This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Using Zero Trust to Contain Ransomware & Improve Cyber-resilience in the age of AI

Download resources

About this session

Paul Schofield, a senior systems engineer at Illumio, argues that even highly effective endpoint detection (around 96%) still lets attackers in, and that the real damage comes from unchecked lateral movement across flat, unsegmented networks and slow, inflexible incident response. Drawing on his own experience responding to an infection at Hewlett-Packard, he describes wanting a single control to shut down manufacturing and not having one. He frames AI as raising the stakes on both sides (citing a World Economic Forum survey where most respondents believed AI benefits attackers more than defenders) and argues the answer is not more AI but a smaller attack surface, achieved through zero trust micro-segmentation: labeling assets, separating IT from OT, building application allow-lists instead of block-lists, and integrating with SIEM/SOAR tooling for automated quarantine and recovery from immutable backups. He walks through NIST's zero trust maturity model across five pillars and a live-style example isolating an infected, high-value machine while preserving specific protocols like DICOM for medical imaging. Audience questions cover dynamic versus static labeling and a live poll on whether AI favors attackers or defenders.

As we transform our business models to deliver more agile services the increasing threat of ransomware can potentially disrupt those services causing an impact on society. While we can continue to spend more money or traditional security approaches a shift in thinking to Zero Trust will be more effective and save money.

 In this workshop we will address the following topics:

  • How to identify and define risk
  • How to reduce the attack surface
  • How to contain a ransomware attack
  • How to respond and restore services during an attack
  • How to identify and define risk
  • How to reduce the attack surface
  • How to contain a ransomware attack
  • How to respond and restore services during an attack
  • Key takeaways

    • Do not treat EDR as sufficient on its own; even at roughly 96% effectiveness, the remaining gap is what causes months-long undetected breaches.
    • Flatten-network risk matters more than entry point; label and segment assets so a compromise at one endpoint cannot reach high-value systems.
    • Separate IT and OT traffic explicitly, for example blocking RDP between them, and build allow-lists (only permitted protocols like DICOM) instead of trying to enumerate every rule to block.
    • Prepare a single, fast control to isolate or shut down a business function (like manufacturing) during an active incident rather than discovering mid-attack that no such control exists.
    • Plan for reinfection during recovery, since slow recoveries are often caused by reinfection rather than the initial compromise; pair segmentation with immutable backups.

    Speakers

    Paul Schofield
    Paul Schofield
    Senior Systems Engineer · Illumio
    With 30 years of experience in the industry, Paul Schofield is an information security veteran. Currently leading Illumio's strategic partnerships, Paul brings a wide range of experience in the security industry, including partnership, governance… Read moreRead less

    With 30 years of experience in the industry, Paul Schofield is an information security veteran. Currently leading Illumio's strategic partnerships, Paul brings a wide range of experience in the security industry, including partnership, governance, risk management, mergers and acquisitions, due diligence, and investigations. Previously, he was a security services architect at Imperva, deploying security solutions to the Fortune 100. Prior to his consultancy days, Paul was a member of the global risk management team at HP/ Agilent Technologies, focusing on due diligence for mergers and divestiture. Paul is also a co-founder of the Boston Chapter of the High Technology Crime Investigation Association, HTCIA.

    Resources

    Tags

    More from GoSec 2024

    Also from Paul Schofield

    On the same topic

    This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.