Discussion about this post

User's avatar
Philip Griffiths's avatar

Great piece. I especially agree with the distinction between hard boundaries and soft guardrails. My only addition: for agents, hard boundaries need to start before the API/tool/action layer. Many controls govern what an agent does after reachability already exists. The missing foundation is identity-bound reachability: can this agent, model, tool, or service create a private path to this resource, for this session, under this policy, at all? That is where Zero Trust has to evolve from access control to connectivity control. This surmises a talk I gave recently at the CSA/DoW Zero Trust Symposium.

Jack Fitzpatrick's avatar

Interesting article.

Zero Trust was built to solve an access problem: who gets in, what they can access, and under what conditions.

Ransomware and data theft expose a different problem.

Once access is granted, who determines whether a destructive action should execute?

An attacker with valid credentials, MFA, and authorized access can still encrypt data or exfiltrate sensitive information.

Identity control answers who. Execution control answers whether.

The next evolution of cybersecurity isn’t more verification. It’s authorization at the moment of execution.

Detection explains what happened.

Execution control determines whether it can happen at all.

Jack Fitzpatrick

Vice President - Data Protection

DataFenz

DataFenz

jack@DataFenz.com

770-289-6945

3 more comments...

No posts

Ready for more?