Illumio is a Leader and a Customer Favorite in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

The Zero Trust Hub Editions

Zero Trust trends, insights, and resources for today’s cybersecurity leaders

Subscribe on LinkedIn
September 26, 2026
Want more Zero Trust trends, insights, and resources?
Explore Past Editions

The Monday Microsegment for the week of 9/28/2026

NEWS

A Breach Shouldn’t Be a Performance Review for Your CISO

In Resilience Forward, Raghu Nandakumara says boards are evaluating security on the wrong thing: whether a breach happened. No CISO can wipe out all cyber risk. The job is to manage risk within the tolerance and budget the board agreed to. So the real question is whether the program met that bar.

Read more
NEWS

Stop Chasing Cyber Threats. Start Containing Them.

On the Cyber Sidekick Podcast, Raghu Nandakumara argues that prevention and detection alone are no longer enough. He explains why organizations must prioritize containment and focus security investments on the business processes that matter most to reduce operational risk.

Listen now
THE WEEKLY BRIEFING

Seeing Is Deceiving: Zero Trust for the Deepfake Era

John Kindervag
Chief Evanglist

In January 2024, a finance employee in the Hong Kong office of the engineering firm Arup got a message about a confidential deal.  

He thought it looked like phishing, and he was right. So he did the careful thing and joined a video call to confirm it. He saw his CFO’s face, heard his CFO’s voice, recognized other colleagues who also joined, and approved fifteen transfers worth $25.6 million.

Every other person on that call was a deepfake built from public footage.

Chase Cunningham, also known as Dr. Zero Trust, makes an interesting point about that case: the employee did the right thing by checking, but the check still lied to him.

Every control you run rests on an assumption about what’s difficult, expensive, or impossible to fake. In the past, a face, a voice, and a signed vendor update each served as proof of identity because forging them cost more time and money than the fraud returned.  

Today, AI has dropped that time and cost to almost nothing. Security controls built to work on those assumptions are still running, except now they’re outdated and handing access to attackers.  

Zero Trust starts from the position that any signal can be forged, so instead it focuses on what something can reach once it gets inside your environment. Verification tells you what showed up at the door, but policy decides how far into the building it gets.

Trust is a vulnerability, and now it fails at machine speed

Trust is a human emotion with no place in a digital system. I’ve argued that for 15 years. The Arup story puts a price tag on it.

The pattern repeats across the decade. MGM’s help desk trusted a caller who knew the right employee details. Thousands of companies trusted a signed SolarWinds update from a vendor they’d worked with for years. Each control did its job while the assumption underneath it was already bankrupt.

What’s changed is how much time you get to catch one of those assumptions failing. In 2022, handing stolen access from one criminal group to another took most of a day. By 2025, the fastest recorded breakout time from a compromised host was 27 seconds.

So ask what your security policy's reaction time is. If revoking a hijacked service account takes a ticket, a change window, and three approvals, you've built a control that moves in geological time next to the attack. Those decisions have to be made in advance and enforced without you.

Assume every agent is compromised, then limit what it can reach

Machine identities now outnumber human ones by a wide margin.  

A growing share are AI agents that spawn sub-agents. Unlike your human employees, none of them go through onboarding or security training, and none of them get suspicious when something feels off.

Prompt injection means an agent’s orders can be rewritten by any document it reads. Unfortunately, no system prompt solves that.

How do you fix this? Give every agent a named human owner, an end date, and a kill switch you've tested. Then put enforcement outside the agent, where its failure modes can't reach it.

That outside layer is what Zero Trust was built for. Define the protect surface, map the flows into it, then write policy that denies everything you haven’t explicitly allowed.  

Microsegmentation is how that policy gets enforced between workloads, and it’s what stops lateral movement when a forged signal gets through.

Zero Trust starts when verification stops working

The assumptions inside your policy are expiring faster than your review cycle can catch them. Every signal your controls treat as proof was priced for a world where faking it took a studio or a nation-state budget.  

That work now runs on commodity hardware in an afternoon.

Waiting costs you because it compounds your exposure. Each quarter adds more machine identities with standing access and more paths into your best assets.  

Assume the signal is fake and the agent is compromised, then go find out what either one can reach. That answer is your real security posture, and Zero Trust is how you shrink it before somebody else measures it for you.

Read more
STATSHOT

What’s Exposed

Customer PII was the most common type of data stolen or compromised in both 2025 and 2026, with little change between the two years. Employee PII and intellectual property also changed little. Anonymized customer data was breached more often in 2026, while other corporate data saw the sharpest decline.