Dr Chase Cunningham: Good morning, good afternoon, good evening, good I don't know, whatever it is, wherever the hell you are. my name is Chase Cunningham or Dr. Cunningham, Dr. Zero Trust, whatever. It doesn't really matter. I'm here with important people, the security Jedi. There's no security Sith that I'm aware of, but we have the Jedi here. So why don't you give us a little bit of background on who you are and what you do, and then we'll start talking through this very interesting report you guys just published. SecurityJedi: Yeah, man. thanks thanks for having me first of all. But for folks that haven't met Nicholas D'Cola, the VP of customers here at Zero Networks. been here for several years, helping grow the company. Before that, I spent fifteen years at Microsoft leading various cloud security teams and and working with customers to solve security challenges. So yeah, again, thanks for having us. Dr Chase Cunningham: Yeah, so this is interesting report, near and dear, kind of close to my heart, cause lateral movement I think is I honestly don't care about the breach side of it, because breaches happen, like you're gonna get popped. That's just the nature of the beast. But where things go wrong is the lateral movement thing. So let me throw some of these stats out here from the executive summary, because this is where it really starts to get interesting. So eighty-seven percent of servers accept inbound RDP or SSH traffic from many internal resources. 78% of servers are reachable over SMB or WinRM. 43.2% of internal authentication still relies on old ass NTLM. And 12.2% of organizations exhibit observable user-to-server administrative pathways. So, like those are the the immediate like knee-jerk data points here. Let's walk through why that's so significant. SecurityJedi: Yeah, if funny, we'll we'll start on NTLM because it's maybe the oldest. is just, you know, again, this is back to how networks were built. We we plugged everything together to make it work, because the IT guy was told, make that shit work. and he went and made it work. And it all worked. And you know, the applications are built. And the good thing about Microsoft, you know, from the days I was there, like Windows is just backwards compatible. Although I did read recently that the next version of Windows will actually disable NTLM. by default. but of course I'm sure some GPO will turn it back on in the environment. so I still think we have a lot of work there. But yeah, I mean just using a a legacy auth is like you know harder for customers to turn off in the environment. And so we see, you know, almost 50% or almost half s of traffic still authenticating uses NTLM because of legacy applications. I mean, I've been to manufacturers that said, I have this Windows NT box on my manufacturing floor and that app still runs because it runs the manufacturing floor and we have no plans to get rid of it. And that kind of stuff happens and I I I get it, it's tough. But then how do you like take that thing and box it off in the corner so that at least you know when you get breach, 'cause you know, assume breach like they can't actually use that in the environment. Dr Chase Cunningham: Fix here. All right, cool. so I mean, following on to that, like I I do stuff all the time looking through Shoden and other things just because number one, I think it's fun to poke around the internet, but those are external RDP and SSH and misconfigurations. But what we're talking about here is the internal side, like the coming from there to the inbound stuff and then being able to do things within that infrastructure. explain the risk to the non technical network geeks here, 'cause they would just think, Well, aren't networks supposed to be connected? Like, isn't that how this thing works? SecurityJedi: Yeah, I mean, I always like to use the house model, right? Like, hey, if I walk in your house, you don't want me to just walk into your bedroom, right? I I'm I don't live with with Dr. Zero Trust, right? Nor should I be in your bedroom snooping around. That'd be kind of weird. why do you want an attacker to be able to do that? So yeah, you want some connectivity so apps can do what they need, but if you take going a little more technical, if you take an application server, it's got all these ports listening, you probably only need one or two. And instead we just leave open everything, which means it's open to that attacker. So it's almost like, hey, that door to your bedroom should have maybe have a little hole so that somebody can give you as, you know, food if they're delivering food, but you know, shouldn't be allowed to just walk in your room if if they're not really intended to be in that room. and yeah, I mean RDP and SSH is great utilities. It allows, you know, IT admins to be able to do what they need to do on a day to day basis. But it is the bane that keeps attackers running free and and doing what they love to do inside of a network, right? Like once they're in, I want privilege on that next machine, right? And if you look at any of these tools, even you know, automated pen test tools or any pen test team, they all mimic the same thing that the attacker does. and they do the same thing. They just get in and now it's happening at AI speed, which is even more concerning. Cause now if I get in and I have an AI automation and you shared that article about the first kind of autonomous AI attack running an environment, like if that thing knows, let me just go try and see where RDP's open. That's a quick ping sweep across the network and boom, now I know everything is Windows, I know everything is Linux. Now I know what to go target. And I've just done my recon in literally seconds, right? Like not hours, days or weeks that it would normally take them to do that. Dr Chase Cunningham: Are we are we, since we're talking on the AI side of things, are we at the stage of like cataclysm, I guess? Because if we don't start doing things better, I mean, the there's no stopping this AI related freight train, whatever. I mean, is from a network perspective, are we staring down the gun of like things can go horribly awry very quickly, or is it just still the same stuff, but we need to deal with it in a you know Expedient manner. SecurityJedi: so I don't think expediency necessarily fixes it. Like take take we've been talking to some customers and you know they're worried about mythos. Like, okay, that means Microsoft is able to find patches and vulnerabilities in Windows or Linux or whatever. But that also means if the attacker can use that type of AI frontier model as well, they can also find those fast and potentially use them in the environment fast. which means now instead of them poking and prodding for weeks looking for that zero day, looking for that thing that they can use. Now they can do that in minutes. So I don't know if we're like looking down I I mean, I venture to bet that we're looking looking down the the barrel of the gun because ultimately the way to close those things down is patching, but you're reliant on the vendor to release the patch. And what patching process have you ever seen that can get done in a few hours? I mean, any environment I've ever worked in with customers, like patches are maybe monthly process at best. Dr Chase Cunningham: If you're lucky, yeah. SecurityJedi: yeah. I've seen many where the that patching process is like, you know. 90 days to 180 days once the patch releases. Dr Chase Cunningham: Years SecurityJedi: Yeah. In other places, because we don't know what apps will break when we do it. And then and like and so, you know, I just don't think patching is gonna solve the problem because even if Microsoft released it and it came out or Linux released a patch, you still gotta get it, you gotta test it, you gotta make sure your development team tests their application on top of it. So expediency doesn't make any faster. I do think a gentic passing patching and testing process will make it easier. Don't think it'll make it faster because you're still gonna run a wan wanna run it for a week here, a week in prod or sorry, a week in staging, a week in prod before you start rolling out to all the machines. so yeah, I think we're at a point where we have to do something, like really do zero trust inside of networks with, you know, micro-segmentation and other capabilities. And like it's no longer like it's almost like antivirus, you know, 20 years ago. Most people didn't have it, and then at one point you're like, shit, we just have to have it. Like it's a baseline. And then EDR became that next baseline. And now this is kind of the next baseline, especially with AI speeding all this up. Dr Chase Cunningham: Well, mean the following on there, it's in the first ten pages. You guys say the top ten risks that enable lateral movement. One, broad admin protocol exposure. Okay, excessive number two, excessive reachability. Number three, privilege access, excessive privilege access. Number four, overprivilege, number five, legacy authentication. Number six, exposed control plane infrastructure. Number seven, vulnerability pivots, eight, east-west visibility lacking, and then nine and ten. Endpoint to critical asset reachability and poor containment process. I mean, all of those things sound like things that we've been talking about should be fixed for like 30 years, but we're still sitting around with people going like, well, we have to AI this thing and we need to come up with some new way to fix it and you know, blah the market continues to skew horribly into the space around new fangled shit. Like, why is why are those basic things still such a problem? SecurityJedi: I think just in the past, it was hard, right? Like if you go into a large network and you try to do that, let's just take one application and I said, Hey, Chase, go look at that application, gather data for thirty days, analyze that data, figure out what should be allowed, what shouldn't be allowed, and doing all of that with a human for one application is literally at least six weeks, right? And then you're worried, well, wait, did I catch everything in the 30 days? Maybe I should really do it for like 60 days or 90 days, right? So you don't have like the confidence to like just flip the switch and and protect. even if you just went in and said, let's go limit RDP and SSH and SMB, those three major ones that attackers love to use. Like, crap, like who are we gonna break? I don't want to piss off this other IT guy over here that's doing whatever, you know, da da da, or some user that actually RDP's inner developer. So it's very hard for folks. It takes a lot of time and like. The only way to do this is, you know, kind of what we do at zero networks is with automation that's, you know, very deterministic, that takes all that capability that a human would do and shrinks it down so you can do it on all your assets at the exact same time. Right. Like so I think that's the big shift where we focused is because we saw this coming of like, you kind of have to do this and there's no way to do it with humans. Like we just don't have enough capacity and time. We're short on cyber people, like people are already overloaded with responding to the number of alerts they have and all the things they have to do. with other stuff because now you got a whole nother movement. I was talking to a customer today. They're like, we have like five big movements, right, in in the company or, you know, strategic things. One of them was like quantum. You know how much work's gotta go into figuring out where you gotta be ready for quantum? Like yeah, we had a whole conversation just about that. And then we're like, then we have this thing and then we have Microsecond Zero Trust and like a few other, you know, strategic projects and like there's not enough time in the day, unfortunately. Like we need we need to use some automation and some AI to help us solve some of these things. Dr Chase Cunningham: I mean, tangential question, but since you mentioned the quantum thing, like the quant every time somebody says quantum, I just want to find a puppy and punch it because I'm like, this is such a waste of my time. Like, what how do you how what's your perspective on the quantum thing? And like how do you see that as a as a real issue we face today? Cause I mean, here we're literally talking about a report you guys published that's got just really good proof that the basics are still eating people alive, but you said it, you've got customers that are like, We're worried about quantum. It's like Barney Fife trying to figure out how to nu use a nuclear reactor. Like, let's just deal with the real basics first. Or is that is that wrong? SecurityJedi: No, I I'm with you. It's the it's the basics, right? Like it's people I get it, you have to it's back to prioritization, right? Again, we only have so much time as a human. Just like any of your personal things in your personal life, you I say, I gotta get a new license, I gotta go register my car, I gotta do whatever. There's like a bit of prioritization, like I can't register the car until I have a license, and you you gotta stack rank them and go do those things in order. And for some reason, like we try to take on too much and say and and not really Do the risk analysis. And what I mean by that is like, what's the likelihood that it's gonna happen and what's the impact if it happens? Like, sure, if someone cracks quantum computing and can crack your certificates, that's probably not very good, right? Like the impact's very, very high. But the likelihood right now is we're not seeing a lot of people running around with quantum computers doing quantum things, right, in the dark space. because to build one, you need a shit ton of money, right? And until it becomes a little more commodity. But AI, very commoditized. Very easy to get into people's hands. Fable five's now back out there. And you know, you can go sign up for 20 bucks a month. And hey, I'm a security researcher. I want to run this pen test. And it's not very hard to get around those guardrails to start doing those things. So the likelihood there is much higher. And we know the impact is almost the same, right? Somebody gets in spreads and drops ransomware on all your machines. Your business is down. Like they look at the Jaguar thing that happened a couple months ago. That impact, because of all the employees they have. like affected the UK GDP. Like wasn't just Jaguar, it affected UK GDP. and again, the likelihood and impact is is very high, right? So I think the people are not kind of taking in that whole risk matrix of what's the likelihood, what's the impact of that actually happening. Dr Chase Cunningham: I mean that just skews that skews people fixing the problem, I think, right? It's just 'cause you've got all the the chasing of shiny objects and your CEO went to some I don't know, some meeting somewhere and somebody was talking about quantum blah blah and they like, shit, like let's figure quantum and you're the poor CISO sitting there going, like, Well, wait a minute, dude, we got port four four five open on every endpoint in this thing. Like, can we solve that first? And then there's one well, is it quantum resilient? Like, dude, what what the fuck are you talking about? Like, this is not a quantum problem. I d I don't know. I mean Your your your next piece in here talks about excessive internal reachability. And this is this is something that should be very understandable for everybody, is you've got one thing inside of a piece of infrastructure that's talking to a whole lot, like we used to call it the hub and spoke model. I've seen it, you know, and your your your statement is like in the AI era, which is what we're kind of talking about here, containment is survival. Like that should be a very understandable and fixable issue, I would think. SecurityJedi: Yeah, I mean it should be, right? Network segmentation isn't new, right? I mean, we thought about putting firewalls in the middle of the network years and years ago and and we kind of did that. And I'm gonna pick on us IT folk, right? Like w the first time we put the firewall in the middle of the network, we went, shit, RDP and SSH and whatever else doesn't work that I need to use on my daily basis. just write me a rule that allows that everywhere, right? And then I don't have to worry about it anymore. Instead of kind of smartly implementing it and controlling it in a way to protect the environment and contain the contain a breach if it were to happen. So then the results of that is again, we've had networks running for many, many years. and it's just a hodpodge of, hey, Chase did this, Nick did this, so and so did this. And then when you put all that together, it's like, that means everything's reachable everywhere on many, many things, right? Because you solve some problem one day, I solved a problem, and then the next person solved their problem and it ultimately combined to really, you know, open the network up, right? Like it's just kind of a result of the years of building on top of building on top of building. And you know, think about a large company that's doing mergers and acquisitions. They bring in a bunch of stuff and they bring in a bunch of stuff. And then you just got a frank inside of network where, hey, we got to make the business run. And so we opened this to this. And next thing you know, that really meant opening this to that to this to this you know, and you have this big jigsaw of lines connected. Dr Chase Cunningham: Yeah, it's the Rubik's Cube from Hell. And I mean, it's, you know, what was that movie, Hellraiser, right? With the box that kept like reconfiguring itself, and then you wind up with Cenobytes and things get even worse from there. I mean, following onto that, SecurityJedi: Yeah. Yeah. Dr Chase Cunningham: like, you know, benchmark stats here for kind of the ex the privilege side of this, which is also very interesting to me, because every time I do a workshop, I always ask the people in the room how many people in here have PowerShell on their machine? And most people raise their hand. Like, great. How many people in here have not used PowerShell in two years? And everybody keeps their hand up. I'm like, why do we have that? Turn that shit off. Like it shouldn't be that big a deal. And I mean, your benchmark stats, 99% of users hold excessive standing permissions, which are usually unused for more than 60 days. 80% of a tax leverage stolen creds. Shocker. And then most organizations expose administrative services by default. Like those, again, those things are not. difficult, but i is it a is it an understanding or is it a a comprehensive kind of map that is needed or is it just folks are not approaching the problem with a focus on actually solving it? SecurityJedi: I think it's the wrong mindset, right? Like we we need a shift from default allow to default block. Right. and and the model just ha we we absolutely have to flip it. I don't see any other way. like if I was gonna go start from ground zero and build a network today, it would be default block for a network, default block login, and like you would have to have steps to enable those as you need them. And there would have to be a justification on why you're opening that thing, right? Like so that you can track it along the way. but going from a default open to a default block is very, very hard. but this is where I think automation can really help us, right? Of okay, let's learn what's going on in the network and the identities and start to take away those things. Because again, if you take away some of the key ones, service accounts, privilege accounts, and reduce them, not take away, but reduce them so that people can still do their job. But then reduce them from not having a standing privilege all day long that could be reused. Then all of a sudden, like all that like risk just gets reduced and mitigated, right? And yeah, then you have small pieces. Great. Now let's start a project to figure out how to tail down those last, you know, five percent that you need to tail down without breaking the business. And some of that means you gotta go talk to the business. Hey guys, you some dev shit over here talking to prod with a service account and like it shouldn't be doing that. You got six months to fix it. Okay, that's not good enough. You got nine months to fix it. But at least you have that one thing that you can now watch and say, Okay, let's make sure nobody's using this in a in a illegitimate way versus trying to watch everything in the network. It's like trying to watch all the stars at the exact same time and and figure out which one blinked, right? Like if I know that most of those blinks don't matter and that one over there does, then I can focus in on those things to do that. So I I think it's it's just a mind shift mindset shift, right? Like starting with your doors locked and then Opening only as needed. Dr Chase Cunningham: But I mean from when you're talking to customers and you say that that's like the you know, the mind shift that's needed, what's their reaction? 'Cause I know when I talk to people about default deny and those types of things, there's always the like, I don't know if I wanna tell people that we're gonna default deny things. I mean, I think that that's a cop out, but like what what's your, you know, response to that type of issue? SecurityJedi: Yeah, I mean we we get you know some hesitancy, some people are fully bought in, they know this is the way they gotta go. and it's like any organization or big shift in a mindset or change or what whatever we're doing in the IT cyber world, right? Some people are laggards and some people are the people that are on the bleeding edge of the sword or or knife, as you might might say, right? And they're like, Hey, we know we gotta do this, we're gonna be ahead of the curve, we don't wanna be that that last one, and some are like, Okay, I'm gonna let other people do it, and then When they prove it works, then I'll kind of jump on the bandwagon. So I we get a bit a a mix of both. but again, I think the customers that are reaching out to us are a a little bit more leaning that way and they're like, we realize we need to do this. And so, like, this like tell us how how's the easiest way to do this and how we can solve this problem in in a quick manner without breaking the business. and there's always a bit of skepticism and you have to build some confidence and show them, hey, this can work. And once you're like, look, let's take these things over here that are non-critical to your business. Hey, let's really do that micro segmentation. Let's do that identity segmentation as an example. And they go, Wow, that works. Like, cool. Now I got some confidence. Like, okay, let's go pick the next non critical thing and then work up to the big critical stuff. And that normally helps build that confidence and and and you know, helps you build that shift. I mean, it's no different than going to the gym. You don't go in and just bench three hundred pounds. You're like, Okay, I gotta start, you know, building up to that and then you build that confidence, like, okay, cool, I can do three hundred pounds. so you have to you have to build some confidence along the way. It's not gonna be an overnight thing. In my opinion. Dr Chase Cunningham: Yeah, so strategy and you know, taking small chunks and that type of thing. So, okay, well following on to that, when they're thinking about, you know, small, some of your stats on the machine and service identities are pretty sm mind boggling. A hundred and nine to one is the ratio of machine and service identities to humans. And that's in twenty twenty six. By twenty thirty, wouldn't that be eleven hundred to one? I mean, that it's just you can't possibly keep up with things the way they're going with Ricky the intern in a spreadsheet, right? SecurityJedi: Yeah. I mean, just remember, like I remember when I started in the Marine Corps, we had, you know, twenty desktops in in the battalion I was at and twenty users. Right. There was no servers. Like you you kind of shared email over I think it like Banyad Vines at the time, which was didn't really have a central server at time. and then we went to Exchange and N D and then next thing you know, now you have these servers that have to support all these users and that one desktop could have five people logging into it, accessing their mailboxes. And now with the explosion of cloud, I kinda thought SaaS would take it away a little bit, but it doesn't, it just keeps growing. Now with cloud, like I can just spin up twenty resources to do my test and do my thing, and all of those have their own identities and non-human identities that are running around in the environment. So yeah, the explosion just continues to grow. I don't think it's gonna get any smaller, right? and even a SaaS essentially, if you're paying someone's SaaS, they have a bunch of machines and non-human identities running in the background over there. so yeah, it's just I remember a couple of years ago I think I asked around like what's the average user to server ratio and it was like one to fifty and you know, now it's just growing higher and higher and higher. because we're providing more services to the users to be able to do their jobs, right? that's kind of the whole point of what we do in IT. Dr Chase Cunningham: Yeah, I mean it it the the the more you add, the more you add and the more you add it becomes, you know, it's the self licking ice cream cone of misery. I mean, that's you know, where we go from there. I think it was interesting too to read through some of the stuff y'all were pointing out about the Eternal Blue still being a very prevalent issue, move it being one of those ones. Those are I mean, Eternal Blue is from twenty seventeen, and it still is something that you could use. I mean You know, to be perfectly frank, the stuff you were talking about with SMB and RPC and those shares, whatever else. I mean, I was using those for red team ops mm back in two thousand and gosh, like ten. you know, and but they're still there now. And it's we're not doing things much better, it doesn't seem. Well, I mean, is is there Was there during this research like something that came out like, thank God we're getting this right? 'Cause everything I see here and I would just like bash my head against the wall of like, How is this still a problem? SecurityJedi: Yeah, I I I wouldn't say there's anything in the research where I'm like, Cool, we're on the right path, or we're going down the right path, right? It's very, very much a a bit status quo. And personally, some days I'm like, Man, we should just reset and like the next OS version of Linux and Windows should just be like all this legacy crap gone. And you customers, you know, and organizations and it could be even us, need to build to net new standards, right? And if and you know. You you have to, but because if we keep supporting the legacy, I just I think customers will just keep it running, right? and unfortunately it's it's just easier for them. It's cost more cost effective. They're a business, they're trying to make money. I understand why they do it. I don't blame them. they're just they're just trying to do what they do. But yeah, I didn't see anything specific and this is why we really looked into this, is because again, once an attacker gets in, just like you know from your red team days, like once you're in. If all the doors are open, I'm just going wherever I want. I'm going right to that thing or th those things over there and discovering what I really want to get after. and again it depends. It could be a ransomware attack, could be intellectual property theft. but I I think, you know, I see more organizations talking to us, you know, about hey, their zero trust journey and how to you know, get to a point where they can close these things down. So they're thinking about it. So I do think there's thought process moving in the right direction. I think we need to move faster. I think we're behind the curve already and and need to move much faster. Dr Chase Cunningham: Yeah, well, I mean, we can move faster now. I I think that that's that's something that seems to be getting forgot forgotten by a lot of people is like, okay, you're moving faster on everything else, business and all the other things with all these automation. Why not do it for segmentation, isolation, those types of things? 'Cause they're that they're that critical. Like if I was in charge of an org and they said you've got a million dollars and I only could afford one thing, for me, I would focus on isolation segmentation above all, 'cause I I accept that endpoints are gonna get breached. I accept that people are freaking idiots and gonna click on phishing links. You know, I can't take care of their mobile, whatever else, but strategically speaking, focused efforts wise, I can sec section isolate and segment things and that way I know at least it's survivable. SecurityJedi: Because you did you naturally did that risk analysis of the impact versus likelihood and like came to the conclusion somebody's gonna get in, somebody's gonna click on a spearfish. I can't really stop that. I could maybe reduce or mitigate it, but if they do get in and I can stop them from spreading, by the way, if you take away an attacker being able to spread an environment, I always joke, what what are they gonna do? They'll even go to the network that is open because they don't they're they're all operating on an ROI model as well, right? They don't wanna spend all this money trying to get in your network if it's actually contained in a way. so yeah, that's it's it's funny. We had a customer that actually kind of did the same thing. They said, Hey, to their internal team, if we could buy something like Zero Networks that would help us contain a breach versus something like REDR that does detection and response, but I could only buy one, what would you do? And and naturally their their technical folks were like, did the same thing really fast in their head and was like, Well, like if you can't spread, like then that's better for the business. But if I detect you and I miss it and you spread, like That's going to cost us more to the business. So the right thing is containment first. And yes, we still need detection and response. Like we obviously want to try to detect that attacker. But if I only could do one, I want the one that's going to contain, not the one that's going to detect, right? Because detection's important, but we we we see in many, many news articles it's not it's not stopping the attacker. Dr Chase Cunningham: No, and I I think that it's interesting too, when your your points that you guys pointed out about lack of east west visibility, North South is pretty well defined. People typically have a good understanding of ins and outs of what's going on there. But when you get into East West, usually it is the wild west, and they're lucky if they see a percentage of what's going on there. Is is it more because there's too much or is it because they don't have the actual capabilities to even look at that in your opinion? SecurityJedi: I don't think they have the capabilities. They're not naturally built into operating systems, OT devices, et cetera, to give you that East West visibility. So I think they're they're lacking some capability. And I think also if you look at that, like some said, okay, well, I'm at least gonna put a firewall between my data center and all my clients. So like but now you're like instead of having an easy network, you're forcing all the traffic through something, right? Instead of having simplified, you know, more open, more more flat network. not open, but like you could still segment on the endpoints. So one I I just think they're lacking the capability, right? By default, you you can't go to Windows or Linux and be like, show me all network connections and then aggregate those in a way in a very simple way. That's what microsegmentation providers typically provide you is that first visibility and then the ability to actually control it and contain it and and bring it down to only what's needed. so yeah, I I think they're just lacking capability. Again, the the stuff wasn't built that in that model from an OS perspective. Shit, T C P IP wasn't built in that model. Yeah. Dr Chase Cunningham: Well and there's con there's context too, right? Like th that's always something you miss too is context 'cause you a lot of folks well, they're logging 'cause of logs because the logs cause they logged it, but it's like, well, what's the context of what's going on in that transaction? SecurityJedi: Yeah. I mean, even our our partner Palo Alto, as an example, like has some things on their firewalls from from the middle of network of perspective that like hook Active Directory to figure out, you logged onto that machine and now I know it's chase on that machine cause to try to add context. But they had to do all these weird things. I call it weird because it's kind of not natural to how TCP IP was built, right? To try to figure out where, you know, you're at, what machine you're using. It was you that connected to this server to give that visibility. But then again, you you had to go change the network to force the traffic in this model to be able to do that. So yeah, I I think the capability is just probably the biggest lacking piece for for customers. Dr Chase Cunningham: Yeah, capability and context. Okay, so on containment readiness, I thought this was very interesting too. So this is industry standard sort of stuff. Two hundred and forty-one days is the average for identify containment breach, which is a long time. Then y'all calculated it out, which I actually thought this was sort of comical the way the math worked out, right? Is seven seven one comma two hundred to one is the breakout to containment ratio. So that's a big giant ass number. But really the the stat that stuck out most to me was attackers begin moving laterally in as little as twenty seven seconds. And when I immediately saw that I thought like, okay, that sounds a little bit like marketology. But then I backed up and I went, Well, wait a minute. When I was doing red team stuff and I popped a machine, the first thing I did was start figuring out where I was going next. And it didn't take me twenty seven seconds. It was usually like, shit, I got shell, I'm moving to the next thing. that that is a very realistic statistic that people should really take away from this. Twenty seven seconds ain't long. SecurityJedi: And it's gonna get faster, right? To back to the article you shared. if there's an autonomous agent there, like twenty-seven seconds is the time it takes you to go, I'm on the box. Let me try, you know, I know this is the domain controller, mate. One qu one quick query, I know this is the domain controller. This machine's pointing at cool. Let me see if I can quickly move over there. That takes you a few seconds to process, run a command, get it. Okay, cool. Let me see if I can RDP to that machine. That's a quick couple quick commands. But an AI will do that in milliseconds. Right? Like way, way faster than the human can actually do it. and so yeah, it's it's it's gonna I think it's gonna get even faster over time. and by the way, we're not the only one that saw that stat. Like this was also in like CrowdStrike's report, right? So it's not marketology, which is a great scientific verb by or tur term by the way. I love it. so yeah, like it's it's it's happening. It's really in the wild. It's not people just making it up, multiple vendors are seeing this. and I did some IRs when I was at Microsoft and yeah, we saw literally we used to tell people it's literally twenty four to forty hours before an attacker has domain admin in an environment. Like that's on average what we saw in real attacks that we showed up and helped recover on. so you can imagine that's just a machine to domain admin, like breaking out to one other machine is gonna be a lot faster and it's gonna get even faster with autonomous agents for sure. Dr Chase Cunningham: Especially with shared creds and all the other stuff that you're able to pull. yeah, I think it's very interesting one. So the kind of one of the last pieces of this paper that you guys came out with, what I thought was super kind of nuanced and and very applicable for where we're going, right, is emerging watch item, AI driven ladder one. We talked about that a little bit here, but so there's two vectors that you kind of pointed out. Vector one, AI is the attacker, which is what we kinda and then AI agents as the target. And Let me read this because this is something people should pay attention to. And I'll share the link to this report on YouTube and everything else. But enterprises are deploying AI agents and co-pilots inside their environment at unprecedented pace. We know that. Okay, great. Agents that already hold broadstanding access across email databases, cloud API, code repositories, and SaaS platforms are in play. An attacker who can influence the behavior through prompt injection, poisoning, retrieval poisoning, or compromise. Of those credentials inherits the legitimate permissions of that agent. The credential never has to be stolen. That's the the twist on that whole thing, right? And I don't one other piece that people are also starting to pay attention to is agents' memory. All that stuff gets stored in the memory of the agent. And it's the the memories, they don't forget. They're like elephants, you know, or like a a pissed off ex-wife. Like they don't forget. They're always thinking about these things. What's the fix for that? Is it just segmentation isolation or is there a new agentic approach that has to be put in SecurityJedi: I think it's gonna a combination of both. it's funny, I was actually talking to a large partner and distributor, and they were like, hey, we're building all these AI agents, like we're really worried about AI segmentation. And I said, You understand AI segmentation is just network segmentation as a start, right? And they were like, What? And I was like, think about it. If I have an AI agent on a machine and I say it can talk to this LLM in my network and it can talk to this SaaS over here, but it can't talk to Chase's LLM over there, you just segmented it. It can't talk over there. You made sure it can't even access the data. So it has to start at the network layer. Then you have to go to the identity. Okay, what identity is that AI agent allowed to use to access that LLM? And then you have to go to the prompt layer and what data and prompts and guardrails do you need inside of there? So I think it's like a multi-layered approach. and it to me, it starts at the network. Because if you don't have that, again, back to that default block and only allow what's needed, then that AI agent can now all of a sudden start to talk to things. Identity and prompt doesn't matter. If they can reach it, It can reach it and you know, yes, you can limit some identity and prompt inside of that, but if it can't reach it, that's how you stop it from getting to the things that it shouldn't be getting to, right? So it has to start at the network layer, and then yes, we need to move up the stack of controlling the identity that's accessing these various different things, and then what data is inside of those prompts and and returned inside those prompts. So to me it's a multi-layered approach, but it all again goes back to the start of let's start with default to die. Okay, then what are we what AI What are we gonna allow those agents to talk to? Okay, why do they need that access? Cool. Okay, let's allow it. What identity should only be allowed over top of that? And then what guardrails can you put in place on top of that? Right. Dr Chase Cunningham: Yeah, I mean we didn't reinvent the OSI model that I'm aware of. Like the OSI model is still there. We didn't re-architect infrastructure. We just dropped agents in there and their applications that do things quicker, better, faster. So it's yeah, I think the the focus should still be on the right fundamentals at doing it that way. Okay, so these questions, folks, like if you're gonna take anything away from this report, these are the seven questions that you should sort of know about and ask, right? So if one laptop is compromised. What could be reached? Number two, can ransomware spread across business critical systems? Can you reach the backup infrastructure? Cause guess what? If your backups get hosed, everything is hosed. Number three, how many privileged identities carry standing access? Not just whether they're not their privileged, but do they have standing access? How quickly can you isolate a compromise without the business going down? Definitely a very good question. do you measure your internal blast radius every quarter? I would love to see how many honest people said that they've ever even done that. Because my guess would be very, very small. And then the last couple here, how many AI agents run in your environment and what can they touch? And then finally, if an attacker prompts one of those agents, what would it be able to talk to? Like, folks, ask yourself those questions. Make that part of your stand up. Like that, those are things people have to answer. I mean, that that's table stakes, right? SecurityJedi: Yeah, I mean what once you start thinking about those questions, then you say, I don't know the qu I don't know the answer. Like any, you know, human. Maybe we get we're very curious. let's go learn. So, hey, like what's your blast radius? I don't know. Let's figure out how to go measure that. Then now we have a measurement. Cool. Let's see if in the next six months, nine months, whatever, twelve months, I know people have change processes. Let's see if we can get that down by to by ten percent. Now you have a goal, you know, fifty, twenty, whatever percentage that is. You have a goal to work towards to reducing that to make yourself you know, better and more resilient. And all ultimately all of this is cyber resilience, right? Your goal as an IT person is to keep the business running. that is granting them application access, but also preventing the attacker from being able to, you know, take down those applications that they need to use to keep the business running. Dr Chase Cunningham: That's the the takeaway that I think really, you know, for me is that we we're starting to move towards an era of resilience and containment and response. I think people have kind of got to the the broad understanding of like, you know, we stop breaches. Well, except for the breaches, you don't stop, right? I mean that like your breaches happen, anything that's engineered can be reverse engineered. The very nature of, you know, compromises is just proving that. So I think that that's what folks in my opinion should take away. if you're listening to this, you know, podcast. Read this report, reach out to Nick and the other folks over at Zero Networks 'cause they did a great job. I think you guys analyzed like a t twenty something trillion particular pieces of data from this. SecurityJedi: Yeah. Yeah, yeah. Ton ton of signal went into this. And yeah, I would say like we are hearing a a bit more from the board, you know, like, hey, asking the company how are we resilient? And if you're an executive or a leader in a company, I I would be asking yourself today to get ahead of it, how are we providing cyber resilience to the business? And if you're not asking that question and getting an answer for your team, then you should, you know, start again using these type of seven questions we shared. is a good start to really get you there and thinking in that model. Dr Chase Cunningham: Yeah, and the other thing that Zero Networks has got, and I'll put the link to it here, is they've and Nick was instrumental in building this too, was a a breach sort of mapping simulation type capability. And it's it's a really good way for folks to throw this into your system. It's not gonna brick anything. and you're just able to figure out what lateral movement looks like. So if you have that question of like, well, what is lateral movement in our network, why not figure that out instead of just trying to keep guessing? So my two cents would be. I like free stuff and I like tools that give me understanding of what's going on. Look at what's available here and you know, Zero's done a good job of making it where everybody can use it. SecurityJedi: Yeah, we we we really wanted to give something to to the teams to help them, you know, show upwards in a visual way. Like, look, if an attacker were in, again, we focused only on privilege ports, those things that we learned from this report that is what attackers go after and is open in most organization. and like, look, if they get here, they could get here. And if they could get to this thing, they can get to all these other things. Like in a very simple, easy way to understand that you can show any leadership executive board. to justify why you need to go do these things. I that's a lot one of the hardest part about their job is justifying why to invest in these things. so hopefully this will help folks drive that with their cus with their leadership teams. Dr Chase Cunningham: So there you go, folks. Like great report, great analysis. Nick's been awesome. He knows his stuff. and you know, this whole breach map thing is very valuable. So take the time, check it out, use these things and figure it out for yourself. Don't wait. It you quit sitting around with your thumb in your ass waiting for bad things to happen. That's that is not a good strategy. use your thumb for other things than putting it in your ass. It would be my two cents. SecurityJedi: Use it to run breach map. There you go. Dr Chase Cunningham: There you go. Yeah, use your thumb on the breach map button. So awesome. SecurityJedi: Yeah, yeah, yeah. Awesome. Dr Chase Cunningham: Nick, thanks for jumping on here, man. And as always, folks, when you listen to this, look up Security Jedi, look up Zero Networks, check their stuff out. They're solid people and they're they want to help. SecurityJedi: Thanks. Appreciate having us, man.