against known vulnerabilities. The models involved were GPT-5.6 Sol and an even more capable pre-release model, with safeguards intentionally lowered for the test. According to OpenAI, the models became hyperfocused and went to extreme lengths to get the test solution. In plain terms, they tried to cheat on the eval by hacking Hugging Face to steal the answers.&nbsp;</p>

<h2>The attack chain&nbsp;</h2>

<p>The mechanics were ordinary even if the attacker wasn&#39;t.&nbsp;</p>

<p>The models found a zero-day in a package proxy to get out to the internet. They escalated privileges and moved laterally through Hugging Face&#39;s internal infrastructure until they reached the target: the ExploitGym answer key in a production database.&nbsp;</p>

<p>Hugging Face&#39;s account matches. Malicious content exploited code-execution paths in its data-processing pipeline and landed on a processing worker. From there the attacker escalated to node-level access, harvested cloud and cluster credentials, and moved into several internal clusters. OpenAI&#39;s account fills in on the other side. Its models exploited a zero-day in the research environment, escalated, and moved laterally to a node with internet access, then chained stolen credentials and more zero-days into a remote-code-execution path against Hugging Face production.&nbsp;</p>

<p>Compromise one system. Gain privilege. Steal credentials. Move to the next. Repeat until something valuable is reachable. That sequence is why lateral movement is the control point that decides how bad a modern attack gets.&nbsp;</p>

<p>The incident didn&#39;t turn serious because an AI found one vulnerability. It turned serious because that first foothold led somewhere that mattered.&nbsp;</p>

<h2>Preventing infiltration is no longer enough&nbsp;</h2>

<p>Keep patching. Keep securing pipelines. Keep protecting credentials and watching for bad behavior. None of that goes away. But this incident shows why you can&#39;t build a security model on stopping every first compromise.&nbsp;</p>

<p>AI changes the economics of offense. It can hunt for vulnerabilities, test combinations, retry what failed, and run thousands of actions without getting tired. Hugging Face described an autonomous framework running many thousands of actions across short-lived sandboxes. Work that used to need a skilled team can now be automated.&nbsp;</p>

<p>So, the asymmetry keeps widening. Vulnerabilities and possible paths grow faster than any team can patch, investigate, or contain by hand. Traditional detection leans on human habits: known tools, known protocols, known sequences. AI agents have none of those. They adapt as they go. The reliable move is to remove the paths, not to recognize the attacker walking them.&nbsp;</p>

<h2>Enterprise networks give an attacker room to run&nbsp;</h2>

<p>The <a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report">Zero Networks 2026 Lateral Movement Exposure Report</a> shows the size of the problem. Across hundreds of enterprise environments, one compromised system could reach a median of about 85% of the network in a single hop. By the second hop, reachability approached the entire environment. About 60% became reachable inside the first hour. A small foothold can become an enterprise-wide incident before most teams finish triage.&nbsp;</p>

<p>This isn&#39;t spread across thousands of exotic techniques. About 71% of threat-relevant activity sat in four familiar protocols: SMB, RDP, WinRM, and RPC. Businesses run on those every day. Attackers spread on those same protocols.&nbsp;</p>

<p>The gap holds across the industry. In <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-forecast.pdf">Kiteworks&#39; 2026 Data Security and Compliance Risk Forecast</a>, a survey of 225 security leaders, 63% said they can&#39;t enforce purpose limits on AI agents and 60% can&#39;t shut down one that misbehaves. Most can watch an agent go wrong. Far fewer can stop it.&nbsp;</p>

<p>Hugging Face fits the pattern. The execution path created access. Credentials and too much internal connectivity created reach. Lateral movement turned one vulnerable worker into access across multiple clusters.&nbsp;</p>

<h2>Stop the movement, stop the attack&nbsp;</h2>

<p>Defenders have an edge here. You may not know which vulnerability a human or an AI finds next. You do get to decide which systems can talk to each other and which identities can use privileged pathways.&nbsp;</p>

<p>If the first compromised worker can&#39;t freely reach other nodes, the attack stalls. If stolen credentials can&#39;t be reused across clusters, it stalls. If admin protocols are limited to the users and systems that need them, it stalls. The attacker might still get initial execution. The company-wide breach never happens.&nbsp;</p>

<p>That&#39;s the design goal: one compromised system stays one compromised system.&nbsp;</p>

<p>Detection still matters. It just can&#39;t be the only thing standing between initial access and real damage. AI-enabled attackers move at machine speed. An architecture that waits for an analyst to see an alert, work out the path, and block it by hand will keep losing the race.&nbsp;</p>

<p>When Hugging Face&#39;s own responders tried commercial frontier models to analyze the attack logs, the providers&#39; safety guardrails blocked the requests. The models couldn&#39;t tell an incident responder from an attacker, so the team fell back to open-weight models they ran themselves. Provider-side safety is not a containment strategy. Containment must live in the network.&nbsp;</p>

<h2>How Zero Networks handles this&nbsp;</h2>

<p>Zero Networks decides which network paths are allowed to exist at all. It deploys directly on servers, cloud workers, and endpoints, and it works at the process level rather than only at the perimeter. So, you can enforce a rule like this: this dataset-processing worker may never SSH into an internal database cluster, no matter what credentials it holds. Present stolen credentials and the path still isn&#39;t there. The attack stops at the boundary.&nbsp;</p>

<p>In the Hugging Face case, the first code execution on the worker was a software flaw. The moment that agent tried to move across internal clusters with harvested credentials, it would have hit a wall. The 17,000-plus recorded events in the campaign all depended on one thing: the ability to move. Take that away and the breach stays a single worker instead of a multi-cluster event.&nbsp;</p>

<h2>A practical agenda for CISOs&nbsp;</h2>

<p>Ask four questions:&nbsp;</p>

<ul>
	<li>How much of our environment can one compromised system reach?&nbsp;</li>
	<li>Which pathways lead to critical servers, cloud workloads, and clusters?&nbsp;</li>
	<li>Can stolen credentials move through those pathways?&nbsp;</li>
	<li>Can we contain a compromised workload automatically, without waiting for an analyst?&nbsp;</li>
</ul>

<p>Then act on the answers. Segment the network so one compromised system can&#39;t reach the rest. Restrict privileged protocols to the systems that genuinely need them. Bind identities to paths so stolen credentials can&#39;t travel. Automate containment so a suspicious workload is isolated in seconds.&nbsp;</p>

<p>The goal isn&#39;t to predict every AI-enabled attack. It&#39;s to remove the pathways that let any attacker, human or autonomous, turn access into impact.&nbsp;</p>

<p>Hugging Face detected the activity, contained it, rebuilt the compromised nodes, rotated credentials, and tightened cluster controls. All necessary. The larger lesson is preventative. Constrain the blast radius before the incident starts.&nbsp;</p>

<p>AI will find vulnerabilities faster. Attackers will chain them faster. The answer isn&#39;t a permanent race to patch everything first. You don&#39;t have to outrun every new attack. You have to out-architect its ability to spread.&nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/breach-map">The blast radius is a design choice</a>. <a href="https://zeronetworks.com/request-demo">Book a walkthrough</a> and watch Zero Networks contain lateral movement in your own environment.&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Zero Standing Privileges: What It Means, Why It Matters, and How to Implement It</title>
          <link>https://zeronetworks.com/blog/zero-standing-privileges-what-it-means-why-it-matters-and-how-to-implement-it</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Wed, 22 Jul 2026 14:22:00 +0000</pubDate>
          <dc:date>Wed, 22 Jul 2026 14:22:00 +0000</dc:date>
          <category><![CDATA[Identity Access Control]]></category>
          <dc:subject><![CDATA[Identity Access Control]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/zero-standing-privileges-what-it-means-why-it-matters-and-how-to-implement-it#When:1244</guid>
          <description><![CDATA[Excessive privileged access is the norm in enterprise environments. Ninety-nine percent of users, roles, and services hold excessive standing permissions; meanwhile, privileged ports are used somewhere inside the average enterprise every 10 minutes, according to Zero Networks telemetry. And those same ports &ndash; RDP, SMB, WinRM, SSH, RPC &ndash; are the primary highways for lateral movement, with more than 70% of threat activity flowing through just four admin protocols. &nbsp; Zero standing&#8230;]]></description>
          <content:encoded><![CDATA[<p>Excessive privileged access is the norm in enterprise environments. <a href="https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report">Ninety-nine percent of users, roles, and services</a> hold excessive standing permissions; meanwhile, privileged ports are used somewhere inside the average enterprise every 10 minutes, according to Zero Networks telemetry. And those same ports &ndash; RDP, SMB, WinRM, SSH, RPC &ndash; are the <a href="https://zeronetworks.com/blog/the-4-protocols-driving-enterprise-risk-in-2026">primary highways for lateral movement</a>, with <a href="https://zeronetworks.com/blog/one-compromised-system-and-boom-meet-your-blast-radius">more than 70% of threat activity</a> flowing through just four admin protocols. &nbsp;</p>

<p>Zero standing privileges (ZSP) is an advanced response to that condition that removes excessive standing access rights by default and replaces them with narrowly scoped, time-bound entitlements. We&rsquo;ll break down what ZSP means, why persistent access has become one of the most exploited weaknesses in modern networks, and a practical approach to implementing the ZSP standard. &nbsp;</p>

<h2>What Does Zero Standing Privileges (ZSP) Mean? &nbsp;</h2>

<p>Zero standing privileges is a security principle that requires eliminating persistent, always-on access rights in favor of just-in-time, just-enough access &ndash; granted only when it&#39;s needed and only for as long as it&#39;s needed. &nbsp;</p>

<p>Rather than a user, service, admin, or AI agent holding a permission indefinitely, access is requested, verified, and provisioned for a defined window, then automatically revoked when that window closes.&nbsp;</p>

<h3>ZSP vs. the Principle of Least Privilege (PoLP)&nbsp;</h3>

<p>At a high level, zero standing privileges and least privilege are different articulations of the same underlying principle: &nbsp;</p>

<ul>
	<li>The <strong>least privilege principle</strong> states that a user, process, or system should receive only the minimum level of access required to perform its intended function &ndash; but it does not limit how long privileges are available. &nbsp;</li>
	<li><strong>ZSP</strong> applies the same access scoping discipline that PoLP requires, then adds a time dimension: access isn&#39;t just limited to <em>what&#39;s</em> necessary, it&#39;s limited to <em>when</em> it&#39;s necessary.&nbsp;</li>
</ul>

<p>The <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">principle of least privilege</a> was first introduced in the 1970s, while zero standing privileges was coined within the last 10 years, meaning ZSP is an <em>evolution</em> of the PoLP &ndash; not a distinct philosophy. And in fact, least privilege is a core tenet of ZSP.&nbsp;</p>

<h3>Key Pillars of Zero Standing Privileges &nbsp;</h3>

<p>Like <a href="https://zeronetworks.com/blog/what-is-zero-trust-security-without-the-marketing-bs">Zero Trust</a> or any other security philosophy, ZSP is an ideal upheld by a few core principles: &nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/blog/mfa-is-our-dna-zero-networks-multi-factor-segmentation"><strong>Just-in-Time (JIT) Access</strong></a>: Critical for operationalizing the time constraint that is core to zero standing privileges, JIT access allows organizations to unlock temporarily elevated permissions before automatically revoking them. &nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action"><strong>Least Privilege Principle:</strong></a> By restricting every identity &ndash; including admins and service accounts &ndash; to least privilege by default, enterprises implement the foundation for ZSP. &nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/how-real-time-network-visibility-enables-automated-zero-trust-enforcement"><strong>Always-Current Network Visibility:</strong> </a>A live network map delivers the real-time insights teams need to keep policies granular and prevent privilege creep. &nbsp;</li>
</ul>

<h3>Where JIT Isn&rsquo;t Possible: A Risk-Aligned Approach to ZSP in Real Enterprise Environments &nbsp;</h3>

<p>While just-in-time access is central to the zero standing privileges philosophy, it&rsquo;s important to note that not every application or workload is designed to support just-in-time access. Some legacy systems require persistent connectivity. Others break under real-time gating. &nbsp;</p>

<p>This is why a risk-aligned approach to just-in-time access &ndash; and, in turn, to ZSP &ndash; is critical. By enforcing just-in-time access controls on <a href="https://zeronetworks.com/blog/10-common-lateral-movement-techniques-how-to-stop-them">lateral movement paths</a>, privileged activity, and interactive sessions, while applying least privilege policies to everything else, organizations can achieve zero standing privileges where it matters most without the risk of breaking something. &nbsp;</p>

<p>A risk-aligned approach like this gets enterprises as close as their environments allow to comprehensive ZSP while effectively managing legacy limitations.</p>

<h2>Why Standing Privileges Are a Security Risk&nbsp;</h2>

<p>Privileges accumulate over time for the sake of operational ease. But the same internal pathways that enterprises rely on to keep the business operating are the ones that attackers exploit, creating gaps that leave organizations vulnerable to familiar risks. &nbsp;</p>

<h3>Lateral Movement and Privilege Escalation &nbsp;</h3>

<p>Over&#8239;<a href="http://crowdstrike.com/en-us/cybersecurity-101/identity-protection/identity-segmentation/">80% of attacks leverage stolen credentials at some stage</a>.&#8239;When an identity carries broad, always-on access, attackers immediately inherit those entitlements via stolen credentials, allowing them to <a href="https://zeronetworks.com/blog/stopping-privilege-escalation-how-to-neutralize-stolen-credential-threats">escalate privileges</a> and <a href="https://zeronetworks.com/resource-center/topics/lateral-movement-innovations-prevention-techniques">move laterally across the network</a> without triggering alerts. &nbsp;</p>

<h3>Overprivileged Service Accounts and Machine Identity Sprawl&nbsp;</h3>

<p>Machine and service identities now <a href="https://www.paloaltonetworks.com/idira/identity-security-landscape-report">outnumber human identities 109:1</a>, and only <a href="https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024">2.6% of workload identity permissions</a> are actually used &ndash; meaning the overwhelming majority of machine access exists as unmonitored and unnecessary risk. To top it off, <a href="https://zeronetworks.com/blog/agentic-ai-cybersecurity-risks-how-to-secure-ai-agents">AI agents are compounding the issue</a>. Roughly <a href="https://www.ibm.com/think/insights/agentic-ai-security">80% of enterprises</a> are already deploying AI agents, but <a href="https://www.ibm.com/downloads/documents/us-en/131cf87b20b31c91">nearly two-thirds don&rsquo;t have the necessary policies</a> to effectively govern them. &nbsp;</p>

<p>Because <a href="https://zeronetworks.com/blog/identity-based-attacks-tactics-trends-identity-security-best-practices">identity-based attacks exploit legitimate permissions</a> and blend in with normal activity, more detection tools and alert dashboards won&rsquo;t solve the problem. &nbsp;</p>

<h2>How to Implement Zero Standing Privileges&nbsp;</h2>

<p>Implementing the zero standing privileges model requires a multi-step approach for removing excessive &ldquo;always-on&rdquo; access and operationalizing granular, dynamic controls. &nbsp;</p>

<h3>1. Discover every network asset, identity, and activity&nbsp;</h3>

<p>Start by comprehensively mapping every identity, asset, and existing privileged pathway &ndash; including service accounts, AI agents, and machine identities, not just human users and admins. &nbsp;</p>

<h3>2. Learn network connections and baseline permissions&nbsp;</h3>

<p>Determine what access is genuinely needed by observing real behavior, logon activities, and asset access patterns rather than relying on assumed or historically granted permissions.&nbsp;</p>

<h3>3. Build deterministic, identity-based policies&nbsp;</h3>

<p>Translate learned network insights into policies grounded in real behavior. <a href="https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior">Automatically restrict all identities</a> to pre-approved assets and logon types, and define privileged access policies for specific resources tied to identity. &nbsp;</p>

<h3>4. Enforce JIT network-layer MFA for privileged access&nbsp;</h3>

<p>Enforce JIT verification for access to admin protocols, critical services, and other privileged activity. Use context-aware, identity-based policies to ensure that only in-scope identities are eligible for access, and network-layer MFA to provision access only for the duration needed &ndash; without adding operational friction. &nbsp;</p>

<h3>5. Dynamically adapt policies on an ongoing basis&nbsp;</h3>

<p>Standing privilege has a way of creeping back in as new accounts, services, and access paths are created. Policies should adapt continuously based on <a href="https://zeronetworks.com/platform/network-map">real-time visibility</a> that automatically flags out-of-scope privileged access, anomalous paths, and high-risk ports. &nbsp;</p>

<h2>Close Privileged Pathways by Default with Zero Networks &nbsp;</h2>

<p>Zero Networks delivers every core pillar of ZSP in a single, unified platform &ndash; <a href="https://zeronetworks.com/platform">automated, identity-based microsegmentation</a> enables least privilege enforcement at scale, <a href="https://zeronetworks.com/use-cases/apply-mfa-to-anything">just-in-time network-layer MFA</a> keeps privileged access closed by default, and our <a href="https://zeronetworks.com/platform/network-map">real-time network map</a> delivers up-to-date insights that power adaptive policies. &nbsp;</p>

<p>By making least privilege the default and adding an adaptive authentication at the exact moment of privileged access, Zero Networks removes risky always-on permissions and closes the privileged internal pathways attackers rely on to escalate breaches. <a href="https://zeronetworks.com/request-demo">Request a demo</a> to learn more. &nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>1,000 Fixes a Month, and It Won&#8217;t Save You, The Only Winning Move Is Not to Be Reachable</title>
          <link>https://zeronetworks.com/blog/1000-fixes-a-month-and-it-wont-save-you-the-only-winning-move-is-not-to-be-reachable</link>
          <dc:creator><![CDATA[Benny Lakunishok]]></dc:creator>
          <pubDate>Mon, 20 Jul 2026 18:00:00 +0000</pubDate>
          <dc:date>Mon, 20 Jul 2026 18:00:00 +0000</dc:date>
          <category><![CDATA[Cybersecurity Trends &amp; CVEs]]></category>
          <dc:subject><![CDATA[Cybersecurity Trends &amp; CVEs]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/1000-fixes-a-month-and-it-wont-save-you-the-only-winning-move-is-not-to-be-reachable#When:1234</guid>
          <description><![CDATA[Microsoft has released the largest Patch Tuesday in its history: fixes for 570 vulnerabilities, including three zero-days&mdash;two already exploited in attacks&mdash;and 141 remote code execution flaws. &nbsp; Microsoft may be the most dramatic example, but it is not the only one. Since Anthropic introduced Mythos Preview on April 7, 2026, Microsoft&rsquo;s monthly Patch Tuesday count rose from 120 vulnerabilities in May to 200 in June and a record 570 in July&mdash;a 375% increase in two&#8230;]]></description>
          <content:encoded><![CDATA[<p>Microsoft <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/">has released the largest Patch Tuesday</a> in its history: fixes for 570 vulnerabilities, including three zero-days&mdash;two already exploited in attacks&mdash;and 141 remote code execution flaws. &nbsp;</p>

<p>Microsoft may be the most dramatic example, but it is not the only one. Since Anthropic introduced Mythos Preview on April 7, 2026, Microsoft&rsquo;s monthly Patch Tuesday count rose from 120 vulnerabilities in May to 200 in June and a record 570 in July&mdash;a 375% increase in two months. Google&rsquo;s major Chrome releases followed a similar pattern: 126 security fixes on May 5 jumped to 429 on June 2, an increase of approximately 240%, followed by another 433 fixes on June 30. Adobe&rsquo;s monthly vulnerability count more than doubled as well, rising from 52 vulnerabilities in May to 123 in June&mdash;a 137% increase. These figures do not establish that Mythos found these vulnerabilities (although I believe these are of direct result of Mythos and similar models), but they illustrate how many vulnerabilities exist (a lot more for sure) and that we will forever be in a chase a step behind them to really solve for the issue they create an organization must think in a containment mindset.&nbsp;</p>

<p>Five hundred and seventy vulnerabilities in a single month should also force us to ask a harder question: What happens when finding vulnerabilities <a href="https://zeronetworks.com/blog/ai-driven-vulnerability-research-and-the-growing-importance-of-containment-architecture">scales faster than our ability to fix them</a>?&nbsp;</p>

<p>Anthropic says its Mythos Preview model has already found thousands of high-severity vulnerabilities, including flaws in every major operating system and web browser. As these capabilities improve and proliferate, both defenders and <a href="https://eur06.safelinks.protection.outlook.com/GetUrlReputation">attackers will gain the ability to discover vulnerabilities</a> at a speed and scale that human security teams cannot match.&nbsp;</p>

<p>Microsoft&rsquo;s record Patch Tuesday may be an early indication of that future: AI discovers more flaws, vendors disclose more flaws, and security teams receive an ever-growing list of systems that must be tested and patched immediately.&nbsp;</p>

<p>The traditional security model tells CISOs to run faster. The better answer is to change the race.&nbsp;</p>

<h2>The Vulnerability Is Only the Entry Point&nbsp;</h2>

<p>A vulnerability does not usually create a companywide outage by itself. It gives an attacker an initial foothold.&nbsp;</p>

<p>The attacker still needs to move from that compromised browser, laptop, server, identity, or application to the systems that matter: domain controllers, databases, production environments, backup infrastructure, cloud control planes, and operational technology.&nbsp;</p>

<p>That is where lateral movement turns an isolated security incident into a business crisis.&nbsp;</p>

<p>Zero Networks&rsquo; <a href="https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report">2026 Lateral Movement Exposure Report</a> analyzed 54 trillion activities across 312 live enterprise environments. The findings reveal how much freedom attackers typically inherit after that first compromise:&nbsp;</p>

<ul>
	<li>80% of enterprise servers are reachable from anywhere inside the network</li>
	<li>87% accept inbound RDP or SSH connections from broad internal sources&nbsp;</li>
	<li>78.7% are reachable over SMB or WinRM</li>
	<li>43.2% of internal authentication still relies on NTLM</li>
	<li>A single compromised host can reach 85% of internal systems on the first hop</li>
</ul>

<p>That last number should concern every CISO. It means an attacker may not need a sophisticated multistage campaign to cross the environment. In many enterprises, the first compromised machine already has a pathway to nearly everything else.&nbsp;</p>

<p>This is the real danger behind the growing number of vulnerabilities. AI is creating more ways in, while enterprise networks still provide too many ways across.&nbsp;</p>

<h2>Detection and Response Cannot Carry the Security Model&nbsp;</h2>

<p>For years, organizations have built security architectures around a familiar sequence:&nbsp;</p>

<ul>
	<li>An attacker exploits a vulnerability.&nbsp;</li>
	<li>Security tools identify suspicious activity.&nbsp;</li>
	<li>The SOC investigates the alerts.&nbsp;</li>
	<li>Responders determine what happened.&nbsp;</li>
	<li>The organization contains the attacker before material damage occurs.&nbsp;</li>
</ul>

<p>Detection and response remain necessary. CISOs still need EDR, SIEM, threat intelligence, incident response, and strong vulnerability management.&nbsp;</p>

<p>But these capabilities are becoming less useful as the <strong>primary control </strong>because the model depends on defenders having enough time. AI is compressing that time.&nbsp;</p>

<p>Attackers can use automation to identify exposed systems, test credentials, enumerate network pathways, and move through trusted administrative protocols. RDP, SMB, SSH, WinRM, and RPC are not inherently malicious. They are the same tools administrators and applications use every day, which makes malicious use harder to distinguish quickly from legitimate activity.&nbsp;</p>

<p>Our research found that more than <a href="https://zeronetworks.com/blog/top-10-lateral-movement-risks-in-enterprise-networks-and-what-to-do-about-them">70% of enterprise threat activity</a> travels over SMB, RDP, WinRM, and RPC. &nbsp;</p>

<p>That creates a fundamental disadvantage for a detection-first strategy: the SOC must identify malicious intent inside traffic the business already trusts, investigate it, and respond before the attacker reaches a critical system.&nbsp;</p>

<p>At machine speed, that is a dangerous bet.&nbsp;</p>

<p>The new model should not assume the organization will detect every important action in time. It should assume:&nbsp;</p>

<ul>
	<li>Some vulnerabilities will remain unpatched.&nbsp;</li>
	<li>Some zero-days will be exploited before disclosure.&nbsp;</li>
	<li>Some identities and credentials will be compromised.&nbsp;</li>
	<li>Some malicious activity will look legitimate.&nbsp;</li>
	<li>Some alerts will arrive after the attacker has begun moving.&nbsp;</li>
	<li>Human responders will not always act before automated attackers.&nbsp;</li>
</ul>

<p>The architecture must contain the attack even when those assumptions prove true.&nbsp;</p>

<h2>Build an Architecture That Does Not Care About the Next 100 Vulnerabilities&nbsp;</h2>

<p>No organization can become literally immune to software vulnerabilities. But it can become resistant to their blast radius. Imagine that an attacker exploits an unknown Chrome or Windows vulnerability on an employee laptop tomorrow.&nbsp;</p>

<p>The first question should not be: <em>Will our SOC detect it?&nbsp;</em></p>

<p>The first question should be: <em>What can that laptop reach?&nbsp;</em></p>

<p>Can it initiate RDP or SSH connections to servers? Can it access file shares over SMB? Can an attacker use stolen credentials over WinRM or RPC? Can it reach a domain controller, backup system, production database, or critical cloud workload?&nbsp;</p>

<p>In too many environments, the answer is yes.&nbsp;</p>

<p>A containment-first architecture changes that answer. It continuously identifies legitimate communication, removes unnecessary pathways, closes privileged ports by default, and requires identity verification when users or agents request high-risk access.&nbsp;</p>

<h2>The 5-Step Practical CISO Checklist&nbsp;</h2>

<h3>1. Measure the actual blast radius&nbsp;</h3>

<p>Start with evidence, not architecture diagrams.&nbsp;</p>

<p>Select a representative employee device, server, privileged identity, cloud workload, and operational asset. Determine which systems each one can actually reach and over which ports and protocols.&nbsp;</p>

<p>Ask:&nbsp;</p>

<ul>
	<li>Can a typical endpoint reach critical servers?&nbsp;</li>
	<li>Which administrative protocols remain broadly open?&nbsp;</li>
	<li>Can one compromised credential unlock multiple environments?&nbsp;</li>
	<li>Is there a direct pathway from user devices to critical assets?&nbsp;</li>
	<li>How many systems are reachable on the first hop?&nbsp;</li>
</ul>

<p>A vulnerability score tells you how serious a flaw might be. A blast-radius assessment tells you <strong>how serious it is in your business.&nbsp;</strong></p>

<h3>2. Close unnecessary east-west pathways&nbsp;</h3>

<p>Most internal access exists because nobody has removed it&mdash;not because the business requires it. Microsegmentation drastically reduces pathways there by the blast radius and almost eliminates the chance of something unpatched to be exploited.&nbsp;</p>

<p>Identify and eliminate connections created by flat network designs, legacy configurations, permissive firewall rules, and operational convenience.&nbsp;</p>

<p>Allow the communications the business needs. Deny everything else.&nbsp;</p>

<p>Do not wait for the next vulnerability announcement to decide that employee laptops should never have been able to reach production servers.&nbsp;</p>

<h3>3. Protect privileged protocols at the moment of access&nbsp;</h3>

<p>RDP, SMB, SSH, WinRM, and RPC create powerful administrative pathways. They also give attackers the ability to expand a small foothold rapidly.&nbsp;</p>

<p>Keep privileged ports closed until legitimate access is requested. Require just-in-time identity verification for unexpected human or AI-agent access while allowing known machine-to-machine communications to continue.&nbsp;</p>

<p>Identity based Microsegmentation help to <a href="https://eur06.safelinks.protection.outlook.com/GetUrlReputation">only open certain ports as needed after strong validation such as MFA</a>.</p>

<h3>4. Make containment independent of detection&nbsp;</h3>

<p>Test whether controls stop lateral movement even when the organization has not yet identified the initial compromise.&nbsp;</p>

<p>Assume:&nbsp;</p>

<ul>
	<li>The endpoint tool missed the exploit.&nbsp;</li>
	<li>The credentials appear valid.&nbsp;</li>
	<li>The attacker uses legitimate administrative tools.&nbsp;</li>
	<li>The SOC has not opened an incident.&nbsp;</li>
	<li>The vulnerability has no available signature.&nbsp;</li>
</ul>

<p>Then determine how far the attacker can travel.&nbsp;</p>

<p>Detection should provide visibility and context. It should not be the only thing standing between one infected laptop and a companywide outage.&nbsp;</p>

<h3>5. Replace SOC-speed metrics with resilience metrics&nbsp;</h3>

<p>Mean time to detect and mean time to respond still matter, but they do not tell the board whether the business can withstand an AI-speed attack.&nbsp;</p>

<p>Add metrics such as:&nbsp;</p>

<ul>
	<li>Percentage of critical assets protected from unnecessary access.&nbsp;</li>
	<li>Percentage of privileged pathways closed by default.&nbsp;</li>
	<li>Percentage of servers reachable from standard user devices.&nbsp;</li>
	<li>Number of verified pathways to critical systems.&nbsp;</li>
	<li>First-hop reachability from a compromised endpoint.&nbsp;</li>
	<li>Time required to isolate a workload or environment.&nbsp;</li>
	<li>Reduction in attack paths over time.&nbsp;</li>
</ul>

<p>The central board-level metric should be simple:&nbsp;</p>

<p><strong>How much of the business can one compromised asset disrupt?</strong>&nbsp;</p>

<h3>6. Prepare a credible answer for the board</h3>

<p>Boards will increasingly ask:&nbsp;</p>

<p>What happens when AI finds an exploitable vulnerability before we can patch it?&nbsp;</p>

<p>&ldquo;We expect to detect the attack&rdquo; is no longer a sufficient answer.&nbsp;</p>

<p>A stronger answer is:&nbsp;</p>

<p>We know which systems a compromised asset could reach. We have removed unnecessary pathways, restricted privileged protocols, verified high-risk access, and limited the blast radius before the attack begins.&nbsp;</p>

<p>That is a measurable statement of resilience.&nbsp;</p>

<h3>7. Prioritize vulnerabilities by reachable impact</h3>

<p>CISOs should continue patching aggressively, but CVSS scores alone cannot determine business risk.&nbsp;</p>

<p>Prioritize remediation using:&nbsp;</p>

<ul>
	<li>Active exploitation.&nbsp;</li>
	<li>Internet exposure.&nbsp;</li>
	<li>Asset criticality.&nbsp;</li>
	<li>Privilege available on the affected system.&nbsp;</li>
	<li>Systems reachable from that asset.&nbsp;</li>
	<li>Existing containment controls.&nbsp;</li>
	<li>Potential impact on uptime, revenue, safety, and operations.&nbsp;</li>
</ul>

<p>A critical vulnerability on a contained asset may create less business exposure than a lower-rated flaw on a workstation that can reach 85% of the environment.&nbsp;</p>

<h2>Start With the Mythos Readiness Pack&nbsp;</h2>

<p>We created the <a href="https://zeronetworks.com/landing/mythos-readiness">Mythos Readiness Pack</a> to help CISOs translate this new model into practical action.&nbsp;</p>

<p>The pack helps organizations determine whether their current architecture can contain attacks accelerated by systems such as Mythos. It includes:&nbsp;</p>

<ul>
	<li>A <strong>Breach Map Tool</strong> that exposes the pathways an attacker could use to move from an initial compromise to critical systems.&nbsp;</li>
	<li>A <b>board briefing deck</b>&nbsp;that enables CISOs to benchmark and walk through their own resilience posture and AI exposure - ready to present as their own.&nbsp;</li>
	<li>An&nbsp;<strong>AI threat brief</strong>&nbsp;that explains to a board the best AI strategy is one that doesn&#39;t chase&nbsp;AI threats - it contains them.&nbsp;</li>
</ul>

<p>This is not another vulnerability scan.&nbsp;</p>

<p>It does not produce a longer list of defects for an already overloaded team to remediate. It answers the question traditional vulnerability management leaves unresolved:&nbsp;</p>

<p><strong>What can an attacker do after exploiting one of them?&nbsp;</strong></p>

<h2>Stop Racing. Start Containing.&nbsp;</h2>

<p>Microsoft and Google deserve credit for finding and fixing vulnerabilities before more attackers can exploit them. Organizations should deploy those fixes as quickly and safely as possible.&nbsp;</p>

<p>But patching 570 vulnerabilities every Patch Tuesday cannot become the blueprint for the future.&nbsp;</p>

<p>Mythos and frontier models that follow it will find more flaws. Attackers will automate more of the attack chain. Security teams will receive more signals, more patches, more exposure data, and less time to make decisions.&nbsp;</p>

<p>CISOs cannot hire enough people or buy enough detection tools to win that race indefinitely.&nbsp;</p>

<p>The answer is an architecture that expects vulnerabilities, assumes compromise, and prevents the attacker from turning initial access into business disruption. The answer is called Microsegmentation. No matter what happens, the business is always up and running.&nbsp;</p>

<p>Build one where the next 1,000 vulnerabilities cannot become the next crisis.&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Building Cyber Resilience in Financial Services: 6 Real-World Success Stories</title>
          <link>https://zeronetworks.com/blog/building-cyber-resilience-in-financial-services-6-real-world-success-stories</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Mon, 13 Jul 2026 21:58:00 +0000</pubDate>
          <dc:date>Mon, 13 Jul 2026 21:58:00 +0000</dc:date>
          <category><![CDATA[Network Security]]></category>
          <dc:subject><![CDATA[Network Security]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/building-cyber-resilience-in-financial-services-6-real-world-success-stories#When:1218</guid>
          <description><![CDATA[In financial services organizations, the systems cyber attackers most want to reach are also the most critical to business operations. Meanwhile, legacy infrastructure resists change, auditors and pen testers keep finding the same gaps, and AI-driven vulnerability discovery is collapsing the time between disclosure and exploitation, so the cost of standing still keeps climbing &ndash; but simply patching faster isn&rsquo;t a viable solution. &nbsp; This roundup features six Zero Networks&#8230;]]></description>
          <content:encoded><![CDATA[<p>In <a href="https://zeronetworks.com/resource-center/brochures/zero-networks-effortless-microsegmentation-for-financial-institutions">financial services organizations</a>, the systems cyber attackers most want to reach are also the most critical to business operations. Meanwhile, legacy infrastructure resists change, auditors and pen testers keep finding the same gaps, and <a href="https://zeronetworks.com/blog/protecting-against-mythos-daybreak-and-beyond-frontier-ai-security">AI-driven vulnerability discovery</a> is collapsing the time between disclosure and exploitation, so the cost of standing still keeps climbing &ndash; but simply patching faster isn&rsquo;t a viable solution. &nbsp;</p>

<p>This roundup features six <a href="https://zeronetworks.com/company/customer-stories">Zero Networks customers</a>, spanning private credit, investment banking, wealth management, and beyond, who <a href="https://zeronetworks.com/resource-center/topics/network-security-fundamentals-what-it-is-why-it-matters">closed network security gaps</a> without the operational complexity and outage risks that had stalled prior attempts. &nbsp;</p>

<p>We&rsquo;ll walk through how these firms <a href="https://zeronetworks.com/platform">leveraged automated, identity-driven microsegmentation</a> to secure legacy systems, enforce granular controls without breaking critical connections, mitigate recurring pen test and audit findings, and <a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">build architectures designed to contain</a> vulnerabilities that can&#39;t yet be patched. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/brochures/zero-networks-effortless-microsegmentation-for-financial-institutions"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Blog_Callout_-_Financial_Serevices_Infosheet_Download_%281%29.png" /></a></p>

<h2>Legacy Complexity in Enterprise Networks: Closing Security Gaps &nbsp;</h2>

<p>Inherited infrastructure is the norm in financial services and enterprise orgs. Assets accumulate across years of mergers and vendor decisions, often maintained by separate teams with no unified network visibility. This leaves security teams to face a forced trade-off: accept protection gaps, or risk operational disruptions by enforcing granular controls. &nbsp;</p>

<h3>Real-World Examples &nbsp;</h3>

<p><a href="https://zeronetworks.com/company/customer-stories/shielding-90b-in-capital-under-management-from-cyber-threats">Antares Capital</a> is one of the largest direct lenders in the US and is responsible for $60B+ in middle-market lending. Their team recognized lateral movement as a portfolio risk as much as a security risk. But disparate legacy assets made it difficult to get a complete view of the network, so the team struggled to determine which ports were actually necessary for business operations. &nbsp;</p>

<p>Similarly, <a href="https://zeronetworks.com/resource-center/videos/risky-business-interview-aaron-steinke-of-la-trobe-financial-talks-about-zero-networks">La Trobe Financial</a>&rsquo;s environment had been evolving since the 1980s, leaving the security team to untangle decades of legacy complexity. As one of Australia&rsquo;s leading and most trusted alternative asset managers &ndash; and responsible for securing over $20B in assets &ndash; La Trobe understood the urgent need to close legacy enterprise security gaps, but many systems were so deeply embedded in critical operations that replacing them would require years of effort and millions of dollars. &nbsp;</p>

<blockquote>
<p>Other microsegmentation products work if you&rsquo;re in a cloud native environment &ndash; if everything is modern, shiny, and new &ndash; down here in the real world, we have to deal with some pretty horrible old school protocols that don&rsquo;t play nice.</p>

<p>- Aaron Steinke, Head of Infrastructure, La Trobe Financial &nbsp;</p>
</blockquote>

<h3>The Solution: Full Network Visibility and Agentless Integration &nbsp;</h3>

<p>Antares Capital and La Trobe Financial solved their enterprise legacy complexity challenges with Zero&rsquo;s deterministic automation engine and agentless approach: &nbsp;</p>

<ul>
	<li>Automated discovery of all network assets and identities &ndash; including legacy systems &ndash; uncovered traffic patterns and dependencies across previously siloed environments. &nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">Deterministic, human-on-the-loop automation</a> fuels policy creation and enforcement, enabling precise rules that scale protection to legacy systems without risking disruption.&nbsp;</li>
	<li>Agentless architecture deploys in minutes by leveraging native, host-based firewalls, enabling a seamless fit with legacy systems &ndash; without introducing latency. &nbsp;</li>
</ul>

<p>By integrating with existing infrastructure and unlocking <a href="https://zeronetworks.com/platform/network-map">end-to-end network visibility</a>, Zero Networks removed the legacy barriers that stand in the way of comprehensive <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">microsegmentation</a> for many financial and enterprise institutions. &nbsp;</p>

<p>As a result, <strong>Antares reached full segmentation in under three months</strong>, freeing 10+ hours a week across cloud and networking teams; La Trobe reached a security posture its team described as historically "out of reach," <strong>without a multi-year, multi-million-dollar modernization project</strong>. &nbsp;</p>

<h2>Implementing Microsegmentation without Disrupting Critical Operations&nbsp;</h2>

<p>Even when legacy complexity is not the primary barrier to a more robust network security posture, financial services organizations often hesitate to implement granular network segmentation for fear that it will break something &ndash; will enforcement disrupt the trading systems, client workflows, or applications the business depends on? Overly complex tools and unsustainable manual burdens can break critical connections outright or leave gaps and inconsistencies that risk continuity over time. &nbsp;</p>

<h3>Real-World Examples &nbsp;</h3>

<p><a href="https://zeronetworks.com/company/customer-stories/replaced-an-overly-complex-microsegmentation-solution">Baron Funds</a> oversees ~$49B in client assets, making continuity and access integrity extremely critical. After <a href="https://zeronetworks.com/blog/modern-vs-legacy-microsegmentation-what-to-look-for-in-todays-top-solutions">other microsegmentation solutions</a> broke the network, the organization was hesitant to move forward, but pen testing reinforced the need for more granular segmentation. &nbsp;</p>

<p><a href="https://zeronetworks.com/company/customer-stories/block-lateral-movement-and-control-every-network-identity">Evercore</a> faced the same underlying concern. A leading global independent investment bank, Evercore needed to <a href="https://zeronetworks.com/blog/how-to-prevent-lateral-movement-cybersecurity-risks-strategies">shut down lateral movement</a> across a complex, high-value enterprise environment without adding operational friction or deploying intrusive agents. But traditional approaches &ndash; manual access controls, privileged group clean-up, and firewall-based segmentation &ndash; required an extraordinary amount of effort that made inconsistencies inevitable and still left exploitable pathways open. &nbsp;</p>

<h3>The Solution: Deterministic Automation and Living-off-the-Land Defense &nbsp;</h3>

<p>Baron Funds and Evercore confidently embraced microsegmentation by removing the manual effort, guesswork, and operational complexity of legacy solutions with Zero Networks: &nbsp;</p>

<ul>
	<li>Policies are built from observed traffic and network behavior over a defined learning period, rather than manually assembled rule sets that require guesswork and introduce human error at scale. &nbsp;</li>
	<li>Deterministic, human-on-the-loop automation eliminates unsustainable manual effort without removing human judgement entirely from the equation. &nbsp;</li>
	<li>Orchestration of the native controls that already exist in today&rsquo;s environments enable a non-disruptive, &ldquo;living-off-the-land&rdquo; defense.&nbsp;</li>
</ul>

<blockquote>
<p>[Zero Networks] actually uses technology that we already have &ndash; it&rsquo;s technology that we&rsquo;ve already had on the network for 20 years. For as long as we&rsquo;ve had firewalls, we could have done this. We just couldn&rsquo;t manage the firewall at scale. You couldn&rsquo;t manage the firewall intelligently. We had every piece of the solution there &ndash; what we did not have was the brains.&#8239;&#8239;&nbsp;&nbsp;</p>

<p>- Henry Mayorga, CISO, Baron Funds&nbsp;</p>
</blockquote>

<p>By accurately automating rules based on learned network realities and enforcing them via native controls, Zero Networks gave both organizations the confidence to enforce granular segmentation without betting business continuity on an untested rule set or an unsustainable manual process. As a result, Baron Funds reached <strong>full segmentation in 30 days with zero disruptions to network traffic</strong>; Evercore <strong>locked down lateral movement across the entire enterprise from a single platform</strong>, managed by a single part-time administrator.&nbsp;</p>

<p>As a Banking IT Manager <a href="https://www.gartner.com/reviews/market/network-security-microsegmentation/vendor/zero-networks/product/zero-networks-segment/review/view/6667150">pointed out in a Gartner Peer Insights review</a>, the value of these results compounds at scale: &nbsp;</p>

<div style="background:#eeeeee;border:1px solid #cccccc;padding:5px 10px;"><em>&ldquo;I had a very realistic outlook on implementing Microsegmentation in a dynamic and complex environment. I was blown away by the volume and accuracy of the Zero Networks automation engine &hellip; It would have been impossible for our team to create and implement 16,000+ rules.&rdquo;&nbsp;</em></div>

<div style="background:#eeeeee;border:1px solid #cccccc;padding:5px 10px;">IT Manager, Banking, 3B &ndash; 10B USD Firm Size&nbsp;</div>

<h2>Pen Tests, Audits, and Cyber Compliance Requirements: Prioritizing and Validating Controls&nbsp;</h2>

<p>Penetration tests and <a href="https://zeronetworks.com/blog/cybersecurity-compliance-playbook-standards-requirements-best-practices">compliance requirements</a> are some of the most common forcing functions for microsegmentation initiatives &ndash; especially in highly regulated industries like financial services. But pen tests and audits don&rsquo;t only expose gaps to help security leaders prioritize strategies, they also validate the impact of controls. &nbsp;</p>

<h3>Real-World Examples &nbsp;</h3>

<p>Auditors had repeatedly flagged a specific gap with La Trobe Financial: the absence of MFA on <a href="https://zeronetworks.com/blog/the-4-protocols-driving-enterprise-risk-in-2026">high-risk protocols like RDP</a> and SSH. But prior attempts to implement MFA on admin protocols and legacy systems had introduced latency, bugs, or errors severe enough to make the fix impractical.&nbsp;</p>

<p><a href="https://zeronetworks.com/company/customer-stories/automated-microsegmentation-in-30-days">ACT Commodities</a> &ndash; a leading global provider of market-based sustainability solutions &ndash; uncovered the scale of exposure across its Azure Cloud environment the same way. Pen testers could access the environment and exfiltrate data within just five minutes, but reimplementing firewalls, adjusting configurations, and completing the other tasks necessary to protect servers proved too difficult.&nbsp;</p>

<p>Like many financial services organizations, diversified holding company <a href="https://zeronetworks.com/resource-center/videos/aaron-goodwin-of-briley-financial-talks-about-zero-networks">B. Riley Financial</a> saw the same security gaps surface in pen test results year after year but faced an impossible tradeoff: address persistent findings and disrupt key operations or live with known risks to maintain business as usual.&nbsp;</p>

<blockquote>
<p>There were a lot of years of doing penetration testing and coming up with similar results. There was always a critical. There was always a high. There were always multiples. And we just couldn&rsquo;t stop those from reoccurring; no matter what we did, those same things would just show up again &ndash; we thought we had it fixed and then we&rsquo;d find out a year later that we still had that issue.&rdquo;</p>

<p>- Aaron Goodwin, CISO, B. Riley Financial &nbsp;</p>
</blockquote>

<h3>The Solution: Closing Gaps by Default with Containment Architecture&nbsp;</h3>

<p>La Trobe, ACT Commodities, and B. Riley all closed exploitable pathways before a pen test or audit could find them, rather than remediating findings one at a time after the fact &ndash; if at all. With Zero Networks, these financial services orgs implemented comprehensive microsegmentation and <a href="https://zeronetworks.com/resource-center/guides/resilient-by-design-architecting-security-that-keeps-operations-running">built containment into the network architecture</a> via capabilities like: &nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/blog/mfa-is-our-dna-zero-networks-multi-factor-segmentation">Network-layer MFA</a> that extends authentication to high-risk protocols like RDP and SSH without touching the underlying legacy systems or introducing new points of failure.&nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">Least-privilege access</a> enforced by default, closing the specific pathways that attackers &ndash; and therefore, pen testers &ndash; rely on, rather than depending on manual review to catch every gap.&nbsp;</li>
	<li>Continuous, automated policy enforcement generates audit-ready evidence as a byproduct of normal operation.&nbsp;</li>
</ul>

<p>By closing gaps structurally rather than chasing them one finding at a time, security teams turn audits and pen tests from a source of stress to a validation exercise. For example, after implementing Zero Networks, La Trobe <strong>closed the exact MFA gap auditors had consistently flagged without breaking legacy systems</strong>; ACT Commodities&#39; five-minute <strong>breach window closed entirely</strong>, with later pen tests revealing <strong>unwanted lateral movement was completely blocked and contained</strong>; and B. Riley finally received <strong>a penetration test report with no high alerts</strong>, closing out a cycle of findings that had persisted for years.&nbsp;</p>

<blockquote>
<p>We had six findings in our penetration test, and every one of them would have been prevented or mitigated with Zero Networks. There&rsquo;s not one other product we have that could have come close... Zero Networks is a cornerstone piece of security technology.</p>

<p>Chris Turek, Former CIO, Evercore&nbsp;</p>
</blockquote>

<h2>Containing Vulnerabilities Before Patching: Preemptive Security in the Frontier AI Era&nbsp;</h2>

<p>Security teams have long faced an uphill battle keeping up with day-to-day <a href="https://zeronetworks.com/resource-center/topics/preventing-vulnerability-exploitation-a-guide-to-cybersecurity-trends-and-cves">vulnerability management.</a> The issue has compounded in this age of frontier AI, where <a href="https://zeronetworks.com/blog/protecting-against-mythos-daybreak-and-beyond-frontier-ai-security">models like Mythos and Daybreak</a> can find, analyze, and generate exploits for vulnerabilities at a speed and scale no human team can match. &nbsp;</p>

<p>For example,&#8239;<a href="https://cyberscoop.com/anthropic-mythos-software-flaws-glasswing/">Mythos found over 10,000 previously unknown vulnerabilities</a>&#8239;in seven weeks, including bugs that had evaded automated detection for decades.&#8239;The window between disclosure and exploitation has collapsed. Even if vendors release mountains of patches to mitigate this influx of discovered vulnerabilities, organizations face an impossible tradeoff: patch immediately and manage updates that contain thousands of fixes at a time, or wait and prioritize while accepting risk exposure. &nbsp;</p>

<p>Instead, financial institutions need a way to protect uptime before patches exist, or while validating that patches won&rsquo;t cause unintended operational disruptions. &nbsp;</p>

<h3>Real-World Examples&nbsp;</h3>

<p><a href="https://zeronetworks.com/blog/ciso-insights-how-to-pass-every-penetration-test">B. Riley Financial faced versions of the vulnerability exposure problem</a> multiple times. In one case, a Microsoft Outlook vulnerability involving outbound SMB traffic left the firm exposed with no patch available from the vendor. Waiting for a fix meant leaving the exposure open.&nbsp;</p>

<div style="background:#eeeeee;border:1px solid #cccccc;padding:5px 10px;">&ldquo;We stay on top of [patching], but it&rsquo;s always a grueling cycle. You still have to have time to test those patches with the different groups, different systems, different operating systems &hellip; Patching will only go so far. What can we do to stop or break the cycle of the attack?&rdquo;&nbsp;</div>

<div style="background:#eeeeee;border:1px solid #cccccc;padding:5px 10px;">- Aaron Goodwin, CISO, B. Riley Financial&nbsp;</div>

<h3>The Solution: Structural Containment as a Buffer Against Unpatched Risk&nbsp;</h3>

<p>With Zero Networks, B. Riley deployed a targeted rule blocking outbound SMB traffic from Outlook to the internet, closing the specific path the vulnerability relied on. &nbsp;</p>

<div>
<div style="padding:100% 0 0 0;position:relative;"><iframe allow="autoplay; fullscreen; picture-in-picture; clipboard-write; encrypted-media; web-share" frameborder="0" referrerpolicy="strict-origin-when-cross-origin" src="https://player.vimeo.com/video/1152718170?badge=0&amp;autopause=0&amp;player_id=0&amp;app_id=58479" style="position:absolute;top:0;left:0;width:100%;height:100%;" title="How to Pass Every Pen Test [B. Riley] Webinar Snippet"></iframe></div>
<script src="https://player.vimeo.com/api/player.js"></script></div>

<p>And critically, this is just one example of how a <a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">cyber resilient network architecture</a> designed for containment protects financial institutions against vulnerabilities without patching. More broadly, <a href="https://zeronetworks.com/platform/network-segmentation">automated, identity-driven microsegmentation</a> buys security teams time to patch safely by: &nbsp;</p>

<ul>
	<li>Closing unnecessary access paths by default, limiting what any unpatched vulnerability can reach, regardless of how it was discovered &ndash; or how quickly.&nbsp;</li>
	<li><a href="https://zeronetworks.com/blog/stopping-privilege-escalation-how-to-neutralize-stolen-credential-threats">Constraining privileged access</a> to explicitly authorized identities, so admin protocols aren&rsquo;t lateral movement highways. &nbsp;</li>
	<li>Scaling protection across the entire network, including OT and legacy systems that can&rsquo;t always be patched on short notice &ndash; or at all. &nbsp;</li>
</ul>

<blockquote>
<p>Having microsegmentation in place has really given us a precautionary protection layer so we can delay applying some of these patches. This gives us plenty of time to test, make sure everything&rsquo;s working, and then apply it, but still have that protection layer in place.&nbsp;</p>

<p>- Aaron Goodwin, CISO, B. Riley Financial &nbsp; &nbsp;</p>
</blockquote>

<h2>Cyber Resilience for Financial Services: Build a Self-Defending Architecture with Zero Networks &nbsp;</h2>

<p>Legacy complexity, operational disruption risk, compliance pressure, and accelerating vulnerabilities are distinct challenges almost every financial institution faces, but they can all be solved with <a href="https://zeronetworks.com/platform">a single platform</a>. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/guides/mfa-powered-microsegmentation-for-financial-services"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Blog_Callout_-_Financial_Services_Buyer_s_Guide_Download_%281%29.png" /></a></p>

<p>By delivering automated discovery across legacy and modern assets alike, a deterministic policy engine that builds and enforces rules from real traffic and identity behavior, agentless integration with existing infrastructure, and network-layer MFA for privileged access, Zero Networks enables financial services orgs to <a href="https://zeronetworks.com/resource-center/videos/self-defending-by-design-the-future-of-cybersecurity-defense">build a self-defending network architecture</a> that proactively blocks attacks without disrupting the business. &nbsp;</p>

<p>See how Zero Networks makes cyber resilience practical for financial institutions &ndash; <a href="https://zeronetworks.com/request-demo">request a demo</a>.&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>How to Automatically Generate Least-Privilege Policies Based on Network Behavior</title>
          <link>https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Fri, 10 Jul 2026 19:45:00 +0000</pubDate>
          <dc:date>Fri, 10 Jul 2026 19:45:00 +0000</dc:date>
          <category><![CDATA[Identity Access Control]]></category>
          <dc:subject><![CDATA[Identity Access Control]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/how-to-automatically-generate-least-privilege-policies-based-on-network-behavior#When:1215</guid>
          <description><![CDATA[The principle of least privilege states that a user, process, or system should receive only the minimum level of access required to perform its intended function &ndash; and virtually every security leader agrees. &nbsp; But scaling least privilege enforcement across sprawling, multi-business-unit enterprise networks with tens of thousands of assets takes more effort and resources than most teams can spare. As a result, 99% of identities still hold excessive permissions. &nbsp; Rather than&#8230;]]></description>
          <content:encoded><![CDATA[<p>The <a href="https://zeronetworks.com/blog/a-practical-guide-to-least-privilege-access-zero-trust-security-in-action">principle of least privilege</a> states that a user, process, or system should receive only the minimum level of access required to perform its intended function &ndash; and virtually every security leader agrees. &nbsp;</p>

<p>But scaling least privilege enforcement across sprawling, multi-business-unit enterprise networks with tens of thousands of assets takes more effort and resources than most teams can spare. As a result, <a href="https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report">99% of identities</a> still hold excessive permissions. &nbsp;</p>

<p>Rather than relying on manual processes to generate and enforce least privilege access policies, security teams can <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">leverage deterministic automation</a> for adaptive, accurate policies &ndash; without the manual overhead. We&rsquo;ll walk through how least privilege policy automation works and share tips for unlocking <a href="https://zeronetworks.com/blog/how-to-measure-cyber-resilience-zero-trust-roi">Zero Trust outcomes</a> faster. &nbsp;</p>

<h3>Key Answers&nbsp;&nbsp;</h3>

<ul>
	<li><strong>Which tools or solutions help enforce the principle of least privilege?</strong> <a href="https://zeronetworks.com/platform">Identity-aware microsegmentation</a> and just-in-time MFA &ndash; powered by an automated policy engine that continuously learns network behavior &ndash; are the core mechanisms. Together, they restrict every connection to the access that&rsquo;s operationally necessary for only as long as it&rsquo;s necessary. &nbsp;</li>
	<li><strong>What tools help automatically generate least-privilege policies based on observed network traffic?</strong> Solutions powered by deterministic automation engines that continuously monitor network activity, build a behavioral baseline from observed connections, and generate policy directly from that baseline. For example, Zero Networks learns all network connections over a 30-day period before leveraging those insights to build deterministic, highly accurate firewall rules and policies that adapt dynamically across networks spanning multiple data centers, cloud regions, and business units. This keeps least privilege enforcement accurate and simple even for the largest, most complex orgs.&nbsp;</li>
	<li><strong>How can security teams automatically learn and map network connections to create access policies?</strong> <a href="https://zeronetworks.com/platform/network-map">Real-time monitoring</a> that captures which identities and assets communicate, over what protocols, and how frequently can be used as the direct input for policy generation rather than relying on assumed or documented access requirements.&nbsp;</li>
	<li><strong>Do AI-generated least privilege policies rely on determinism?</strong> No. AI-generated policies are typically probabilistic, based on statistical inference. Deterministic automation generates and enforces policies directly from observed behavior using fixed logic and producing a traceable, precise rule rather than a likely guess.&nbsp;</li>
</ul>

<h2>Automating Least Privilege Access to Accelerate Zero Trust &nbsp;</h2>

<p><a href="https://zeronetworks.com/resource-center/topics/zero-trust-security-a-complete-guide-to-principles-architecture-and-best-practices">Zero Trust security</a>&#8239;is based on the philosophy &ldquo;never trust, always verify.&rdquo; Enforcing least privilege by default is a non-negotiable tenet of Zero Trust &ndash; while Zero Trust defines the philosophy, least privilege enforces the mechanics. &nbsp;</p>

<p>Modern <a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">Zero Trust architectures</a>&#8239;apply least privilege across human identities, machine-to-machine communications, APIs, AI agents, and service accounts.&#8239;<a href="https://zeronetworks.com/blog/network-segmentation-all-you-need-to-know">Network segmentation</a>, identity segmentation, and <a href="https://zeronetworks.com/blog/what-is-multi-factor-authentication-mfa">just-in-time&#8239;multi-factor authentication (MFA)</a>&#8239;are the solutions that make this comprehensive coverage possible &ndash; but it&rsquo;s only achievable at scale when automated. &nbsp;</p>

<p>AI agents introduce a new challenge &ndash; unlike a static service account, an agent&rsquo;s access needs can shift from task to task. <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP&rsquo;s Agentic Applications Top 10 Project</a> addresses this directly through its Least Agency principle, which calls for constraining an agent&rsquo;s autonomy, tool access, and decision-making authority to limit the blast radius of prompt injection or compromised agents.&nbsp;</p>

<h3>Manual Policy Creation Challenges: Static Rules, Security Gaps, and Scale &nbsp;</h3>

<p>Manual policy management has a structural ceiling. Rules are typically written from assumptions about what a role or service account <em>should</em> need, and those assumptions rarely stand up to network realities. So, when least privilege policies are a primarily manual effort, a few common challenges emerge: &nbsp;</p>

<ul>
	<li>Static rules go stale almost immediately &nbsp;&nbsp;</li>
	<li>Security gaps or operational breakage as assumed access requirements produce either overly permissive rules that leave too much room for lateral movement, or overly restrictive ones that break legitimate traffic&nbsp;</li>
	<li>A scale problem headcount can&#39;t fix &nbsp;</li>
</ul>

<p>As Gartner points out&#8239;in its report,&#8239;<a href="https://zeronetworks.com/resource-center/reports/gartner-reimagining-network-microsegmentation"><em>Reimagining Network Microsegmentation: Beyond the IP &ndash; Identity, Context, and Agentless Innovation</em></a>, continued reliance on static rules leaves organizations especially vulnerable to AI-driven attacks. &nbsp;</p>

<blockquote>
<p>Vendors clinging to manual policies face rapid obsolescence, as these methods are completely incapable of securing dynamic hybrid networks against lateral movement.</p>

<p>- Gartner &nbsp;</p>
</blockquote>

<h3>Deterministic Automation vs. Probabilistic Models &nbsp;</h3>

<p>As manual policy management becomes untenable, many cybersecurity tools have rushed to fill the gap with AI capabilities. But AI-generated least-privilege policies aren&#39;t the same as ones built through deterministic automation. &nbsp;</p>

<p>Probabilistic AI models produce outputs based on statistical likelihood; deterministic automation engines rely entirely on learned realities.&nbsp;</p>

<table border="1" cellpadding="1" cellspacing="1">
	<thead>
		<tr>
			<th scope="col">&nbsp;</th>
			<th scope="col">Deterministic Automation</th>
			<th scope="col">Probabilistic (AI) Models</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<th scope="row">Policy is based on</th>
			<td>Directly observed network behavior</td>
			<td>Statistical inference about likely behavior</td>
		</tr>
		<tr>
			<th scope="row">Result</th>
			<td>A traceable rule tied to real activity</td>
			<td>A likely-correct guess</td>
		</tr>
		<tr>
			<th scope="row">Best suited for</th>
			<td>Enforcement decisions</td>
			<td>Visibility, investigation, pattern-surfacing</td>
		</tr>
	</tbody>
</table>

<p>A rule that&#39;s 99% accurate is still wrong enough to break applications or leave security gaps open, which is why AI adoption for security policies is often hindered by <a href="https://zeronetworks.com/blog/network-microsegmentation-in-2026-gartner-research-takeaways">what Gartner calls &ldquo;enforcement anxiety&rdquo;</a> &ndash; the fear that probabilistic algorithms will disrupt business operations. For enterprises that want to automate least privilege policy creation and enforcement at scale but can&rsquo;t risk operational continuity, deterministic engines offer the best of both worlds.</p>

<h2>How Deterministic Least Privilege Policy Generation Works &nbsp;</h2>

<p>Automating least privilege access means translating raw network activity insights to enforceable rules &ndash; in practice, that process occurs in four stages. &nbsp;</p>

<h3>1. Observing Real Traffic to Build a Behavioral Baseline&nbsp;</h3>

<p>Before any policy can be written, a comprehensive <a href="https://zeronetworks.com/platform/network-map">picture of what&#39;s actually happening on the network</a> must be established: which assets and identities communicate, over which ports and protocols, how frequently, and in what direction. This learning period requires continuous observation to build a knowledge base of existing network communication patterns, including logon activity, account behavior, and asset access patterns tied to specific identities&nbsp;&ndash; even across networks with hundreds of thousands of connections and complex identity hierarchies.</p>

<h3>2. Translating Observed Behavior into Enforceable Rules&nbsp;</h3>

<p>Once a behavioral baseline exists, an automation engine can use it to generate precise policies scoped to what&#39;s been observed as necessary for each asset and identity. This is the step that makes the approach deterministic rather than probabilistic &ndash; the policy isn&#39;t inferred from a model&#39;s best guess about likely access needs; it&#39;s derived directly from what was actually observed. That distinction is what allows the resulting rules to walk a fine line: tight enough to constitute <a href="https://zeronetworks.com/blog/perimeter-based-to-identity-centric-enforcing-least-privilege-access-everywhere">genuine least privilege</a> and precise enough to ensure legitimate traffic remains unaffected.&nbsp;</p>

<h3>3. Optional Simulation and Review Before Enforcement&nbsp;</h3>

<p>Even when policies are built from real behavior, most enterprises want an added layer of certainty that enforcement won&rsquo;t break anything. Before any rule goes live, a human on the loop should have the option to simulate its impact &ndash; testing the policy against real traffic in a sandbox environment for visibility into what it would allow and block before it affects production. &nbsp;</p>

<h3>4. Keeping Policy Aligned as Behavior Changes&nbsp;</h3>

<p>Generating an accurate least privilege policy once is only half the problem. Modern enterprise networks evolve constantly &ndash; new assets appear, old ones get decommissioned, and applications shift how they communicate.&nbsp;Or, new business units get acquired, old ones get divested, and applications shift how they communicate &ndash; enterprises need dynamic policy coverage.&nbsp;<a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">Automated lifecycle management</a> keeps policies current in dynamic environments: access paths that go unused get closed, new patterns are incorporated, and rule sprawl is structurally prevented rather than periodically cleaned up after the fact. Always-current <a href="https://zeronetworks.com/blog/how-real-time-network-visibility-enables-automated-zero-trust-enforcement">network visibility fuels the deterministic automation engine</a>, enabling an adaptive least privilege posture. &nbsp;</p>

<h2>Automating Least Privilege Enforcement to Strengthen Business Resilience &nbsp;</h2>

<p>By scaling least privilege across the full enterprise with automation, security teams drastically change the math on what happens when something goes wrong. Because access is continuously scoped to observed network behavior and aligned to business need rather than defaulting to what was granted once and forgotten, breaches are automatically constrained &ndash; regardless of how they start. That translates directly into the <a href="https://zeronetworks.com/blog/what-is-cyber-resilience-how-to-protect-business-continuity">resilience outcomes</a> security leaders need to show the business:&nbsp;</p>

<ul>
	<li><strong><a href="https://zeronetworks.com/blog/what-is-blast-radius-in-cybersecurity-best-practices-for-breach-containment">Smaller blast radius</a> by default: </strong>access never exceeds what&#39;s necessary, significantly reducing the threat of stolen credentials &nbsp;</li>
	<li><strong>Fewer standing, unused permissions: </strong>the exact accumulation attackers rely on to escalate privileges while evading detection gets closed continuously &nbsp;</li>
	<li><strong>Faster containment:</strong> lateral movements pathways that were never open in the first place don&#39;t need to be shut down mid-incident&nbsp;</li>
	<li><strong>Enforcement that doesn&rsquo;t drift: </strong>policies adapt as the network changes, enabling demonstrable compliance and uptime protection &nbsp;</li>
</ul>

<h3>Deterministic Policy Automation: Real-World Example&nbsp;</h3>

<p><a href="https://zeronetworks.com/company/customer-stories/securing-the-infrastructure-behind-21-of-global-shipping">Mediterranean Shipping Company (MSC)</a> operates one of the largest-scale and complex logistics networks in the world, moving 21% of global shipping across a massive footprint of ports, vessels, and facilities spanning dozens of countries. Uptime is nonnegotiable and instability is unacceptable; still, the organization needed a way to strengthen internal defenses. &nbsp;</p>

<p>Manual segmentation was slow to scale, requiring countless hours of log analysis and manual rule maintenance for only partial coverage. Limited visibility into internal traffic patterns further complicated policy creation. &#8239;&nbsp;</p>

<p>MSC offloaded the manual effort of discovery, learning, and policy management to Zero&rsquo;s deterministic automation engine, successfully segmenting roughly 95% of its servers. &nbsp;</p>

<blockquote>
<p>What once took more than a year of manual work and endless log analysis is now fully automated. We&rsquo;ve segmented about 95% of our environment, gained complete visibility into network activity, and dramatically strengthened our defenses.</p>

<p>- <a href="https://zeronetworks.com/company/customer-stories/securing-the-infrastructure-behind-21-of-global-shipping">Sergio Fedelini, SVP, IT Infrastructure, MSC</a></p>
</blockquote>

<h3>Build a Self-Defending Network Architecture with Zero Networks &nbsp;</h3>

<p>Zero provides immediate visibility into every identity and asset on the network, monitors and learns all network connections, then automatically generates and enforces identity-aligned least privilege policies to <a href="https://zeronetworks.com/blog/how-to-prevent-lateral-movement-cybersecurity-risks-strategies">prevent lateral movement</a> by default. Our comprehensive solution operationalizes the principle of least privilege across every axis of network traffic:&nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/platform/network-segmentation"><strong>Automated microsegmentation</strong></a>&#8239;isolates every asset within its own secure perimeter, closing unnecessary communication paths without disrupting operations.&#8239;&nbsp;</li>
	<li><a href="https://zeronetworks.com/platform/identity-segmentation"><strong>Identity segmentation</strong></a>&#8239;enforces granular access rules for users, devices, and applications, ensuring every connection is explicitly authorized. &#8239;&nbsp;</li>
	<li><a href="https://zeronetworks.com/use-cases/apply-mfa-to-anything"><strong>Just-in-time network-layer MFA</strong></a>&#8239;adds adaptive authentication at the moment of privileged access, turning static permissions into temporary access. &#8239;&nbsp;</li>
	<li><strong>Deterministic, highly accurate automation</strong> learns all network behavior to create and enforce least privilege policies at scale.&#8239;&nbsp;</li>
</ul>

<p>Learn how you can automatically generate least privilege policies that dynamically adapt as your network evolves &ndash;&nbsp;<a href="https://zeronetworks.com/request-demo">request a demo</a>. &#8239;&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>CISO&#8217;s Guide to Business Impact Analysis: 3 Steps to Strengthen Cyber Resilience</title>
          <link>https://zeronetworks.com/blog/cisos-guide-to-business-impact-analysis-3-steps-to-strengthen-cyber-resilience</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Wed, 08 Jul 2026 20:08:00 +0000</pubDate>
          <dc:date>Wed, 08 Jul 2026 20:08:00 +0000</dc:date>
          <category><![CDATA[Operational &amp; Cyber Resilience]]></category>
          <dc:subject><![CDATA[Operational &amp; Cyber Resilience]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/cisos-guide-to-business-impact-analysis-3-steps-to-strengthen-cyber-resilience#When:1212</guid>
          <description><![CDATA[After gaining initial access, attackers begin moving laterally in as little as 27 seconds &ndash; and a single compromised host directly exposes 85% of the environment. Still, it takes an average of 200+ days to identify and contain a breach. &nbsp; As models like Mythos, Daybreak, and other tools attackers weaponize for AI-driven exploits compress the window between initial compromise and business disruption even further, time is no longer on the defender&rsquo;s side. Security teams can no&#8230;]]></description>
          <content:encoded><![CDATA[<p>After gaining initial access, attackers begin moving laterally in <a href="https://www.crowdstrike.com/en-us/global-threat-report/">as little as 27 seconds</a> &ndash; and a single compromised host <a href="https://zeronetworks.com/blog/one-compromised-system-and-boom-meet-your-blast-radius">directly exposes 85% of the environment</a>. Still, it takes an average of <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:607b9590-38e0-4c91-b433-aa8a17f5b5e8/original/as/cost-of-a-data-breach-2025-full-report.pdf">200+ days to identify and contain</a> a breach. &nbsp;</p>

<p>As <a href="https://zeronetworks.com/blog/protecting-against-mythos-daybreak-and-beyond-frontier-ai-security">models like Mythos, Daybreak</a>, and other tools attackers weaponize for AI-driven exploits compress the window between initial compromise and business disruption even further, time is no longer on the defender&rsquo;s side. Security teams can no longer afford to plan for prevention; they must engineer for the impact of a breach. &nbsp;</p>

<p>A <a href="https://zeronetworks.com/blog/from-documentation-to-enforcement-translating-bia-to-real-cyber-resilience">business impact analysis (BIA)</a> is a vital step in gaining consequence clarity and tailoring cyber resilience strategies to business and board-level priorities. But all too often, a BIA documents critical systems, the disruptions that would materially impact the organization, and how long the business can tolerate downtime without detailing current exposure or producing cyber resilience priorities. &nbsp;</p>

<p>We&rsquo;ll walk through <a href="https://zeronetworks.com/resource-center/guides/ciso-guide-business-impact-analysis-for-cyber-resilience">a business impact analysis template that translates documented business priorities</a> into actionable cyber resilience enforcement steps, giving CISOs the necessary insights to protect uptime where it matters most. &nbsp;</p>

<h2>How to Conduct a Business Impact Analysis for Cyber Resilience: 3-Step Framework&nbsp;</h2>

<p>A BIA built to produce resilient architecture, not just documentation, moves through three steps: critical asset identification and business exposure quantification, attack path analysis and containment metrics, and investment prioritization. Each step is designed to hand off concrete inputs to the next, ultimately delivering a set of specific intervention priorities tied to specific exposure reductions. &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/guides/ciso-guide-business-impact-analysis-for-cyber-resilience"><img alt="" src="https://zeronetworks.com/images/uploads/blog/BIA_Guide_Download_%281%29.png" /></a></p>

<h3>Step 1: Identify Critical Assets and Quantify Business Exposure&nbsp;</h3>

<p>The first step in resilience-focused business impact analysis is to identify which systems and assets are critical to the strategic success and day-to-day operations of the company. This means evaluating assets across five dimensions of business exposure: &nbsp;</p>

<ol>
	<li><strong>Regulatory Classification:</strong> If an asset contains data that is restricted by regulations, then a compromise could incur fines, time-consuming reporting, and disclosure requirements.&nbsp;</li>
	<li><strong>Revenue Exposure: </strong>If an asset is critical to delivering goods and services or measuring consumption of goods and services, any downtime or breach would disrupt revenue streams and could even force the organization to pay penalties or credits to impacted customers.&nbsp;</li>
	<li><strong>Financial Sensitivity: </strong>If an asset has the ability to issue or redirect payments, compromise could impact the organization&rsquo;s operational cash flow.&nbsp;</li>
	<li><strong>Customer Notification Requirements: </strong>If customer notification processes &ndash; often tied to revenue exposure and regulatory classification &ndash; are required due to a cyber incident, they can impact ongoing customer conversations and sales cycles. &nbsp;</li>
	<li><strong>Reputational Sensitivity: </strong>If assets containing data or conducting functions that are core to the organization&rsquo;s communications or value proposal are impacted by a breach, it could cause reputational harm.&nbsp;</li>
</ol>

<p>Identifying business-critical systems requires collaboration across multiple stakeholders &ndash; CISOs need to gather information from CROs, CIOs, COOs, and business unit leaders to fully grasp the organization&rsquo;s overall risk exposure and the disruptions that would materially impact uptime, revenue, or customer commitments, ensuring the assessment reflects real-world operational priorities. &nbsp;</p>

<p>Following this step, CISOs should have a preliminary list of critical assets, enough information to justify <em>why</em> it&rsquo;s critical, and a baseline estimation of the business impact if a compromise occurred. &nbsp;</p>

<h3>Step 2: Analyze Attack Paths Against Containment Metrics &nbsp;</h3>

<p>With an inventory of critical assets and an understanding of how downtime would impact the business, CISOs can tackle the question that most urgently affects business continuity: how exposed are critical systems today? &nbsp;</p>

<p><a href="https://zeronetworks.com/resource-center/breach-map"><img alt="" src="https://zeronetworks.com/images/uploads/blog/Breach_Map_Download_%281%29.png" /></a></p>

<p>This is where many BIAs miss out on delivering practical value &ndash; they document priorities on paper without establishing whether critical systems are actually protected or where they&rsquo;re vulnerable. &nbsp;</p>

<p>An attack path analysis evaluates the level of effort it would take an attacker to move from a common ingress point to a business-critical asset. No analysis can comprehensively map every breach scenario, so CISOs should focus on categories that reflect the current threat landscape, like: &nbsp;</p>

<ul>
	<li>Compromised user&nbsp;</li>
	<li>Compromised cloud identity&nbsp;</li>
	<li>Technical perimeter entry&nbsp;</li>
	<li>Trusted vendor/third-party access&nbsp;</li>
</ul>

<p>For each threat category and critical system, security teams should identify the nearest ingress point and map a plausible attack path relative to three containment dimensions: path distance, privilege requirements, and data-layer controls. &nbsp;</p>

<table aria-rowcount="4" border="1" data-tablelook="1184" data-tablestyle="MsoTableGrid" dir="ltr">
	<thead>
		<tr aria-rowindex="1" role="row">
			<th data-celllook="0" role="rowheader" scope="col">
			<p paraeid="{1e4908a2-8100-4388-b538-812d434032f4}{215}" paraid="383932005">Containment Dimension&nbsp;</p>
			</th>
			<th data-celllook="0" role="columnheader" scope="col">
			<p paraeid="{1e4908a2-8100-4388-b538-812d434032f4}{222}" paraid="68759084">What It Measures&nbsp;&nbsp;&nbsp;</p>
			</th>
			<th data-celllook="0" role="columnheader" scope="col">
			<p paraeid="{1e4908a2-8100-4388-b538-812d434032f4}{229}" paraid="1426913898">Specific Details to Capture&nbsp;</p>
			</th>
		</tr>
	</thead>
	<tbody>
		<tr aria-rowindex="2" role="row">
			<th data-celllook="0" role="rowheader" scope="row">
			<p paraeid="{1e4908a2-8100-4388-b538-812d434032f4}{237}" paraid="508423885">Lateral Movement&nbsp;Path Distance: How do I get there?&nbsp;&nbsp;</p>
			</th>
			<td data-celllook="0">
			<p paraeid="{1e4908a2-8100-4388-b538-812d434032f4}{248}" paraid="785317868">How many structural barriers and controls exist between the ingress point for a&nbsp;breach&nbsp;scenario&nbsp;and the&nbsp;critical&nbsp;asset.&nbsp;</p>
			</td>
			<td data-celllook="0">
			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="1" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{16}" paraid="429339906">Authentication boundaries crossed&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="2" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{22}" paraid="1220889257">Network segments traversed&nbsp;&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="3" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{28}" paraid="1403619062">Enforced inspection points in path (proxies, Layer 7 firewalls, etc.)&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="4" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{34}" paraid="1446823224">Cross-domain traversal (on-prem to cloud, cross-tenant, IT/OT, vendor to internal, etc.)&nbsp;</p>
				</li>
			</ul>
			</td>
		</tr>
		<tr aria-rowindex="3" role="row">
			<th data-celllook="0" role="rowheader" scope="row">
			<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{48}" paraid="1200791260">Privilege Requirements: Can I access the resource once&nbsp;I&rsquo;m&nbsp;there?&nbsp;&nbsp;</p>
			</th>
			<td data-celllook="0">
			<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{59}" paraid="1592085386">How difficult it is for an attacker to gain the privileges needed&nbsp;to reach the critical asset.&nbsp;</p>
			</td>
			<td data-celllook="0">
			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="1" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{72}" paraid="1893703436">Escalation levels&nbsp;required&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="2" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{78}" paraid="521534071">Persistent privileged&nbsp;access&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="3" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{84}" paraid="1413229517">Service account density&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="4" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{90}" paraid="495969119">Additional&nbsp;authentication requirements&nbsp;&nbsp;</p>
				</li>
			</ul>
			</td>
		</tr>
		<tr aria-rowindex="4" role="row">
			<th data-celllook="0" role="rowheader" scope="row">
			<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{98}" paraid="658755188">Data Layer Controls: How much damage can I do?&nbsp;&nbsp;</p>
			</th>
			<td data-celllook="0">
			<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{105}" paraid="1867779758">How much damage an attacker could do once they reach the critical asset.&nbsp;</p>
			</td>
			<td data-celllook="0">
			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="1" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{114}" paraid="911927746">Encryption at rest&nbsp;&nbsp;</p>
				</li>
			</ul>

			<ul role="list">
				<li 335552541="" aria-setsize="-1" data-aria-level="1" data-aria-posinset="2" data-font="Symbol" data-leveltext="" data-list-defn-props="{">
				<p paraeid="{2eac279f-49a1-4d19-bbfa-f3cfdbaf4c3a}{120}" paraid="113516941">Identity-based access controls&nbsp;&nbsp;</p>
				</li>
			</ul>
			</td>
		</tr>
	</tbody>
</table>

<p>The result, run across every combination of scenario and critical asset, is a documented map of exposure tied to likely attack tactics rather than a general sense of risk. This breakdown of exposure across all critical assets bubbles up to two enterprise-level risk insights: &nbsp;</p>

<ul>
	<li><strong>Asset-level worst case path:</strong> The compromise scenario that presents the shortest, least obstructed route for an attacker to reach a business-critical system. &nbsp;</li>
	<li><strong>Enterprise-level highest cost path: </strong>The single scenario-to-asset combination with the weakest containment and the highest business exposure &ndash; the easiest attack with the greatest business impact. &nbsp;</li>
</ul>

<p>These insights deliver a baseline for <a href="https://zeronetworks.com/blog/how-to-measure-cyber-resilience-zero-trust-roi">measuring cyber resilience</a> improvements over time, and a natural starting point for prioritizing enforcement and investment. &nbsp;</p>

<h3>Step 3: Prioritize Security Strategies and Investments for Reducing Business Risk Exposure &nbsp;</h3>

<p>With critical assets identified and their exposure mapped against likely attack scenarios, CISOs have what they need to answer the question that turns documentation into a <a href="https://zeronetworks.com/blog/how-to-build-cyber-resilience-via-automated-containment-an-architectural-framework">cyber resilience roadmap</a>: what actions will reduce the most risk &ndash; and fastest?&nbsp;</p>

<p>As a general principle, interventions that <a href="https://zeronetworks.com/blog/what-is-blast-radius-in-cybersecurity-best-practices-for-breach-containment">reduce blast radius</a> structurally, by eliminating an attacker&#39;s ability to reach a critical asset in the first place, are more durable than interventions that depend on detecting and responding to an attack already in progress. With that in mind, security teams should focus on strengthening the same dimensions of threat containment used to analyze exposure: &nbsp;</p>

<ul>
	<li><strong>Increase path distance or completely remove pathways to critical assets: </strong>Granular <a href="https://zeronetworks.com/blog/network-segmentation-all-you-need-to-know">network segmentation</a>, additional authentication boundaries, and inspection points placed along the worst-case attack path can eliminate entire compromise scenarios rather than simply slowing them down. &nbsp;</li>
	<li><strong>Reduce privilege exposure: </strong><a href="https://zeronetworks.com/blog/stopping-privilege-escalation-how-to-neutralize-stolen-credential-threats">Eliminating persistent privileged access</a>, reducing service account scope, enforcing just-in-time reauthentication, and introducing additional authentication requirements for critical assets can reduce privilege exposure, making it harder for attackers to successfully reach critical assets. &nbsp;</li>
	<li><strong>Enforce data layer controls: </strong>Implementing <a href="https://zeronetworks.com/platform/identity-segmentation">identity-based access controls</a> and encryption at rest limits the potential damage if attackers do manage to reach critical systems, helping to ensure that a compromise won&rsquo;t escalate to downtime. &nbsp;</li>
</ul>

<p>For each recommended intervention, CISOs should document the expected impact in terms the business understands: which worst-case path do these strategies break or lengthen, which critical assets do they better protect, and how do they reduce business exposure? This creates a direct line from investment to risk reduction, making budgetary conversations concrete and clearly tying security outcomes to business continuity. &nbsp;</p>

<h2>Build a Cyber Resilient Architecture with Zero Networks &nbsp;&nbsp;</h2>

<p>Zero Networks closes the gap between business priorities and real-world enforcement with&#8239;<a href="https://zeronetworks.com/platform">automated, identity-based microsegmentation</a>. Zero provides immediate visibility into every identity and asset on the network, then&#8239;<a href="https://www.scworld.com/perspective/navigating-the-8d-city-why-multi-dimensional-network-security-is-no-longer-optional">automatically enforces adaptive, identity-aligned policies</a>&#8239;that prevent lateral movement to critical assets to safeguard business resilience. &nbsp;</p>

<p>The&#8239;<a href="https://zeronetworks.com/company/customer-stories">average Zero customer&#8239;achieves</a> 90%+ segmentation within 90 days, achieving comprehensive protection that measurably reduces risk exposure without disrupting regular operations. &nbsp;</p>

<p>Find out how Zero Networks can help you build a cyber resilient architecture with measurable business value &ndash;&#8239;<a href="https://zeronetworks.com/request-demo">request a demo</a>. &#8239;&#8239;&nbsp;</p>]]></content:encoded>
        </item>
      
        <item>
          <title>Network Microsegmentation in 2026: Gartner Research Takeaways</title>
          <link>https://zeronetworks.com/blog/network-microsegmentation-in-2026-gartner-research-takeaways</link>
          <dc:creator><![CDATA[Mikella Marley]]></dc:creator>
          <pubDate>Thu, 02 Jul 2026 21:47:00 +0000</pubDate>
          <dc:date>Thu, 02 Jul 2026 21:47:00 +0000</dc:date>
          <category><![CDATA[Network Segmentation &amp; Microsegmentation]]></category>
          <dc:subject><![CDATA[Network Segmentation &amp; Microsegmentation]]></dc:subject>
          <guid isPermaLink="false">https://zeronetworks.com/blog/network-microsegmentation-in-2026-gartner-research-takeaways#When:1210</guid>
          <description><![CDATA[Ninety-five percent of security leaders agree that microsegmentation is key to strengthening cyber defenses, yet only 9% are successfully protecting more than 80% of their critical systems with microsegmentation. &nbsp; In other words, organizations understand the value of microsegmentation, but there&rsquo;s a gap between intent and execution. The question is: how can enterprises deploy microsegmentation at scale, in real-world environments, without multi-year projects or partial coverage that&#8230;]]></description>
          <content:encoded><![CDATA[<p><a href="https://zeronetworks.com/resource-center/reports/research-report-the-maturing-microsegmentation-market">Ninety-five percent of security leaders agree</a> that microsegmentation is key to strengthening cyber defenses, yet <a href="https://www.prnewswire.com/news-releases/elisity-commissioned-omdia-survey-reveals-90-of-organizations-falling-behind-on-microsegmentation-despite-near-universal-demand-302754959.html">only 9% are successfully protecting more than 80% of their critical systems</a> with <a href="https://zeronetworks.com/blog/what-is-microsegmentation-our-definitive-guide">microsegmentation</a>. &nbsp;</p>

<p>In other words, organizations understand the value of microsegmentation, but there&rsquo;s a gap between intent and execution. The question is: how can enterprises deploy microsegmentation at scale, in real-world environments, without multi-year projects or partial coverage that leaves gaps for attackers to exploit? &nbsp;</p>

<p>Gartner answered just that in its report, <a href="https://zeronetworks.com/resource-center/reports/gartner-reimagining-network-microsegmentation"><em>Reimagining Network Microsegmentation: Beyond the IP &ndash; Identity, Context, and Agentless Innovation</em></a>. The research identifies three critical insights that should shape how security teams evaluate <a href="https://zeronetworks.com/blog/modern-vs-legacy-microsegmentation-what-to-look-for-in-todays-top-solutions">modern microsegmentation solutions</a> &ndash; we&rsquo;ll break down what they are and what they mean for the evolving landscape of zero trust microsegmentation. &nbsp;</p>

<h3>Key Answers &nbsp;</h3>

<ul>
	<li><strong>What does Gartner&#39;s research say about innovative microsegmentation in 2026?</strong> In <a href="https://zeronetworks.com/resource-center/reports/gartner-reimagining-network-microsegmentation"><em>Reimagining Network Microsegmentation: Beyond the IP &ndash; Identity, Context, and Agentless Innovation</em></a>, Gartner identifies three critical insights shaping the future of network microsegmentation: the shift from IP-based rules to identity-first enforcement, the need for autonomous policy governance that moves beyond manual management, and the requirement for agentless, multimodal enforcement architectures that can deliver comprehensive coverage across heterogeneous enterprise environments.&nbsp;</li>
	<li><strong>Who are the leading enterprise microsegmentation vendors in 2026?</strong> Gartner&#39;s <a href="https://www.gartner.com/document-reader/document/7776453?ref=solrResearch&amp;refval=551996103&amp;"><em>Reimagining Network Microsegmentation report</em></a> names a range of sample vendors actively shaping the market, including Zero Networks, Palo Alto Networks, Akamai, Aqua Security, Broadcom, Cisco, ColorTokens, Elisity, Fortinet, Illumio, and Zscaler. Zero Networks is also recognized in the <a href="https://zeronetworks.com/blog/its-official-zeros-customers-are-the-happiest-microsegmentation-users">2026 Gartner Peer Insights Voice of the Customer</a> report with a perfect 5-star rating and a 100% willingness-to-recommend score. Likewise, Zero Networks earned a Platinum rating in <a href="https://zeronetworks.com/resource-center/reports/zero-networks-named-platinum-leader-in-microsegmentation-insights-from-the-ema-prism-report">EMA&rsquo;s PRISM Report</a>; we at Zero are proud to receive the analyst validation and customer trust that defines leading microsementation solutions.&nbsp;</li>
	<li><strong>What does identity-first microsegmentation mean in practice? </strong>Policies are bound to verified user, machine, or AI identities rather than network addresses, and enforced dynamically as those identities move across environments. This includes non-human identities like service accounts and AI agents, which already significantly outnumber human identities and are frequently over-privileged and under-monitored.&nbsp;</li>
	<li><strong>What is the most effective zero trust microsegmentation approach for stopping lateral movement?</strong> Gartner&#39;s research points to a combination of identity-first controls, automated policy governance, and agentless enforcement across the full environment. Together, these eliminate the coverage gaps and static policies that attackers rely on to move laterally, regardless of how initial access was gained.&nbsp;</li>
	<li><strong>What should security leaders look for when evaluating microsegmentation vendors? </strong>Three capabilities aligned to Gartner&#39;s critical insights: whether identity governs reachability at the network layer, whether policy automation is accurate, scalable, and auditable with human-on-the-loop controls, and whether the platform can reach the full environment &ndash; including legacy, IoT/OT, and cloud &ndash; without requiring agents on every asset.&nbsp;</li>
</ul>

<h2>Identity-First Microsegmentation: Replacing IP-Based Rules &nbsp;</h2>

<p>For decades, network segmentation meant drawing boundaries around IP addresses, <a href="https://zeronetworks.com/blog/what-is-a-vlan-definition-core-components-and-segmentation-strategies">VLANs</a>, and ACLs. The logic was sound for static, on-premises environments: define what can talk to what, and enforce it at the network layer. But the environments these tools were built for no longer exist &ndash; according to Gartner, that&rsquo;s why it&rsquo;s time to pivot from IP-centric rules to unified identity fabric. &nbsp;</p>

<blockquote>
<p>&ldquo;The shift from network-centric to identity-first segmentation is a response to the evolution of traditional perimeters to hybrid architectures, the rise of dynamic, cloud-native environments, and the adoption of NHI. Static controls like IP addresses, VLANs, and ACLs are now ineffective, for ephemeral workloads and serverless architectures make manual rule management unmanageable and leave organizations vulnerable to lateral movement attacks.&rdquo; &nbsp;</p>

<p>Gartner, Reimagining Network Microsegmentation: Beyond the IP &ndash; Identity, Context, and Agentless Innovation &nbsp;</p>
</blockquote>

<p>IP-centric policy governs a location, not an identity &ndash; when a workload moves, a cloud instance spins up, or an AI agent is provisioned into your environment, a static rule doesn&#39;t follow it. The policy appears intact, but the coverage is full of gaps; for security leaders, that creates a false sense of protection.&nbsp;</p>

<h3>Dynamic Security Enforcement for Human Users, Machine Identities, and AI Agents</h3>

<p>The proliferation of non-human identities (NHI) like service accounts and AI agents adds urgency to the identity-first segmentation shift. &nbsp;</p>

<p>Machine and service identities <a href="https://www.paloaltonetworks.com/idira/identity-security-landscape-report">already outnumber human identities 109:1</a> &ndash; a trend expected to accelerate as organizations anticipate 85% growth in AI agents over the next year. But NHI are notoriously over-privileged and under-monitored: <a href="https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024">just 2.6% of workload identity permissions</a> are actually used, and 51% of workload identities are completely inactive; meanwhile, nearly <a href="https://www.ibm.com/downloads/documents/us-en/131cf87b20b31c91">two-thirds of organizations do not have AI governance</a> policies. &nbsp;</p>

<p>The takeaway? Enterprises need <a href="https://zeronetworks.com/platform/network-segmentation">microsegmentation solutions</a> that anchor controls to the actual human user, non-human identity, or workload rather than their network location. &nbsp;</p>

<blockquote>
<p>&ldquo;Relying on static, IP-based microsegmentation guarantees catastrophic vulnerability to AI-driven attacks. Vendors clinging to manual policies face rapid obsolescence, as these methods are completely incapable of securing dynamic hybrid networks against lateral movement.&rdquo;&nbsp;</p>

<p>Gartner, Reimagining Network Microsegmentation: Beyond the IP &ndash; Identity, Context, and Agentless Innovation &nbsp;</p>
</blockquote>

<h3>Context-Aware Identity Governance and Complete Visibility &nbsp;</h3>

<p>Identity-first microsegmentation ensures policies can be dynamically enforced based on the real-time identity of users and NHI as they move across environments. At the core of this shift is what Gartner calls the Unified Identity Graph &ndash; a single, comprehensive view of network identities and context that enables real-time, granular policy enforcement. &nbsp;</p>

<p>When it comes to evaluating microsegmentation vendors, this means security leaders should look for: &nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/platform/network-map">Real-time network mapping</a> that delivers comprehensive visibility into all identities, assets, and network behavior &nbsp;</li>
	<li>Policy-based access control (PBAC) that autonomously enforces identity-based, context aware policies across hybrid and multi-cloud infrastructures&nbsp;</li>
	<li>Product architecture that natively supports identity-based segmentation, so <a href="https://zeronetworks.com/platform/identity-segmentation">identity governs reachability</a> at the network layer &nbsp;</li>
</ul>

<h2>Autonomous Governance, Agentic AI, and the End of Manual Segmentation Policy Management&nbsp;</h2>

<p>Just as modern, dynamic environments have rendered IP-centric rules insufficient, they&rsquo;ve made manual microsegmentation strategies impossible to scale in today&rsquo;s rapidly changing, distributed infrastructures, leaving a gap between what&#39;s configured and what&#39;s actually happening on the network. &nbsp;</p>

<p>To avoid policy drift and hidden risk exposure, Gartner suggests <a href="https://zeronetworks.com/blog/modern-vs-legacy-microsegmentation-what-to-look-for-in-todays-top-solutions">modern microsegmentation</a> should autonomously map application dependencies, generate policies, and enforce rules in real time. The goal is continuous, adaptive governance that keeps protection aligned to network realities. &nbsp;</p>

<h3>Agentic AI: Opportunities and Risks &nbsp;</h3>

<p>Automated policy creation and enforcement is what Gartner recommends, but how can enterprises get there? The report identifies agentic AI as an enabler of autonomous governance &ndash; but with a trust gap standing in the way. &nbsp;</p>

<p>Agentic AI adoption for security policies is often hindered by &ldquo;enforcement anxiety,&rdquo; as teams fear that algorithms may disrupt legitimate business operations. What&rsquo;s more, the deployment of <a href="https://zeronetworks.com/blog/agentic-ai-cybersecurity-risks-how-to-secure-ai-agents">agentic AI brings its own security risks</a> as agents become targets for adversarial attacks. &nbsp;</p>

<p>Gartner&#39;s prescription for closing this trust gap is explainability and human oversight: policy simulation, transparent reasoning, and human-in-the-loop safeguards that allow teams to review and validate automated rules before they go live. &nbsp;</p>

<h3>Deterministic, Human-on-the-Loop Automation &nbsp;</h3>

<p>Security teams that can&rsquo;t afford to risk operational disruption by replacing human judgement with AI can still operationalize Gartner&rsquo;s insights by leveraging <a href="https://zeronetworks.com/blog/6-processes-to-automate-when-implementing-microsegmentation">deterministic, human-on-the-loop automation</a>, which operates on defined logic rather than probabilistic guesswork while keeping security teams in control of outcomes.&nbsp;</p>

<p>Microsegmentation powered by deterministic automation delivers the adaptive, dynamic protection modern enterprises need by generating precise enforcement based on learned network behavior. For example, Zero Networks&rsquo; automation engine learns allowed network behaviors in order to create dynamic rules for identities and assets. As <a href="https://zeronetworks.com/blog/the-role-of-ai-in-cybersecurity-promises-pitfalls-and-best-practices">Chris Boehm, Zero Networks Field CTO, points out,</a> this type of deterministic automation hinges on learning:&nbsp;</p>

<div style="background:#eeeeee;border:1px solid #cccccc;padding:5px 10px;"><em>&ldquo;Zero Networks learns and then provides automation on top of that without guessing &hellip; when you deploy [Zero], we will learn based on each asset and we&rsquo;ll tell you what that asset is doing &ndash; like a machine, server, service account &ndash; and then we control it, manage it, and automate it. So, that almost feels like artificial intelligence, but we don&rsquo;t advertise that capability at all; we advertise the capability of learning.&rdquo;&nbsp;</em></div>

<p>In other words, deterministic automation relies on learned realities rather than educated guesses, which are central to probabilistic approaches. Keeping a human on the loop to optionally review, approve, or fine-tune policies in a sandbox environment is a key safeguard for peace of mind while still shrinking manual effort and enabling protection to scale alongside modern environments. &nbsp;</p>

<p>Whatever mechanism security teams choose to get there, the ultimate goal remains the same: microsegmentation that shifts away from manual policies and embraces automation, enabling defenses that effectively counter <a href="https://zeronetworks.com/blog/what-is-ai-driven-lateral-movement-ailm">AI-driven attacks</a>. When evaluating microsegmentation tools on this capability, CISOs and cyber leaders should ask questions like: &nbsp;</p>

<ul>
	<li>Does the platform generate policies based on observed network behavior? Can your team see how a policy was derived?&nbsp;</li>
	<li>Can teams simulate and validate policies before enforcement goes live, and test against real traffic to catch potential disruptions before they impact operations?&nbsp;</li>
	<li>Does the platform continuously adapt as environments change, or does staying accurate require manual intervention?&nbsp;</li>
	<li>How does the platform handle policy drift? Does it detect and remediate unauthorized changes automatically?&nbsp;</li>
</ul>

<h2>Agentless Enforcement: How Microsegmentation Scales Across Enterprise Environments&nbsp;</h2>

<p>Autonomous, real-time policy governance only works if the underlying enforcement architecture can actually reach the full environment &ndash; without introducing performance overhead that makes it impractical.&nbsp;</p>

<p>That&#39;s the core of Gartner&#39;s third critical insight: agent-based platforms struggle with performance and scalability across hybrid, cloud, and containerized environments, making granular policy management too complex. The recommended path forward? Multimodal, agentless enforcement that extends comprehensive coverage without the operational burden agents introduce.&nbsp;</p>

<h3>Agent-Based vs. Agentless Microsegmentation &nbsp;</h3>

<p>Agent-based platforms require software on every managed endpoint. In heterogeneous enterprise environments, that creates a structural problem: performance overhead on every host, version management across a diverse fleet, and coverage gaps on the assets that can&#39;t run agents at all &ndash; legacy systems, <a href="https://zeronetworks.com/resource-center/guides/applying-zero-trust-to-ot-systems-with-microsegmentation">IoT and OT devices</a>, unmanaged endpoints, and cloud workloads. These are precisely the assets attackers move through.&nbsp;</p>

<p>Agentless microsegmentation solves this by extending enforcement through existing OS and network infrastructure rather than requiring software on every endpoint. Coverage reaches the full environment, including assets that could never host an agent, without the performance tax or the operational burden of managing agents at enterprise scale.&nbsp;</p>

<p>From a solution evaluation perspective, this insight signals that security teams should ask vendors questions like: &nbsp;</p>

<ul>
	<li>Does the platform require agents on every endpoint, or does it enforce policy through existing infrastructure?&nbsp;</li>
	<li>What happens to coverage on legacy systems, IoT/OT, or cloud workloads where agents can&#39;t be deployed?&nbsp;</li>
	<li>Does the deployment model scale as the environment grows, or does agent management become a ceiling on coverage over time?&nbsp;</li>
</ul>

<h2>Automated, Identity-Driven Microsegmentation for Modern Enterprises: Strengthen Cyber Resilience with Zero Networks &nbsp;&nbsp;</h2>

<p>Modern enterprises are moving away from reactive security to proactive containment &ndash; an evolution Gartner describes as the &ldquo;shift from preventative-only security to <a href="https://zeronetworks.com/resource-center/topics/zero-trust-architecture-how-to-achieve-cyber-resilience">cyber resilience</a>.&rdquo; For security leaders embracing microsegmentation as part of this shift, Gartner&rsquo;s report paints a clear picture of what innovative solutions must look like: identity-first, automated with human oversight, and agentless. &nbsp;</p>

<p>Zero Networks is named in the report as a sample vendor, recognized for <a href="https://zeronetworks.com/platform">automated, identity-driven microsegmentation</a> that delivers on all three critical insights: &nbsp;</p>

<ul>
	<li><a href="https://zeronetworks.com/platform/identity-segmentation">Identity-based policies</a> govern access at the network layer, tied to user, machine, or AI identity, and automatically updated as environments change.&nbsp;</li>
	<li>A deterministic automation engine maps observed network behavior, generates least-privilege policies, and keeps teams in control through human-on-the-loop simulation and staged rollout before enforcement.&nbsp;</li>
	<li>Zero deploys agentlessly, <a href="https://zeronetworks.com/platform/network-segmentation">orchestrating native OS enforcement</a> mechanisms across IT, OT, IoT, and cloud &ndash; no proprietary agents, no rearchitecting, and no coverage gaps on the assets that matter most.&nbsp;</li>
</ul>

<p>The <a href="https://zeronetworks.com/company/customer-stories">average Zero customer</a> segments 90%+ of their environment within 90 days &ndash; 91% faster than legacy approaches, at <a href="https://zeronetworks.com/resource-center/white-papers/esg-technical-validation-zero-networks">87% lower cost</a>. <a href="https://zeronetworks.com/request-demo">Request a demo</a> to see how. &nbsp;</p>]]></content:encoded>
        </item>
      

    </channel>
  </rss>