Illumio is a Customers’ Choice in the 2026 Gartner Peer Insights for Network Security Microsegmentation.

Iran’s Banking Attacks Prove Zero Trust Pays Interest

Christer Swartz
Director of Industry Solutions

In mid-June people across Iran walked up to ATMs that had simply stopped working.  

Point-of-sale systems froze mid-transaction, and bank balances didn’t match what people knew they had. The attack disrupted Bank Melli, Bank Saderat, Bank Tejarat, and the Export Development Bank of Iran. Some services stayed shaky well into July.

No group has credibly claimed the attack, and Iranian officials say the source is still unknown. It made no difference. A country’s banking system treated like a military target, because as far as the people running these campaigns are concerned, it is one.

Air, sea, and land have always been theaters of war. Cyberspace now sits right alongside them, and that changes the math for every security leader — and not just the ones working in high-risk sectors.  

If cyberattacks are acts of war, any company can become collateral damage in a conflict it has nothing to do with. Zero Trust is the only strategy built for that reality.

Cyberspace is the newest theater of war

Striking a country’s banking infrastructure or freezing its ATM network is now discussed with the same seriousness as a missile strike or a naval blockade.  

Cyberspace is now a battlefield. The tools and tactics used in state-sponsored conflict are being tested, refined, and eventually recycled, and none of it stays contained to the two countries actually fighting.

The Five Eyes intelligence alliance has already weighed in. It’s told businesses that cybersecurity can no longer be treated as a back-office IT concern.  

When an intelligence agency that’s usually focused on tracking terrorists and hostile governments starts talking to boardrooms, it’s a sign the line between geopolitics and everyday commercial risk has effectively disappeared.

You don’t have to be the target to become collateral damage

A bank, hospital, manufacturer, or logistics company can be hit by nearly identical tactics tomorrow. None of them needs any connection to whatever conflict inspired those tactics in the first place.

Most security teams still operate as if their perimeter defenses are the whole story. That mindset assumes an attacker needs a specific reason to target you.  

But plenty of attackers don’t need a reason at all in a world where cyberattacks double as geopolitical signaling. They need just one vulnerable system to wreak havoc, and increasingly, they’re using AI to find one faster than ever.

Zero Trust assumes you’re already in the blast radius

This is exactly the scenario Zero Trust was built for.  

A Zero Trust architecture doesn’t need to know who the attacker is or why they’re inside the network before responding. It assumes attackers are already there, or will be soon, and focuses entirely on limiting how far they can move once they arrive.

That’s a different posture than most traditional incident response frameworks. Many teams spend precious hours trying to attribute an intrusion before deciding how to contain it.  

If a system starts behaving abnormally, segmenting it off immediately matters far more than knowing where the traffic came from. It doesn't matter whether it’s a hostile government or a criminal group renting the same tools.

There’s no neutral side in the cyberwar

AI is shrinking the gap between a state-sponsored campaign and a copycat attack on an unrelated company. Techniques that once stayed locked inside classified briefings now show up in common attack kits within months.  

Unfortunately, some teams still treat Zero Trust as optional. They tell themselves they’re not geopolitically significant enough to be a target.  

But those are the ones most likely to learn the hard way that significance was never really the point.

There’s no neutral ground in this kind of war, only security teams that contain the blast radius in time and those that didn’t. Assume you’re already a target, and let Zero Trust handle the rest.

Zero Trust Resources

GUIDE

Zero Trust Segmentation for Dummies

Breaches are inevitable, but the damage isn’t. Zero Trust Segmentation for Dummies simplifies how to stop threats from spreading, protecting your organization before they cause harm.

Read now
REPORT

The Containment Gap

Most security teams trust their detection. They shouldn't. New research from a global survey of 700 IT and cybersecurity leaders reveals a massive gap between spotting threats and stopping them — with only 17% able to isolate a compromised asset in near real time.

Read now
REPORT

2025 Global Cloud Detection and Response Report

Discover how 1,150 global cybersecurity leaders are tackling alert fatigue, blind spots, and lateral movement in the hybrid multi-cloud.

Read now

Ready to learn more about breach containment?