Zero Trust in the AI Era: Start Small, Protect What Matters
John Kindervag提出零信任理念,并强调从小范围开始建立微边界。他指出常见错误包括先购买产品再应用和一次性保护所有东西。他还提到AI的作用在于自动化防御而非修复设计错误,并建议分阶段实施。
2025-8-4 13:59:20
Author: securityboulevard.com(查看原文)
阅读量:17
收藏
John Kindervag—the analyst who coined “zero trust” back in 2010—joins Alan Shimel to talk about how the idea has grown from a heretical memo into standard security doctrine. Kindervag, now at a microsegmentation vendor, still starts every project with the same question: what exact data or system are you trying to protect? His shorthand for that target is the “protect surface,” and he argues you build a micro-perimeter around it before touching anything else.
Too many teams flip the order. They buy a shiny product, point it at the whole network and hope a strategy emerges. That almost always fails, Kindervag warns, because zero trust is a design process, not a SKU. The other common pitfall is trying to secure everything at once; successful rollouts tackle one protect surface at a time and expand only after lessons are learned.
AI inevitably enters the chat, and Kindervag is unfazed. He’s “not losing sleep” over smarter attacks because defenders can use the same technology to automate visibility and policy enforcement long before bad packets reach their target. His mantra: if “only a machine can defeat another machine,” zero trust supplies the blueprint for wiring those machines together—micro-perimeters, segmentation policies and continuous validation combine to raise an attacker’s cost until they move on to softer targets.
The conversation’s takeaway is pragmatic. Zero trust hasn’t morphed into a single product or a one-click wizard, and AI won’t magically fix design mistakes. Start with a modest, low-sensitivity protect surface; learn by doing; then iterate. Treat technology changes—be it smart NICs, GPUs or generative models—as modular parts that plug into the same strategy. Do that, Kindervag says, and you’ll turn big-picture principles into day-to-day security wins long before the next buzzword hits your inbox.

Alan Shimel
Throughout his career spanning over 25 years in the IT industry, Alan Shimel has been at the forefront of leading technology change. From hosting and infrastructure, to security and now DevOps, Shimel is an industry leader whose opinions and views are widely sought after.
Alan’s entrepreneurial ventures have seen him found or co-found several technology related companies including TriStar Web, StillSecure, The CISO Group, MediaOps, Inc., DevOps.com and the DevOps Institute. He has also helped several companies grow from startup to public entities and beyond. He has held a variety of executive roles around Business and Corporate Development, Sales, Marketing, Product and Strategy.
Alan is also the founder of the Security Bloggers Network, the Security Bloggers Meetups and awards which run at various Security conferences and Security Boulevard.
Most recently Shimel saw the impact that DevOps and related technologies were going to have on the Software Development Lifecycle and the entire IT stack. He founded DevOps.com and then the DevOps Institute. DevOps.com is the leading destination for all things DevOps, as well as the producers of multiple DevOps events called DevOps Connect. DevOps Connect produces DevSecOps and Rugged DevOps tracks and events at leading security conferences such as RSA Conference, InfoSec Europe and InfoSec World. The DevOps Institute is the leading provider of DevOps education, training and certification.
Alan has a BA in Government and Politics from St Johns University, a JD from New York Law School and a lifetime of business experience.
His legal education, long experience in the field, and New York street smarts combine to form a unique personality that is always in demand to appear at conferences and events.
alan has 98 posts and counting.See all posts by alan
文章来源: https://securityboulevard.com/2025/08/zero-trust-in-the-ai-era-start-small-protect-what-matters/?utm_source=rss&utm_medium=rss&utm_campaign=zero-trust-in-the-ai-era-start-small-protect-what-matters
如有侵权请联系:admin#unsafe.sh