Video
CISO Panel: Three Enterprises. Built-In AI Containment and Cyber Resilience. Here’s How They Did It.
What does it actually take to contain a breach before it becomes a crisis? Not just in theory – in practice, inside a real enterprise, and under real pressure.
This panel brings together three security leaders who made a deliberate architectural bet: that a closed-by-default network would change the math on cyberattacks, giving their teams a reliable advantage – even as Mythos and Daybreak compress attack timelines. The discussion covers:
- Why these foundations are key in the era of AI-driven attacks, where containment – not speed – is the only defensible answer
- What building a containment architecture required, and what happened when their environments were tested
- The metrics that validate cyber resilience and signal the network architecture is capable of absorbing an incident
Chris Boehm: So as a quick round of introductions, I'll start — I'll be the lovely host of these three executives over here on my left side. My name is Chris Boehm. I am the Field CTO at Zero Networks. I've been here for about a year and a half. I've been in the cybersecurity industry for about 15-plus years — Microsoft, SentinelOne, the list kind of goes on in my career. I would love these guys to tell about their backstory, and then we're going to talk about the core problems that our session's going to hit on. So —
George Perez: George Perez. I am the CISO at Ameris Bank. Previously, I was at Truist, led the integration there. Before that, I led cybersecurity for IHG Hotels.
Blair White: Sorry — I'm Blair White. I'm CISO with Dentsu. Been in tech for about thirty-five years, so I've kind of seen a few things here and there.
Keyur Desai: Hi, myself, Keyur Desai. I'm a VP of Security Architecture and Engineering at Federal Home Loan Bank of Atlanta. Been in the industry for about twenty years, and my team is responsible for managing identities, securing applications, and network security.
Chris Boehm: Awesome. Thank you guys again for being here. You don't always see in these sessions customers up on stage — it's usually the vendor doing a pitch and talking about what they're doing. So we were very proud at Zero to have these three gentlemen come and agree to be up on stage with us at Black Hat. So I want to hit on the first core problem that we're going to hit on: the business problem.
For those who don't know who Zero Networks is, they provide micro-segmentation technology down to every asset in your ecosystem — endpoint security, OT layer. So, what was the business problem that started focusing this conversation of micro-segmentation within your business? Because all three of you are customers of ours, so —
George Perez: You want me to start?
Chris Boehm: Whoever would like to start.
George Perez: Yeah, so for me — there were two things we were looking at. One is we were trying to improve our cyber resiliency from a ransomware attack — how do we slow it down, right? Because recovery, and the effort to do recovery — my peers are spending lots of money to try to get faster. And I said, "Is there a smarter way to actually reduce the risk so we don't have to spend all that money?" So I was looking for that capability, and with the threats out there, how do I mitigate that? So that was my big reason for it. And we'll talk a little bit about how it does that, and why.
Blair White: So we got into it because, historically, like many other companies, we had an extremely flat network. Attacks these days traverse east-west very quickly, so we needed to put something in place — get some fire breaks in. So here we are with Zero, and the micro-segmentation piece is a game changer for us.
Keyur Desai: So for me, the business problem was — cyberattacks are, we are all security, so a cyberattack is imminent, right? But for me, operational resiliency was the key — how do I achieve operational resiliency east-west. And also, with AI, visibility between east-west is key. Having multiple tools, but then when you see something, how do you defend that? That was a key problem for me — I have visibility, but I don't have a means to protect it, and I wanted to see how I can protect at scale.
Chris Boehm: I mean, all of those are pretty core use cases when it comes to micro-segmentation, and I appreciate you all sharing that. But when it comes to — when you start shopping this market, and I know you picked Zero in the end — why did you consider Zero? What were the justifications? How did you validate us? What was the mindset and thought process you guys went through?
George Perez: So for me, it's just like any other industry, any other enterprise — I didn't want to redesign the network. I wanted a solution that would be like sugar — something that dissolves into my network. I don't have to redesign anything, I don't have to do anything in terms of architecting again. And also, at the same time, I wanted to not have a single point of failure. If I put it through the firewall, that would create a single point of failure. So I didn't want a single point of failure in my east-west network.
Micro-segmentation had been on my mind for a long time — you see a flat network and you're just in fear, right?
Chris Boehm: When you say a long time, how long? How long had you been facing this?
George Perez: Maybe about five, six years now.
Chris Boehm: Five, six years?
George Perez: However, the deployment of these types of products has typically been a very lengthy pursuit, right? So you have five guys dedicated for five years to do something like this. We brought Zero in because it really automates it — the speed at which we were able to stand it up was just amazing.
Chris Boehm: I love hearing that, obviously, as a Zero host, so —
Blair White: So for me, I'm going to get a little technical. For me, it's: how do you stop lateral movement, right? A ransomware comes in, it's going to compromise credentials, it's going to try to move laterally. What's the number-one problem with firewalls? You open them up, and you still have to have RDP open, and you have all these protocols that allow you to move laterally, right? Well, with Zero Networks, you're doing it differently — all your ports are closed. You cannot open those ports unless you authenticate with two-factor authentication.
You can't stop an attack — well, in this case, you are stopping the attack, because you cannot move laterally, since with two-factor authentication at play — you can integrate passwordless into it, you can do two-factor, and, most important, you're authenticating to TCP/IP. So that means even if you have an authentication vulnerability, you can't move laterally — you're not going to be able to get past that. And that's the one control that their CEO sold me on — you can replace privileged access management with this, right? You can do lots of different things and really stop the attack.
Chris Boehm: So that actually leads into my next question. When you said, "Hey," the light bulb went off — how did you justify that to your peers, to say "this is something I truly believe in investing into today"? Did you have to justify it? Did you have to have numbers — did you have the case studies to point to? You didn't have that; you'd been with us before those existed.
Keyur Desai: So we're a bank, right? It's important to be able to stay working all the time — you bring down a bank for a day, we have a problem. I said, "You're not going to move laterally." You integrate passwordless and you integrate this technology, it's impossible to move laterally — unless you compromise the host-based firewall. So to me, when you think about the fundamental controls you need — you think endpoint, you think network layer, email gateway, all those things — this is that next level. You want to stop lateral movement, this is the one technology that can do it.
Chris Boehm: So from a business level, were they like, "I accept your opinion, let's just do it," or did you have to fight for it a little bit?
Keyur Desai: No, it was easy, because they were looking for a solution. Their thing was, "I'm going to spend three million dollars to do better recovery." I said, "You don't have to do that — how about if I just reduce the risk? How about you compromise one server, not the whole thing, because I'm implementing this?" So they'd rather spend on the mitigating control than spend all that time and money on resiliency.
Chris Boehm: Yeah, I love that feedback. Who'd like to speak next? We're just going back and forth here.
Blair White: Yeah — so we were able to calculate loss at almost a per-server level, and if not, definitely at a platform level. So when you go to the business, it's like, well, what can we stand to lose here, and how many clients will this impact? When you can break the numbers down to client loss, it's pretty easy to get something like this through — and we had real numbers.
Chris Boehm: Okay. So when you have a little bit of justification and backing behind you, you can easily show the impact this would have for the business. Was there just no pushback, or was there still — sorry.
Blair White: No — we got it right there. There was no question. We were able to prove it.
Chris Boehm: Wow, okay. No, that's awesome — because in this space, as you mentioned, it's been around for quite some time, so it's like, are you coming back to just rub a little sand in this? Maybe it didn't work before? Did you face that conversation?
George Perez: Yeah, so that did come up — like, how many people is it going to take to do this. And what I said earlier, right — five years and five people dedicated. This is one guy — with support of the team, of course — but really one guy rolling this out, and it was deployed in a little over a month.
Chris Boehm: Yeah, okay, I love it.
Keyur Desai: For me — as I said, it's a host-based firewall — the justification was that my application team couldn't keep up with the vulnerabilities being identified today with AI. There are a lot of vulnerabilities; when I ask them to fix it, they say it's going to take three to six months. I can't have that sitting on the network. So now, with Zero, I'm able to lock down the server at a host level — processes, identity, and port, all three in one. So for me it's a win-win: I told them, "If you can't fix the vulnerability for three to six months, I'm going to do this" — so their workload got easier. And for my infrastructure team, they don't have to redesign anything, so that's the easy sell there too. Win-win for everybody.
Chris Boehm: That actually brings up a great question — I haven't talked to you guys about this, but have other groups in your organization started using Zero to solve other problems? Application performance, analysis — have you seen any expansion outside of our core purpose of micro-segmentation?
Keyur Desai: Yes. We got east-west visibility, so I'm able to say — if there's an issue with a process or a system, every time there's an issue, it's assumed to be security or network. Now I'm able to say, "Hey, I see the TCP port, I see the communication, I see this is a particular process" — so I can show them the network and security side is working as it should, and help the group start detecting the problem at the application level.
Chris Boehm: Okay, interesting.
Blair White: I'll add to that. One thing I noticed fairly quickly after it was deployed was that the dev teams became much more conscious of what protocols they had open and what they actually needed open. We had conversations with them saying, "Hey, we have this micro-segmentation product in hand — be thoughtful about how you're deploying this." Not that they needed to be, but it really helped from an SDLC perspective.
Chris Boehm: Okay, awesome.
George Perez: I want to add — if you've been in financial services for a long time, micro-segmentation has been a nightmare to deploy, because you have to understand how your applications work. How many developers actually know how their application works? Not every one of them. So what happens is you're trying to implement micro-segmentation by asking your applications what servers and infrastructure they touch. The difference with Zero Networks is they do all that mapping for you — they give you the confidence that they know how all your applications and servers are talking. So when you go to isolate something, you're a lot more confident pushing that button without being disruptive. If you ask a CIO their number-one problem, it's "I don't want disruption." We rolled it out in three months for workstations; we'll probably do servers in about six. I have friends who are CISOs at really large places who've been doing this for five years and still aren't done, because it's complex. This innovation is a game-changer in how to think, because of what's possible today with AI.
Chris Boehm: I mean — we have another follow-up.
Keyur Desai: I'd like to add one thing — the additional benefit we got was around our obligation to do access management. Now I'm able to say, "These are the servers, these are the users that connect to this application" — it's a benefit to show the business exactly which users and APIs are connecting to your segment. So access management becomes much easier.
Chris Boehm: Okay, I love it. It's one of the weird side effects of our product — we have to learn everything. We do an assessment, learn how your whole environment works, map it out. So with all that visibility, a lot of our customers were like, "Whoa, I didn't know all that — I can see all that." It's interesting how many customers use us for more than just micro-segmentation, even though that's our core focus as a business.
And that's why I was curious — which brings up the talk track everyone here, and maybe even we, have touched on: artificial intelligence, LLMs — there are multiple layers to this. I'm curious — beyond micro-segmentation, what are you doing to even talk about it, work on it, and secure yourselves against AI today? It's a loaded question, I know.
Blair White: So to me, the easy answer is frontier models, and frontier-model attacks — that's what we don't know what it's going to look like yet. With Zero Networks, there are two things you need to do anything: network connectivity, and authentication. If you have passwordless authentication integrated with Zero Networks, and you're doing TCP/IP — it's going to stop the attack. At least for us, if you have a machine that's vulnerable, you do the best you can to patch it; if you can't patch it, you isolate it. So you're one layer in whether or not you get a vulnerability, but moving laterally from that isn't possible. That's not going to solve everything, but it's a good way of mitigating the control.
George Perez: Yeah, I totally agree. The one thing AI has done is accelerate attack speed to machine speed. So I look at it this way: we're going to get pwned.
Chris Boehm: I love the positive thoughts.
George Perez: It's healthy. But what I can do is minimize the blast radius of that attack — that's really what I'm focused on, as well as, of course, making the edge as hard as possible. And hopefully — has anybody seen any AI products around here? — hopefully at some point we'll be able to defend at the same speed they're attacking, so we can just shut it down immediately. But right now that's difficult, so you have to minimize your blast radius.
Chris Boehm: So, in case you couldn't hear — the primary focus is eliminating the attack's blast radius, because of the speed and scale of operations.
Keyur Desai: Yeah, so it's containment — a risk reduction that you get. With AI, as [Blair] said, somebody's going to get owned. We may get owned, but how can I reduce that risk, reduce that lateral movement? That's the beauty of this — if you're contained on that host, maybe a host got popped, but that's the only issue I have to deal with; I can figure out that particular risk.
Chris Boehm: So one of the most interesting things I've heard this week already — Anthropic came up and talked about their core concerns for the market, based on their own assessment. The number-one thing they brought up was lateral movement — "expect it, it's going to happen today, it's just where the market is; they can't even control themselves." It was interesting feedback to hear, telling most of the executives and CISOs in the room that lateral movement should be the number-one concern right now.
I was like, "Oh, that's a fair assessment." I was just thinking about where I was going on the talk track — you brought up how you've been measuring the success of leveraging Zero, but have you had a third party evaluate you after having Zero in place? Have you been through a red-team or pen-test operation? Have you seen anything like, "whoa, I didn't expect that with Zero here"?
George Perez: Yeah, so we did red teaming, and the red team said nothing works. That was the feedback — nothing, because we locked down everything.
Chris Boehm: Wait a minute — nothing worked?
George Perez: For them, nothing works. For business, everything's working. For red teaming, nothing works.
Chris Boehm: Okay, okay — I was like, "uh-oh, hopefully you have something working."
Blair White: Yeah, we red-teamed shortly after, and there was a noticeable difference in the report at the end — a very noticeable difference.
Chris Boehm: That's reassuring. I mean, it's funny, because you go hire a consultant to do an internal pen test, put them in your environment, tell them "go crazy," and they can't. So what are you really pen-testing at that point? You're probably testing for things where you'd have to turn Zero Networks off, and then pen-test for other types of vulnerabilities — because laterally, you're not going to be able to do that unless you allow it. What's the point of that?
Keyur Desai: The other thing that's important, too — when we say lateral movement from agentic AI models, you're thinking about an attack coming in. But you still have to think about the agentic AI you're building yourself, the permissions you're giving it, and letting it flow. So this isn't stopping every type of agent attack, but it is providing visibility to understand where your agentic AI is and what it's talking to. You still need firewalls, you still need defense in depth.
Chris Boehm: So, just to expand on that since we have a few extra minutes — what are you telling your teams? There's a lot of insight here, but what are you advising internally when it comes to AI, and what to be concerned about? Are you doing this yet? This is everyone's talk track right now, so I want this to be a chance for you to share what you're telling your company and focusing on today. Hopefully a lot of it is handled by us, but is there another layer to it you want to share — things you've noticed, things you're focused on because they're a concern?
Keyur Desai: I'll let them talk — so we're going full-throttle on agentic AI automation. I've spent the last four days meeting with every startup company in this space, because I need to solve it. I'm not just doing Copilot — I'm going to be automating all my processes. I have identity access management agentic AIs, I have different things we're doing, so I need something that can put guardrails in place and provide visibility. We're doing a bake-off with a lot of different products — a lot of this is still new, so you have to trust but verify, do POCs, and so on. We're getting into this because we have to get ahead of it: understand the access, what it's touching, what data it's modifying, guardrails, alerts when it does things I didn't give permission for.
Chris Boehm: So, real quick on that — is your focus on building your own LLMs and doing agentic AI on top, or using cloud-based LLMs and doing agentic AI on top of those?
Keyur Desai: We have one we're using temporarily to solve something, but we're going to build our own platform with different LLMs.
Chris Boehm: So the plan is to build your own. Okay, that's all I was —
Keyur Desai: It's the only way to scale.
George Perez: We have the same journey — I'm dealing with the exact same thing. I had the same meeting yesterday.
Chris Boehm: That's why I wanted to bring it up — we're all dealing with it right now.
Blair White: Even we're dealing with it. It's interesting, because to me, personally, from a security perspective, AI has created more brand-new problems than it's solved on the security side. So I'm kind of just waiting for that to come. It's a mad rush to figure out how to get your arms around everything, and it's coming in from all different angles — there are so many different ways to attack services.
Chris Boehm: So, in your opinion, what's the core focus for your business on AI? There's obviously a huge stack, but —
Blair White: I'm putting a lot of focus into the software development side, right now.
Chris Boehm: Software development side. Okay, that makes sense.
Blair White: Because we're developing LLMs from the ground up.
Chris Boehm: Okay. I'm good.
Chris Boehm: You good? Okay — so the next thing I wanted to bring up, just sharing with everyone here: if there's advice you can give from your cybersecurity journey — something you've noticed that's really shaped your career, that you'd want to pass on to other executives — is it a mentor, a skill set, staying cutting edge? What's the thing that's really pushed you forward in your career?
George Perez: I'd say — don't ever stop being a student of the game. I think the number-one thing I've noticed as I've grown in my career is people getting away from the tech and the details, and you have to understand this. Right now, the game is completely changing. In the last six months, I've learned how much platform architecture has changed — and if you're not leveraging autonomous agents built into a platform to do detection and behavior analytics, you're going to fall behind. You're not going to keep up with the threats if you're doing policy-driven stuff. So learn what these technologies are actually doing, because if you keep buying the ones that aren't innovating, it's not going to help you — and you're not going to be able to change it for three years because you signed a three-year deal.
Blair White: I agree, and I'd add — being involved with the community, even something like this, being able to network with other CISOs and other people in the business, is incredibly important. Keeping your ears open, understanding what's out there, because everybody sees something differently. That's helped me in my career quite a bit, actually. It's continuous learning.
Chris Boehm: Yeah, 100%.
Keyur Desai: Be curious. Just keep learning — it's a game. Every morning when you wake up, look at things, look outside, and ask, "What needs to be done, and how can I fix things in a new way?" There's always something you can optimize, whatever you do. Curiosity will keep you going.
Chris Boehm: I love it — and by the way, thank you guys, we're a little early. Do you want to hit a little more on why micro-segmentation was the focus again? I skirted on it pretty quick, and I wanted to make sure we had time for the core message. When we go through the journey of micro-segmentation — I remember when it was starting to be implemented manually, and you mentioned speed of operation, scalability — it was hard for me to even fathom that this could be pushed to the next level of automation. Was there a fear or concern of this overasserting itself in your business? Because that's what I hear from other peers and executives — "I have too much fear this could stop operations." But obviously we have hundreds of customers who do this. So how do you alleviate that fear? I know for some people it's like, "This makes sense, I understand it, I can go through a safe process" — but others don't go that direction.
Keyur Desai: I would say — part of getting where you are in your career is your network. I have a bunch of CISOs I can call and say, "Hey" — Zero Networks put me in touch with the guy at Delta, and I trust him, so when he tells me something, I'm going to listen. When I say something to my peers, they're going to listen too. So you don't have to solve this problem on your own. I got confidence because Zero got me three interviews with three CISOs who had already rolled this out, and that gave me confidence, because I don't have time for a full POC to prove it's flawless or perfect. You use your network to get that done.
For me, micro-segmentation was a dream — we didn't know our east-west traffic, we didn't know every application. We're a security team, but we didn't know every single application or port that needed to communicate. Zero came in and started learning the network, started creating the rules. That's really what helped us get where we wanted to be — and obviously, lateral movement was completely isolated with Zero Networks.
Chris Boehm: Your question was about how people can be standoffish about rolling out a micro- —
Blair White: They've been burned once, at least. Again — this has been around for twenty years, it's not new technology, there's been talk about it for a long time.
Chris Boehm: The peers thing — I love that you brought that up, because that's exactly what I would've done: "Okay, who have you talked to? I know that guy over there, let me ask him some questions, because he's going to do the hard work for me, hopefully, and I can do a little of my own work to re-justify it." But I'm curious how you get past that fear, because it's a common trend in this space — "I've been there before, and it takes five years."
Blair White: Yeah. But if you understand the tech, you understand what it's doing. And, honestly — I'm here to talk about Zero too, but — the way you guys deployed it is kind of brilliant. Before, you had to run a TCP dump server, run packet dumps, figure out what's going on — it takes hours just to map a single server, figure out it's talking on sixteen ports. It's the implementation — if you get people to understand the tech, they're going to be more understanding of it.
Chris Boehm: So you think it's the transparency of how it connects, and how easy it is to justify getting to that level quickly, that made you feel less hesitant?
Blair White: Yeah, I've been in tech a long time, so when you guys talk to me, I'm like, "Oh yeah, totally makes sense, let's do it."
Chris Boehm: I'm seeing a theme with this group right here — they all just get it. Where do we get more of these guys?
George Perez: So, funny story — one of my best friends is a CISO at a very large company, and he's also been a mentor to me. I told him I was rolling out micro-segmentation, and he said, "Why? It's so hard — why would you ever want to do this right now? Everywhere it's been implemented, it's been done wrong. It's hard." And I said, "Watch — it's going to happen, and you're going to come back to me, and you're going to deploy this, because it's that easy now, because of AI." The technology behind it just makes it easier to do. That's how you get confidence.
Chris Boehm: Well, thank you for letting me spin that ball, because it's something I face on a regular basis — I have to justify it technically every time, so at least I know I'm doing it the right way.
But again, thank you three for coming up here on stage and speaking to this lovely audience. Hopefully you learned something a little new and exciting from their point of view, not just a vendor's point of view. Thanks again for joining us. If you'd like, we'll show you what our product is — we even have our own customers, some of them sitting at the booth. So feel free to talk to our customers at the booth. Thanks.