Re-Thinking Cybersecurity – Zero Trust Visibility & Security
Download resourcesAbout this session
Christer Swartz, director of industry solutions at Illumio, argues that decades of cybersecurity, firewalls, VPNs, deep packet inspection, endpoint agents, have failed because the industry keeps trying to identify a threat before acting, while malware now moves faster than detection can keep up. He proposes flipping that workflow: since nearly all malware lands through human error and then spreads laterally through the same handful of open ports (RDP, SSH, DNS) regardless of sophistication, organizations can shut down unused ports and quarantine anomalous behavior without ever identifying what the threat actually is. He illustrates the approach with real incidents, a hotel breached through a Wi-Fi-connected wall clock, a brewery that kept producing during a ransomware attack because it stayed contained to one workload, and describes Illumio's platform: per-workload microsegmentation instead of VLAN-based network segmentation, a correlation tool called Insights that pulls telemetry from firewalls, cloud, and EDR tools into one security graph, and integration with identity and ZTNA enforcement points. A long Q&A covers rollout process (a phased, simulate-then-enforce model), automated versus alert-only blocking, zero-day coverage through behavior rather than signatures, and how SaaS deployments handle customer data.
No cybersecurity Prevention architecture will ever be 100% effective, and the reality needs to be faced that 100% of us will eventually be breached. Most of the cyber industry is focused on preventing a breach and in protecting the health of a workload, but this is a never-ending game of catch-up, since threats are constantly changing, and most threats can spread faster than they can be detected. Preventing the spread of any and all threats needs to be the priority, in order to survive the inevitable breach. All threats share one common dependency: the segment. All threats, from the most complex to the most amateur, share this one common weak link in the security architecture. Segmentation means that if we control the segment we can contain the problem, and even those threats which have slipped past even the most sophisticated threat-prevention tool can be detected and enforced from network behavior which falls outside of expected baselines. Microsegmentation means that every workload is its own dedicated trust-boundary, without relying on segments in the underlying network, meaning breaches can be enforced with zero dependency on traditional security appliances. Illumio discovers all application behavior, then enables the enforcement of all segments in order to prevent the spread of any threats, without needing to first understand the deeper, complex intentions of a threat.
Key takeaways
- Stop trying to identify a threat before acting; by the time detection tools name it, malware has already spread, so shutting down the movement vector matters more than early attribution.
- Audit and close default-open lateral ports (RDP, SSH, unusually large DNS bursts) on every workload; nearly all malware, amateur or professional, moves through this same handful of ports.
- Segment at the workload instead of relying on VLANs or IP subnets; workload-level microsegmentation scales past the practical VLAN limit that containerized and cloud environments quickly exceed.
- Audit unmanaged OT and IoT devices (smart clocks, badge readers, building systems) as seriously as laptops and servers; several real breaches entered through exactly this kind of overlooked device.
- Roll out segmentation in phases, illuminate traffic first, simulate policy without enforcing it, then enforce, rather than blocking cold; this avoids operational disruption and pushback from application owners.
Speakers

Christer Swartz is Director of Industry Solutions for Illumio. He has spent many years in the Networking industry, beginning with a small startup called Cisco. He joined Cisco when their global head-count was 50 people, he was an early CCIE, and… Read moreRead less
Christer Swartz is Director of Industry Solutions for Illumio. He has spent many years in the Networking industry, beginning with a small startup called Cisco. He joined Cisco when their global head-count was 50 people, he was an early CCIE, and remained with them for 9 years. He has worked in the Caribbean, in Europe, and also for a small company called Netflix, when their business model was built around red envelopes and DVD's, then designed their Internet-streaming model to host movies, without breaking the Internet. He worked for many years for Palo Alto Networks, when the industry finally realized that cybersecurity was not just a good a idea but is a business enabler. Application visibility & security needs to be fully agnostic to the network or any security appliances, enabling a fully application-centric approach to seeing who is doing what to whom everywhere, and how to enforce it. 100% of us will eventually be breached, no one is too small of a target, so a breach needs to be assumed but the goal is containing it, preventing a small problem from becoming a disaster. Christer will explain how.

