Security in a Hyper-connected, Asset-driven World & the Real World Attacks that Follow
Download resourcesAbout this session
Nadir Izrael, CTO and co-founder of Armis, argues that most organizations' attack surfaces have exploded beyond managed endpoints into IoT, OT, cloud, SaaS and countless unmanaged connected devices, while most security tooling still targets only the traditional slice. He walks through a real, anonymized case: a hospital ran a proof of concept that mapped its assets and flagged clear, easy-to-fix risks, including an out-of-date, internet-facing Cisco VPN, but never acted on the findings before that same VPN vulnerability let attackers in. He details the resulting ransomware kill chain, from weeks of reconnaissance through taking over Active Directory, disabling active security tools, and encrypting the environment in about two hours, leaving the hospital on pen and paper for nearly two months. He argues attackers are automating reconnaissance and exploitation with AI faster than human SOCs can keep up, making proactive, prioritized risk reduction (rather than exhaustive patching) essential, and closes on framing rising cyber-insurance costs as a persuasive argument for budget. An extended Q&A covers OT-versus-IT risk, data residency, certifications, and how Armis compares to vulnerability scanners like Qualys.
Key takeaways
- Inventory the full attack surface, not just managed endpoints; unmanaged IoT, OT and shadow devices are routinely present and routinely missed.
- Act on easy, cheap fixes an asset-risk report surfaces (unpatched internet-facing systems, invalid certificates, end-of-life software) before they become the entry point for an attack.
- Expect ransomware kill chains to move fast once inside: weeks of reconnaissance can be followed by full Active Directory takeover and encryption in a couple of hours, so early detection during reconnaissance is the best window to intervene.
- Prioritize risk reduction instead of trying to patch everything; the volume of vulnerabilities in any real environment outstrips what continuous patching alone can address.
- Use rising cyber-insurance premiums and quantified attack-cost comparisons as concrete, budget-friendly arguments when pitching proactive security investment to leadership.

