About this session
Sylvain Levesque, senior solutions engineer at Illumio, argues that Frontier AI models such as Anthropic's 'Mitos' have collapsed the time-to-exploit for a published vulnerability from days toward hours, and that once an attacker is inside, the breakout time needed to move laterally (a CrowdStrike-tracked metric, shortest recorded under a minute) leaves defenders almost no window to react. He describes Mitos discovering thousands of previously unknown vulnerabilities, some 15 to 25 years old, converting a large share of a Firefox flaw set into working exploit code, and chaining several vulnerabilities autonomously with almost no human involvement. He cites the Nova Scotia Power breach, where a full data-center compromise knocked out billing, metering, monitoring and the call centre simultaneously, as a warning of what an uncontained breach looks like. His prescription is breach containment through visibility and micro-segmentation: map and tag every asset and communication flow, close unused open ports, lock down high-risk lateral-movement protocols such as RDP, and test new segmentation rules in a simulated 'draft' mode before enforcing them, illustrated throughout with Illumio's Segmentation and Insight products and a closing audience Q&A on process-level rules and onboarding application owners.
Frontier AI models have dramatically sped up access to information, including information that benefits cybersecurity threat actors. These models can both discover vulnerabilities and create code that threat actors can use to breach environments. Cyber warrior no longer need coding skills to launch attacks.
This requires a proactive approach to securing any environment, with Zero Trust now being an absolute requirement as a security architecture, and no longer just a good idea. Learn how Illumio enables a security model which will protect your data from the AI-enabled threats of today and tomorrow
Key takeaways
- Design for breach containment (micro-segmentation, controlled blast radius) rather than prevention alone, since AI-accelerated exploitation has collapsed the window to detect and stop lateral movement before it starts.
- Close unused listening ports and lock down high-risk lateral-movement protocols, especially RDP, plus SSH, SMB, RPC and Telnet, since these are the paths both human intrusions and ransomware actually use to spread.
- Build full communication-flow visibility, tagged by environment, application, role and location, before writing segmentation policy, and test new rules in a simulated 'draft' mode to see their impact before enforcing them.
- Treat the dev-to-prod boundary as a priority segmentation target, since less-monitored, less-patched development environments are a common entry path toward production assets.
- Track published-vulnerability-to-exploit time as a defender metric: AI tooling is pushing it from days toward hours or minutes, so patching and compensating controls need to assume a near-zero response window.
Speakers

Sylvain Levesque is a Senior Solutions Engineer at Illumio with nearly three decades of experience in networking, cybersecurity, and technical solutions engineering. Prior to joining Illumio, Sylvain spent more than 26 years at Cisco, including over… Read moreRead less
Sylvain Levesque is a Senior Solutions Engineer at Illumio with nearly three decades of experience in networking, cybersecurity, and technical solutions engineering. Prior to joining Illumio, Sylvain spent more than 26 years at Cisco, including over 17 years as a Cybersecurity Technical Solutions Architect, where he developed deep expertise in incident response, technical sales, and enterprise security. His technical credentials include CISSP, Kubernetes and Cloud Native Associate, Cilium Certified Associate, and multiple cloud and security certifications. Sylvain holds degrees in Computer Engineering from Université Laval and Electrical Engineering from UQTR. Today, he brings his extensive technical and customer-facing experience to Illumio, helping organizations understand and address complex cybersecurity challenges.

