The Zero Trust Hub
Trends, insights, and resources for today's cybersecurity leaders. Updated weekly.
How Cyber Resilience Ended Up in the Title of My New Book

Chief Evangelist
A few months ago, if you’d asked me what my new book would be about, I’d have said Zero Trust in the age of AI, and I’d have left it there.
My fellow contributors’ chapters changed my mind. They came in from people working on identity, architecture, policy, agentic AI, and federal programs. Nearly all of them spent their pages on the same stretch of the problem: what happens in the hours and days after an attacker is already inside.
By the time the manuscript came together, it made sense that “resilience” needed to be part of the title. Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era is out in October, and the exclusive preview is available today.
Cyber resilience is the ability to absorb a compromise and keep operating through it, and Zero Trust is the strategy that produces it.
We’ve been grading ourselves on the wrong question
For most of my career, the cyber industry has measured itself against one thing: did anything get in? We bought products against that question, built budgets around it, and reported it to boards.
I stopped believing in it while I was still a pen tester. A client would tell me the perimeter held. Meanwhile, I’d already be inside, carrying their data back out the front door. Every tool in the building trusted anything already inside, and nobody had ever written a rule about leaving.
So I started writing rules for outbound traffic, and I set the trust level on every interface and every packet to zero. Trust is something people extend to each other, and a network has no business doing it.
The lesson from those years stuck with me. Getting in was rarely the expensive part, and companies survived that first compromise all the time. The damage came from the weeks that followed, while an attacker moved laterally across a flat network that gave them no reason to stop.
Cyber resilience is the difference between those two outcomes.
Prevention asks you to outrun a machine
AI hasn’t changed that lesson. What it’s changed is the tempo.
A frontier AI model can hand an attacker a working exploit in an afternoon. Closing that same vulnerability across a real environment takes a testing cycle, a change window, a few approvals, and several teams who each own a piece of the problem. That runs in weeks.
AI is making both sides faster. But it only removes the obstacle on one side. The defender’s obstacle is every person who has to say yes before the code ships. No model shortens a change advisory board.
That’s the trap in prevention-first thinking. It asks you to win a race you’re structurally set up to lose.
The way out is to make your decisions before the race starts. A deny-by-default policy you wrote last quarter needs nobody’s sign-off in the middle of an incident. It’s already running, already refusing traffic that was never authorized, at the same speed the attack is moving.
Your most critical systems sit inside a boundary the attacker has to break all over again, and usually can’t.
That’s the “machine speed” half of the book’s title.
Why building resilience with Zero Trust can’t wait
All bad things happen inside an allow rule. I’ve been saying that for years, and AI has only compressed the time you have to act on it.
Every quarter spent perfecting prevention is another quarter your critical assets stay reachable from wherever an attacker first lands. Cyber resilience comes from deciding in advance what’s allowed to talk to what, and then enforcing that decision with policy.
Do that work, and the exploit a model wrote overnight has nowhere to go.
Something will get in eventually. Frontier AI only makes that more certain. What will matter on that day is whether you contained the breach and kept the business running while you dealt with it. That’s the stretch of the problem nearly every contributor wrote about.
Get a first look at Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Download your exclusive preview today.
STATSHOT
Targets of Interest
Technology remained the leading target for nation-state actors, with intrusions rising 6% in the last year. The biggest shift was in financial services, where activity jumped 29% in a year, moving the sector well ahead of government. Government targeting was unchanged, while consulting and professional services fell 6%. Healthcare edged up just 1%. The data shows most sectors saw little change over the last year, but nation-state targeting of financial institutions rose sharply.

Give Machine-Speed Attacks Nowhere Useful to Go
Over four days in July, AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, and ran 12 waves of attacks with human operators mostly out of the loop. The techniques underneath are familiar ones running on a far shorter clock. This post breaks down how the automated attack chain worked and why Zero Trust segmentation decides how far an AI-driven attack gets.
How Far Can One Spider Crawl In Your Network?
Scattered Spider’s attacks on MGM and Marks & Spencer turned ordinary network paths into ransomware. See why hypervisors, backups, and Active Directory should only be reachable by the workloads that need them. Segmentation helps you close the rest.
Get the industry’s first vendor-neutral Zero Trust certification.












