Atelier d’Architecture (High Level Design) : Sécuriser l’Entreprise face au double risque de l’IA
Download resourcesAbout this session
Bruno Germain, a Zscaler solutions architect, builds a vendor-neutral, high-level security architecture around what he frames as AI's dual risk: an increasingly autonomous external attacker, and AI tools embedded internally that open new data-exfiltration paths. He cites the OpenAI-agent attack on Hugging Face, roughly 15,600 logged events from about 700 coordinated, autonomous agents over two days, and a MITRE ATT&CK Sankey-diagram exercise showing 932 billion possible paths through a 14-step kill chain, to argue the attack surface itself hasn't changed, only the attacker's speed and persistence in exhausting it. For the external perimeter, he proposes hiding every system behind a zero-trust proxy with per-application micro-segmentation, TLS decryption and deception signals placed at blind spots the same MITRE mapping reveals. For the internal perimeter, he treats each endpoint as a potential full AI environment, flags MCP connections as an uncontrolled egress point, and calls for end-to-end identity and data-flow visibility, DLP-style guardrails extended to prompts, and AI-aware brokers inserted between agents and the resources they call. Referencing a CSA/SANS readiness paper and new CISA deception guidance, he closes with a phased roadmap: guardrails and access governance first, brokers and deeper automation later, all built on one shared zero-trust control plane.
Aujourd'hui, l'architecture de sécurité d'entreprise fait face à un point de bascule technologique.
D'un côté, l'IA devient un adversaire autonome comme l'évasion de l'agent OpenAI ciblant Hugging Face l’a encore récemment démontré, et de l'autre, l'IA s'ancre en interne ouvrant des vecteurs d'exfiltration de données massifs via des flux légitimes.
Qu'il s'agisse d'une attaque externe ou d'une fuite interne, considérer le périmètre classique est obsolète. De plus, face à des agents IA capables de générer des exploits à la volée, à abuser de manière autonome de l’environnement corporatif ou de se plier à des demandes non-conformes d’usagers, les processus traditionnels de réponse aux incidents – basés sur la détection humaine, les alertes SIEM et la configuration de pare-feux – sont confrontés à une asymétrie temporelle fatale.
Le paysage de l'IA évolue trop vite pour prétendre détenir une solution 'définitive'. Cependant, des pistes se dessinent et doivent être déployées rapidement car l'attentisme n'est pas une option.
Rejoignez-nous pour une session conçue pour les CISOs et Architectes en sécurité: en nous appuyant sur les analyses d'incidents récents et les directives du CSA (Cloud Security Alliance) pour faire face aux modèles autonomes, nous construirons ensemble une architecture cible (High Level Design) permettant de reprendre le contrôle avec une feuille de route pour déployer le tout.
Au programme de cet atelier d'architecture :
Cartographie de l'écosystème et anatomie des vecteurs d'attaque de nouvelle génération (Évasion d'agent autonome vs. Fuite de données interne).
Démonstration (via les flux de Sankey) de l'échec structurel des défenses basées sur le réseau et la détection d'anomalies.
Conception du HLD Cible (Zero Trust) : Comment unifier la protection externe et interne.
Externe : Invalidation de la surface de reconnaissance par l'invisibilité applicative, l’élimination stricte du mouvement latéral et la classification continue des données (DSPM) et autres directives du CSA
Interne : cartographier et sécuriser l'usage des outils d'IA (publics, locaux et agents développeurs) tout en contrôlant l'accès et en évitant la fuite de données sensibles (DSPM/CASB, DLP, et AI Broker).
Roadmap de Transformation : Feuille de route pour les 12 à 18 prochains mois afin d'atteindre une solide posture de sécurité sans paralyser l'innovation
Venez challenger votre architecture actuelle et réfléchir aux fondations de votre résilience future.
—— English —
Title: Architecture Workshop (High-Level Design): Securing the Enterprise Against the Dual Risk of AI
Enterprise security architecture is currently at a technological tipping point.
On one hand, AI is becoming an autonomous adversary - as recently demonstrated by the OpenAI agent evasion targeting Hugging Face. On the other, AI is becoming embedded internally, opening up vectors for massive data exfiltration via legitimate flows.
Whether dealing with an external attack or an internal leak, relying on the traditional security perimeter is obsolete. Furthermore, faced with AI agents capable of generating exploits on the fly, autonomously exploiting the corporate environment, or complying with abusive user requests, traditional incident response processes—reliant on human detection, SIEM alerts, and firewall configurations - face a fatal time-based asymmetry.
The AI landscape is evolving too rapidly to claim there is a single 'definitive' solution. However, promising approaches are emerging and must be deployed quickly; inaction is not an option.
Join us for a session designed for CISOs and security architects. Drawing on analyses of recent incidents and Cloud Security Alliance (CSA) guidelines for addressing autonomous models, we will collaboratively build a target architecture (High-Level Design) to regain control, complete with a deployment roadmap.
Workshop agenda:
Ecosystem mapping and the anatomy of next-generation attack vectors (autonomous agent evasion vs. internal data leakage). Demonstration (using Sankey diagrams) of the structural failure of network-based defenses and anomaly detection.
Target High-Level Design (Zero Trust): How to unify external and internal protection.
External: Neutralizing the reconnaissance surface through application invisibility, strict elimination of lateral movement, continuous data classification (DSPM), and other CSA guidelines.
Internal: Mapping and securing AI tool usage (public, local, and developer agents) while controlling access and preventing sensitive data leakage (DSPM/CASB, DLP, and AI Broker).
Transformation Roadmap: A plan for the next 12–18 months to achieve a robust security posture without stifling innovation.
Come challenge your current architecture and consider the foundations of your future resilience.
Key takeaways
- Map your attack surface against a MITRE ATT&CK kill chain (a Sankey diagram works well) to find blind spots, then place deception/honeypot signals specifically at those gaps rather than deploying them generically.
- Hide internet-facing systems behind a zero-trust proxy so there is no public address to attack, since AI-driven attackers can now exhaustively probe every path in an unchanged attack surface far faster than before.
- Build a full inventory and end-to-end visibility of AI-related identities, agent-to-agent calls and MCP connections before writing access policy; without it, guardrails and brokers have almost no chance of working.
- Extend existing DLP/guardrail investments to cover AI prompts and responses, not just files and email, as the fastest way to reduce near-term exfiltration risk from internally deployed AI tools.
- Sequence the rollout: guardrails and access governance first (to stop immediate risk from tools already in use like Copilot), then brokers/gateways and deeper automation, all on one shared zero-trust control plane rather than siloed point tools.
Speakers

Bruno Germain est un architecte de solutions couvrant les grandes entreprises canadiennes, les gouvernements provinciaux et fédéral pour Zscaler. Dès 2008, il a travaillé sur le développement de normes pour les réseaux virtuels (MiM / SPB / routeurs… Read moreRead less
Bruno Germain est un architecte de solutions couvrant les grandes entreprises canadiennes, les gouvernements provinciaux et fédéral pour Zscaler. Dès 2008, il a travaillé sur le développement de normes pour les réseaux virtuels (MiM / SPB / routeurs virtuels) et a rejoint l'équipe de Nicira en 2012, introduisant le Software Defined Networking (SDN) aux entreprises nord américaines avant d’être acquise par VMware et devenir NSX. Depuis 2014, il met en œuvre des architectures de Zero Trust (ZTA) et a pu travailler et présenter conjointement avec John Kindervag sur le sujet. Il détient un grand nombre de certifications et a occupé des postes chez plusieurs manufacturiers, transporteurs et plus récemment chez Google pour développer et implanter des solutions novatrices ici et à l'étranger.

