S P E C I A L R E P O R T
“ This creates enforceable boundaries around their most critical assets.”
Continuous assurance replaces periodic reviews
Tom Burton also considers segmentation fundamental.
“ If you have to choose one place to start investing. Start with segmentation.”
He acknowledges that implementing effective segmentation is rarely simple.
“ It’ s hard, time-consuming and foundational.”
However, Burton argues that segmentation should sit alongside Zero Trust, continuous patching, contingency planning and improved situational awareness.
“ Segmentation without Zero Trust is little more than an expensive flat network.”
Attila Török similarly believes organisations should“ design networks for breach rather than assuming it can be prevented, so that any compromise is contained to something small.”
Rather than trying to build impenetrable defences, the objective is to contain attacks before they become business crises.
Segmentation without Zero Trust is little more than an expensive flat network.
As attacks accelerate, contributors consistently argued that annual audits and periodic assessments are no longer sufficient.
Dom Glavach, CISO at Black Duck, believes resilience is increasingly defined by speed.
“ The next generation of cyberresilience will be defined by speed: how fast an organisation can move from risk identified to acting decisively.”
That requires more than technology.
“ The first investment for CISOs is the resilience operating model.”
Risk ownership, governance, escalation procedures and executive decision-making must evolve alongside technical capabilities.
Only then should organisations expand visibility across identities, cloud environments, software supply chains and third-party ecosystems while introducing AI-driven automation.
WWW. INTELLIGENTCISO. COM 53