The Zero Trust Hub
Trends, insights, and resources for today's cybersecurity leaders. Updated weekly.
Do the Math: How Zero Trust Flips the Odds on AI Attacks

Chief Evangelist
Earlier this year, an attacker built a hacking machine out of spare parts.
They took a free, open-source AI agent framework, plugged in a commodity model as its brain, and turned it loose. The system researched vulnerabilities on its own, found more than 647,000 exposed instances of a single workflow automation tool, downloaded exploits, and tried to break in.
It compressed hundreds of hours of skilled work into minutes. And it’s able to handle a vulnerability research task for under 70 cents.
Rich Mogull tells that story in his chapter of my new book, Cyber Resilience at Machine Speed. His chapter, “Zero Trust or Zero Day,” explains why the gap between attackers and defenders is a math problem, and why AI has made the attacker’s side of the equation cheap.
A Zero Trust architecture makes it expensive again by forcing every attack through a chain of independent barriers.
AI outruns the patching clock
You’ve heard the old saying that the attacker only has to be right once, but the defender has to be right every time. The imbalance is real, but it’s structural. The good news it that we can change structure.
Attackers face what Rich calls a bounded search problem. They only need one path that works, like an unpatched service or a stolen password. Defenders face combinatorial complexity. We have to guard every asset along every path, including that forgotten test server and the vendor connection from 2019.
For decades, the rare skills needed to find bugs and build exploits kept attackers in check. AI is built for search, it never gets tired, and compute is cheap. That’s why the attacker’s clock now runs in hours, while the defender’s still runs in weeks.
Patches have to be tested, approved, and pushed through change management across systems owned by different teams. Some of those systems aren’t even on the security team’s radar.
This means the exposure window keeps getting wider while the number of attackers who can use it explodes. Every day is day zero.
Zero Trust stacks the odds on every path
For the attacker, paths add up, because any one of them will do.
For the defender, controls along a single path multiply because the attacker has to beat each one in order. Say each control gives the attacker a 50-50 shot. One control is a coin flip. Five in a row drop the attacker’s odds to about 3%, and every failed try makes noise that can trip an alert.
The catch is that the barriers have to be independent and in sequence. If one stolen admin credential works on all five, you built one barrier and photocopied it four times.
That math leads straight to Zero Trust.
I’ve always said that all bad things happen inside an allow rule, and Zero Trust gets rid of the ones you don’t need. You verify every connection, trust nothing because of where it sits on the network, and scope every credential so a stolen one opens a single door.
Microsegmentation is how you enforce that architecture and its least-privilege rules. When a compromised workload can reach three systems out of 3,000, the attacker has to start a new search at every step.
A thousand AI agents probing a deny-by-default environment make a thousand times the noise, since every barrier doubles as a sensor.
You’ll pay for AI cyberattacks either way
We’re going to pay for AI cyberattacks one way or another. We can invest now in Zero Trust and segmentation that drive up the cost of every attack. Or we can keep paying in response cycles and hope we patch before an AI agent finds the zero day in our firewall.
Every day you delay, attackers get cheaper models and better tools, while your environment adds more paths, identities, and legacy systems. Zero Trust is a multi-year journey, and every quarter you wait is a quarter of barriers you won’t have when the next swarm shows up.
The old saying assumed one path, weak detection, and slow response. Add independent barriers, and the attacker has to be right again and again, in a row. The choice is still yours: Zero Trust or zero day.
STATSHOT
Sticker Shock
Every major breach cost category rose in 2026, pushing the average global total to $4.99 million (USD). Detection and escalation, and lost business accounted for nearly two-thirds of that cost, totaling $3.18 million. Post-breach response and notification costs also increased. After a dip in 2025, all four categories reached their highest levels in the four years. In the U.S. alone, the average cost of a breach reached a record $11.5 million, an 11% increase over last year and nearly double the global average.

The Flaw Opens the Door. The Network Does the Rest.
Michael Adjei traces how attackers turn one flaw into a network-wide breach. The exploit just gets them in. The real damage comes next, as they move from machine to machine over paths most networks leave open. Close those paths, and a foothold stays a foothold.
Under Pressure: 100+ U.S. Water Systems Attacked
When attackers hijacked internet-exposed PLCs in July, some utilities lost water pressure, some sites flooded, and a disrupted pump station in Georgia prompted a boil-water advisory. See how Zero Trust security helps water systems contain attacks.
Get the industry’s first vendor-neutral Zero Trust certification.












