Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Zero Trust and blast radius: what IAM and security teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: AI has not changed the fundamentals of security, but instead reinforces Zero Trust, according to Illumio. John Kindervag frames the core issue as organisations doing it wrong rather than Zero Trust being broken, and the message is that containment, blast-radius reduction, and resilience remain the practical controls that determine whether breaches spread.

NHIMG editorial — based on content published by Illumio: Zero Trust Isn’t Broken. Most Companies Just Do IT Wrong

Questions worth separating out

Q: How should healthcare teams reduce blast radius after an identity compromise?

A: Healthcare teams should reduce blast radius by segmenting access around identity, not just around network location.

Q: Why does Zero Trust still matter in AI-heavy environments?

A: Zero Trust still matters because AI changes attack speed, not the need for verification and containment.

Q: What do security teams get wrong about discovery in Zero Trust?

A: They often treat discovery as a one-time inventory exercise instead of a continuous governance function.

Practitioner guidance

  • Reduce lateral movement paths through segmentation Identify the systems that a compromised human identity or service account can reach, then split high-value assets into smaller trust zones.
  • Test containment with identity-based attack paths Run exercises that start from a realistic compromised credential and measure how far it can move before controls stop it.
  • Align PAM and NHI controls to the same blast-radius model Review whether privileged human access and non-human access are governed with the same containment objectives.

What's in the full article

Illumio's full article covers the commentary and context this post intentionally leaves for the source:

  • John Kindervag's full argument on why Zero Trust fundamentals still apply in AI-driven environments
  • The original CSO framing and publication context for the commentary
  • Illumio's accompanying breach containment positioning for teams evaluating segmentation
  • Related perspective on how resilience and containment fit into broader zero-trust adoption

👉 Read Illumio's CSO commentary on why Zero Trust still works in AI-driven security →

Zero Trust and blast radius: what IAM and security teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Zero Trust has not failed. Many implementations have simply stopped at policy language instead of enforcing containment. The article reflects a familiar programme gap: organisations adopt Zero Trust vocabulary but leave identities, workloads, and network paths too broadly connected. That gap is especially visible where human IAM, NHI governance, and segmentation are managed as separate workstreams. The practitioner conclusion is straightforward: if compromise can still traverse the environment, Zero Trust has not been operationalised.

A question worth separating out:

Q: Who is accountable when identity compromise causes operational disruption?

A: Accountability typically sits with the teams responsible for identity governance, infrastructure resilience, and incident response, because the failure spans all three disciplines. In hybrid estates, restoring endpoints is not enough if the identity layer is still compromised. Governance must define who owns trust restoration and recovery validation.

👉 Read our full editorial: Zero Trust still fails when teams ignore containment and blast radius



   
ReplyQuote
Share: