The Illusion of Upgrade: Why Broken Tech Can’t Be Patched into Security
Download resourcesAbout this session
Marc Lueck, CISO in Residence at Zscaler, argues that patching and adding tools onto a 40-year-old firewall-and-VPN architecture cannot fix security, because the architecture itself, not any single vulnerability, is the flaw. He compares this to Maryland's Rourke Temporary Bridge, built to last a decade and still carrying traffic decades later, and walks through cognitive biases, status quo, loss aversion, fear of regret, mere exposure, effort aversion, that keep security teams maintaining tools that no longer deliver value instead of reallocating budget toward higher-value capability. He proposes flipping the typical security investment pyramid: shrink spend on commoditized tools like firewalls and antivirus, and redirect it toward emerging capability judged by outcome rather than tool ownership. He lays out zero trust as five architectural principles, least privilege, least function, least information, least exposure, and negative trust, insisting it is a philosophy to embed, not a product a vendor can sell, since many long-time customers of vendors like his own still have not actually adopted it despite owning the tooling. A long Q&A covers the limits of the NIST zero trust framework, demonstrating control in outsourced cloud environments, and why trust boundaries, not their absence, are what zero trust actually redraws.
Legacy security tech isn’t just outdated — it’s dangerous. From firewalls and VPNs to unsupported operating systems still powering critical services, organizations are clinging to tech that was never built to withstand today’s threat landscape. And yet, every year, more money is spent trying to patch, update, and extend the life of inherently insecure systems. In this provocative session, Zscaler's CISO in Residence Sam Curry, a 30-year veteran and cybersecurity pioneer, explores the real cost of trying to modernize broken architecture — and how Zero Trust principles can help eliminate risk at the root. Attendees will leave with a better understanding of: Why some technologies are beyond saving — no matter how many upgrades or patches are applied The psychological and operational reasons why businesses can’t let go of outdated infrastructure How Zero Trust Network Architecture (ZTNA) eliminates threat vectors like lateral movement and exposed surfaces What to do when business-critical systems can’t be replaced — but must still be protected How to reduce dependency on insecure tech while preserving business continuity Whether you’re a security architect, CISO, or practitioner, this session will challenge your assumptions and equip you with a strategy to stop patching the past - and start securing the future.
Key takeaways
- Stop judging security tools by ownership or compliance checkbox and start judging them by outcome; ask what a firewall actually achieves, not whether you have one.
- Expect status quo bias, loss aversion, and effort aversion to be the real obstacle to modernizing your architecture, not budget or technical difficulty alone; name the bias before you can counter it.
- Deliberately shift investment away from commoditized tools (firewalls, antivirus, VPN) toward higher-value emerging capability, and use that shift, not incremental patching, to absorb a shrinking budget.
- Treat zero trust as five embedded architectural principles, least privilege, least function, least information, least exposure, and negative trust, not a product; owning the tooling does not mean you have adopted it.
- Study a recent third-party or supply-chain incident, even one that did not hit you, and ask concretely how your own architecture and cognitive biases would have handled it.
Speakers

Marc is a CISO and security practitioner with over 27 years of experience crossing multiple industry sectors, from financial services to publishing. With a strong technical background, Marc spent the past 15 years leading security improvement… Read moreRead less
Marc is a CISO and security practitioner with over 27 years of experience crossing multiple industry sectors, from financial services to publishing. With a strong technical background, Marc spent the past 15 years leading security improvement programmes and managing security for the likes of Just Eat, Pearson, T-Systems and Visa Europe. He has been a leading security authority in the UK and Europe for years, spearheading and leading the security peer organisation Club CISO for 3 years, before moving back to his roots in the US this year.
