The Zero Trust Hub
Trends, insights, and resources for today's cybersecurity leaders. Updated weekly.
Venice Learned to Contain a Breach in 1423. We’re Still Catching Up.

VP, Industry Solutions
In 1423, Venice built a hospital on an island in its lagoon and held every arriving ship there for 40 days before anyone aboard could come ashore. It’s one of the oldest containment policies on record. And six centuries later it’s still the one most security programs skip.
The city had no theory of contagion and no way to tell a healthy ship from a plague ship at the harbor mouth. So the Venetians changed the question. Once a ship docked, how far could its crew go, and for how long?
The answer was a holding zone, escorted movement, and hard limits on where a crew could go once ashore. It’s where we get the word quarantine: quaranta giorni, 40 days.
Today, most of our security spending still sits at the harbor mouth. Firewalls, gateways, and detection tooling all work on what gets in, and little of it follows traffic once it’s inside. That leaves the question that decides how bad a breach gets: how far can an attacker travel after they land?
Zero Trust puts that question at the center of the architecture. Microsegmentation is how you answer it. It applies least-privilege access inside your environment, so a compromised workload can reach only the systems it needs to do its job — and nothing else.
Containment is a decision you make before the attack. And it’s a topic I wrote about in John Kindervag’s new book, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era, out this October.
Absence makes the budget wander
Almost nobody argues against segmentation anymore. The disagreement shows up at funding time: the program gets scoped down to a pilot, and the pilot gets pushed to a quarter with more room in it.
Segmentation is easy to defer because it works in the opposite direction from detection. Detection reports what’s happening in the environment, so every alert it raises is evidence that it’s earning its budget. Segmentation keeps things from happening and leaves nothing to report.
At budget time, detection brings the board incidents raised, response times, and a line moving up and to the right. Segmentation brings a quarter where a breach never turned into a major cyber incident and operations continued as normal. Budget follows the controls that can show their work.
So segmentation waits, the way it waited through client-server, virtualization, and the move to cloud. The argument holds steady each time: the platform is moving fast, segmentation would slow it down, and controls can wait until the migration settles.
Migrations never settle, and controls added later always cost more.
Lateral movement is where the money is
IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million. Most of it goes to detection, escalation, and lost business, so the size of the bill follows the size of the attack’s blast radius. The blast radius is a function of reachability, and reachability all comes down to how your architecture is designed.
Attackers have worked this out. Verizon’s 2026 Data Breach Investigations Report found ransomware in 48% of breaches, and 69% of victims refused to pay. When most targets won’t pay for a decryption key, the leverage has to come from somewhere else — so extortion groups have shifted from locking files to causing as much operational disruption as they can.
Reach is the product now. Segmentation goes straight at that business model, because it takes away the reach that makes the extortion pay.
AI runs the old playbook faster
Then AI arrived.
Last July, Sysdig documented JadePuffer, a ransomware operation run end to end by a large language model (LLM). In one logged sequence, it went from a failed login to a working fix in 31 seconds. Two weeks later, Hugging Face disclosed a breach in which autonomous agents from OpenAI escaped their sandbox, harvested credentials, and moved into internal clusters.
Strip the AI out of either incident, and you’re left with an unpatched internet-facing service, credentials reused where they shouldn’t have worked, and movement into systems the agents had no business touching. That’s lateral movement at its most basic.
Attackers are still using the same playbooks as they always have. What’s changed is how fast they can run through them. When an intruder can fail, adapt, and succeed inside half a minute, containment has to be in the environment already, enforced without waiting for anyone to approve it.
Nobody gets 40 days anymore
Venice got 40 days because ships were slow. But nothing in your environment today moves slowly.
Agentic AI is about to put more non-human identities in your network than you’ve ever managed, each holding credentials and reaching across systems by design. Every quarter you delay adding breach containment adds paths to map, policy to write, and cost to work you’ll end up doing anyway.
So start small. Pick the one system you can’t afford to lose and draw a boundary around it before an attacker maps the route for you. A single enforced boundary this quarter does more for you than a perfect plan next year.
Venice worked this out in 1423 without knowing what it was fighting. We know exactly what we’re fighting, and we already have the tools to contain it. The only thing missing is the decision to use them.
Get a first look at Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Download your exclusive preview today.
STATSHOT
The Threat Has a URL
Malicious activity in 2025 was overwhelmingly tied to URLs, not files. URLs accounted for 98.3% of all detections, while files made up just 1.7%. That means URL-based detections outnumbered file-based detections by more than 56 to 1. The threat wasn’t primarily hiding in an attachment. It was waiting behind a link.

Give Machine-Speed Attacks Nowhere to Go
Over four days in July, AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, and ran 12 waves of attacks with operators mostly out of the loop. See how the automated chain worked and where segmentation stops it.
How Far Can One Spider Crawl In Your Network?
Scattered Spider’s attacks on MGM and Marks & Spencer turned ordinary network paths into ransomware. See why hypervisors, backups, and Active Directory should only be reachable by the workloads that need them. Segmentation helps you close the rest.
Get the industry’s first vendor-neutral Zero Trust certification.












