Illumio is a Customers’ Choice in the 2026 Gartner Peer Insights for Network Security Microsegmentation.

The Zero Trust Lesson Hiding Out on Alcatraz

John Kindervag
Chief Evangelist

I’ve spent most of my career explaining Zero Trust in conference rooms. A few months ago, I got to explain it in a cell block.

I was standing on Alcatraz with my friend Hazel Cerra, who recently retired after 26 years in the United States Secret Service. She’s protected presidents around the world and sent people to places a lot like the one we were touring.  

I asked for her first impression. She looked down that long row of iron doors and said she couldn’t imagine why anyone would commit a crime that lands them here. It is, in her words, the definition of the slammer.

Alcatraz earned its reputation on being unusually clear about who belonged inside the walls and how far they could move once they were there. Most security programs never quite make that decision. We’re too busy watching the attack surface grow every time somebody spins up a container or signs up for a new AI tool.

Zero Trust asks a smaller question: what are you actually protecting? The answer is your protect surface, which includes mission-critical data or assets that, if compromised, would negatively affect the business. Defining it is Step 1 of the Zero Trust model, because every control you build afterward depends on getting it right.

Watch our discussion in Alcatraz here:

The Secret Service protects in layers

Hazel described protection as layers, rings running from the outer edge all the way in to the principal. They even protect the airspace overhead. Before a president lands, an advance team has already walked the route, mapped the sightlines, and assigned every resource a job.

Notice what the Secret Service doesn’t do. They don’t secure the entire city. Instead, they focus on the thing that can’t be lost, then build outward from it to protect it in rings.

Focusing on your attack surface works against you here, because it’s unbounded and it expands while you sleep. Your protect surface behaves differently. It’s small, knowable, and changes slowly enough that you can write real policy around it.

Maximum to the problem, minimum to everything else

That’s how Hazel described triage in the Secret Service. When something goes wrong, resources surge toward the principal, and everything else gets the minimum.

Most security budgets do the opposite. We spread controls evenly across the whole environment and end up equally mediocre everywhere.  

A Zero Trust architecture fixes the math by moving the control as close to the asset as it will go, which is exactly what a microperimeter is. You draw one around each protect surface, then write policy that says what’s allowed to talk to it, on which port, for what purpose. Everything else is denied.

This is where I remind people that all bad things happen inside of an allow rule. Knowing your protect surface tells you which allow rules deserve the most scrutiny.

Plan for doomsday every single day

I asked Hazel whether the Secret Service’s mission was really about preventing the bad thing. Her answer was that they expect the bad thing, so they plan for doomsday daily.

In cybersecurity, we call that assume breach, and it changes what good looks like. Containment works. It’s why we have prisons, and it’s why Zero Trust uses microsegmentation to enforce least-privilege access between workloads.  

The intruder who gets in still has to get somewhere, and a well-defined protect surface makes “somewhere” very small.

Defining your protect surface can’t wait

Attackers now move in minutes, with AI shrinking the gap between an initial foothold and real damage.  

If you haven’t named your protect surface before the alert fires, you’ll be defining it during the incident, with the CEO on the phone and the clock running. That’s the most expensive hour to decide what matters most in your environment.

Define it now, while it’s quiet. Name your critical assets, draw the microperimeter, write the policy, and enforce it.  

Alcatraz worked because somebody decided what was most important to lock down long before anyone tested it.

Zero Trust Resources

GUIDE

Zero Trust Segmentation for Dummies

Breaches are inevitable, but the damage isn’t. Zero Trust Segmentation for Dummies simplifies how to stop threats from spreading, protecting your organization before they cause harm.

Read now
REPORT

The Containment Gap

Most security teams trust their detection. They shouldn't. New research from a global survey of 700 IT and cybersecurity leaders reveals a massive gap between spotting threats and stopping them — with only 17% able to isolate a compromised asset in near real time.

Read now
REPORT

2025 Global Cloud Detection and Response Report

Discover how 1,150 global cybersecurity leaders are tackling alert fatigue, blind spots, and lateral movement in the hybrid multi-cloud.

Read now

Ready to learn more about breach containment?