The Zero Trust Hub
Trends, insights, and resources for today's cybersecurity leaders. Updated weekly.
The Zero Trust Lesson Hiding Out on Alcatraz

Chief Evangelist
I’ve spent most of my career explaining Zero Trust in conference rooms. A few months ago, I got to explain it in a cell block.
I was standing on Alcatraz with my friend Hazel Cerra, who recently retired after 26 years in the United States Secret Service. She’s protected presidents around the world and sent people to places a lot like the one we were touring.
I asked for her first impression. She looked down that long row of iron doors and said she couldn’t imagine why anyone would commit a crime that lands them here. It is, in her words, the definition of the slammer.
Alcatraz earned its reputation on being unusually clear about who belonged inside the walls and how far they could move once they were there. Most security programs never quite make that decision. We’re too busy watching the attack surface grow every time somebody spins up a container or signs up for a new AI tool.
Zero Trust asks a smaller question: what are you actually protecting? The answer is your protect surface, which includes mission-critical data or assets that, if compromised, would negatively affect the business. Defining it is Step 1 of the Zero Trust model, because every control you build afterward depends on getting it right.
Watch our discussion in Alcatraz here:
The Secret Service protects in layers
Hazel described protection as layers, rings running from the outer edge all the way in to the principal. They even protect the airspace overhead. Before a president lands, an advance team has already walked the route, mapped the sightlines, and assigned every resource a job.
Notice what the Secret Service doesn’t do. They don’t secure the entire city. Instead, they focus on the thing that can’t be lost, then build outward from it to protect it in rings.
Focusing on your attack surface works against you here, because it’s unbounded and it expands while you sleep. Your protect surface behaves differently. It’s small, knowable, and changes slowly enough that you can write real policy around it.
Maximum to the problem, minimum to everything else
That’s how Hazel described triage in the Secret Service. When something goes wrong, resources surge toward the principal, and everything else gets the minimum.
Most security budgets do the opposite. We spread controls evenly across the whole environment and end up equally mediocre everywhere.
A Zero Trust architecture fixes the math by moving the control as close to the asset as it will go, which is exactly what a microperimeter is. You draw one around each protect surface, then write policy that says what’s allowed to talk to it, on which port, for what purpose. Everything else is denied.
This is where I remind people that all bad things happen inside of an allow rule. Knowing your protect surface tells you which allow rules deserve the most scrutiny.
Plan for doomsday every single day
I asked Hazel whether the Secret Service’s mission was really about preventing the bad thing. Her answer was that they expect the bad thing, so they plan for doomsday daily.
In cybersecurity, we call that assume breach, and it changes what good looks like. Containment works. It’s why we have prisons, and it’s why Zero Trust uses microsegmentation to enforce least-privilege access between workloads.
The intruder who gets in still has to get somewhere, and a well-defined protect surface makes “somewhere” very small.
Defining your protect surface can’t wait
Attackers now move in minutes, with AI shrinking the gap between an initial foothold and real damage.
If you haven’t named your protect surface before the alert fires, you’ll be defining it during the incident, with the CEO on the phone and the clock running. That’s the most expensive hour to decide what matters most in your environment.
Define it now, while it’s quiet. Name your critical assets, draw the microperimeter, write the policy, and enforce it.
Alcatraz worked because somebody decided what was most important to lock down long before anyone tested it.
STATSHOT
Vidar Dominates Infostealers
An infostealer is malware designed to steal credentials, browser data, cookies, and other information from infected devices. Vidar accounts for nearly three-quarters of infected hosts and devices. StealC and RedLine are a distant second and third, while other infostealers account for only a small share. In sum, Vidar is driving the vast majority of the infostealer activity in the wild.

An AI Agent Breached Hugging Face By Itself
Autonomous agents from OpenAI’s own security tests broke the proxy meant to hold them, reached Hugging Face, and landed in production clusters. Christer Swartz breaks down what moved and why containment was the only control that mattered.
Regulators Are Putting Deadlines on AI Threat Plans
Eurozone banks have until October 31 to submit their plans for dealing with AI-enabled cyber risks. This post explains why regulators are setting deadlines on AI threat plans, and why breach containment matters more than the patch backlog.
Get the industry’s first vendor-neutral Zero Trust certification.












