Illumio is a Customers’ Choice in the 2026 Gartner Peer Insights for Network Security Microsegmentation.

How Cyber Resilience Ended Up in the Title of My New Book

John Kindervag
Chief Evangelist

A few months ago, if you’d asked me what my new book would be about, I’d have said Zero Trust in the age of AI, and I’d have left it there.

My fellow contributors’ chapters changed my mind. They came in from people working on identity, architecture, policy, agentic AI, and federal programs. Nearly all of them spent their pages on the same stretch of the problem: what happens in the hours and days after an attacker is already inside.

By the time the manuscript came together, it made sense that “resilience” needed to be part of the title. Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era is out in October, and the exclusive preview is available today.  

Cyber resilience is the ability to absorb a compromise and keep operating through it, and Zero Trust is the strategy that produces it.

We’ve been grading ourselves on the wrong question

For most of my career, the cyber industry has measured itself against one thing: did anything get in? We bought products against that question, built budgets around it, and reported it to boards.

I stopped believing in it while I was still a pen tester. A client would tell me the perimeter held. Meanwhile, I’d already be inside, carrying their data back out the front door. Every tool in the building trusted anything already inside, and nobody had ever written a rule about leaving.

So I started writing rules for outbound traffic, and I set the trust level on every interface and every packet to zero. Trust is something people extend to each other, and a network has no business doing it.

The lesson from those years stuck with me. Getting in was rarely the expensive part, and companies survived that first compromise all the time. The damage came from the weeks that followed, while an attacker moved laterally across a flat network that gave them no reason to stop.

Cyber resilience is the difference between those two outcomes.

Prevention asks you to outrun a machine

AI hasn’t changed that lesson. What it’s changed is the tempo.

A frontier AI model can hand an attacker a working exploit in an afternoon. Closing that same vulnerability across a real environment takes a testing cycle, a change window, a few approvals, and several teams who each own a piece of the problem. That runs in weeks.  

AI is making both sides faster. But it only removes the obstacle on one side. The defender’s obstacle is every person who has to say yes before the code ships. No model shortens a change advisory board.

That’s the trap in prevention-first thinking. It asks you to win a race you’re structurally set up to lose.

The way out is to make your decisions before the race starts. A deny-by-default policy you wrote last quarter needs nobody’s sign-off in the middle of an incident. It’s already running, already refusing traffic that was never authorized, at the same speed the attack is moving.  

Your most critical systems sit inside a boundary the attacker has to break all over again, and usually can’t.

That’s the “machine speed” half of the book’s title.

Why building resilience with Zero Trust can’t wait

All bad things happen inside an allow rule. I’ve been saying that for years, and AI has only compressed the time you have to act on it.

Every quarter spent perfecting prevention is another quarter your critical assets stay reachable from wherever an attacker first lands. Cyber resilience comes from deciding in advance what’s allowed to talk to what, and then enforcing that decision with policy.  

Do that work, and the exploit a model wrote overnight has nowhere to go.

Something will get in eventually. Frontier AI only makes that more certain. What will matter on that day is whether you contained the breach and kept the business running while you dealt with it. That’s the stretch of the problem nearly every contributor wrote about.  

Get a first look at Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Download your exclusive preview today.

Zero Trust Resources

GUIDE

Zero Trust Segmentation for Dummies

Breaches are inevitable, but the damage isn’t. Zero Trust Segmentation for Dummies simplifies how to stop threats from spreading, protecting your organization before they cause harm.

Read now
REPORT

The Containment Gap

Most security teams trust their detection. They shouldn't. New research from a global survey of 700 IT and cybersecurity leaders reveals a massive gap between spotting threats and stopping them — with only 17% able to isolate a compromised asset in near real time.

Read now
REPORT

2025 Global Cloud Detection and Response Report

Discover how 1,150 global cybersecurity leaders are tackling alert fatigue, blind spots, and lateral movement in the hybrid multi-cloud.

Read now

Ready to learn more about breach containment?