Loading...
Loading...

Hi there, I'm Tom Field. I'm Senior Vice President of Editorial with Information Security Media Group.
Please welcome to the conversation today where I'm talking about how AI-driven segmentation is
redefining customer strategy and financial services. Joining me today is Michael VR,
is the Director of Field Security Technology with Akamai. Michael, thanks so much for taking
time to speak with me. Thank you for having me here, Tom. So give me some background here. What are
some of the ransomware trends that you're seeing in financial services and how would you say they've
evolved over the past year? Yeah, honestly, it's a completely different battlefield than it was
even two years ago. We've moved past that era of manual ransomware and what we're seeing now is
kind of the rise of AI-driven predator swarms and the speed is quite honestly, it's alarming.
The volume of attacks, they've increased year over year and the entire kill chain from
reconnaissance to initial access to data transportation as condensed from weeks to days to minutes.
And the real kicker is the barrier for entry as completely vanished. You don't need to be
a nation-state hacker anymore. AI allows low-level expertise affiliates to use agents that perform
complex tool calls and deploy malware that actually learns and adapts to your network defenses
and it does it in real time. We've also recognized that there's an evolution in the tactics.
Basically, banks have gotten much better at playing defense. They're stopping hackers mid-axx so
often that only about half of the encryption attempts really work and since that lock your files
trick isn't to pay the day that he used to be, attackers are getting creative and quite honestly,
they're a bit more aggressive since they can't always lock your data, they just steal it instead
and they'll threaten to leak private coin information or shut down the bank's apps with a
lead-off attack until somebody pays up. So it's kind of less about kidnapping the data and more
about blackmail and what's pretty well is that ransomware groups are now head hunting. They're
looking for actual employees to sell their logging credentials and it's easier to walk in through
the front door with a real key than it is to pick the lock. Now this is why adversaries say or
people say adversaries aren't breaking in their logging in, right? That's right.
Where do you find that institutions are most challenged to detecting contained ransomware today
in this environment? So the challenge is that financial institutions are often sitting on a
legacy architecture with complex hyper clouds and a constantly shifting perimeter.
Many times the enforcement of security is done asymmetrically or it's fragmented
and only portions of the infrastructure are supported by subsets of the solutions.
The sheer number of breaches that attackers are getting through the perimeter defenses,
it demonstrates they can pretty much do that at will. And once they're inside,
they find a relatively flat network where your assets are virtually unguarded and they've rushed
and the rush to the cloud has also multiplied the attack surface as well. There's a lot of
complexity there. And without high communication controls, every single server essentially becomes
its own attack surface. Attackers are also focusing on living off the land and they're leveraging
legitimate protocols to blend in. They're moving laterally, they're staying invisible and they do
that while they're exchanging your data to sell or ransom a bit later. Once an attacker penetrates
the perimeter, detection and containment become a nightmare. It's less about breaking in now and more
about a quiet high speed takeover. Michael, talk to me about AI driven segmentation.
How is it different from traditional segmentation as we know it? And of course, why is it needed now
more than ever? So you can think of traditional segmentation, kind of like building a stone wall.
It's static, it's manual and once it's up, it's kind of a nightmare to change. If you misconfigure one
rule, you risk impacting an entire network segment. Dynamic environments, they are pretty
difficult to accommodate, especially if you're crossing multiple boundaries. AI-driven
segmentation is more like a high-tech living armor. And at the risk of over simplifying it,
it's a matter of analyzing your network and infrastructure and how it communicates
and taking the guesswork out of policy creation. Instead of engineers deciding if an application is
ready, AI should answer that automatically and continuously. This makes your rules adaptable,
it makes them dynamic and it improves your time to value and risk reduction,
but also is improving your accuracy in reducing the operational burden.
And we need it now because AI-driven offense requires an AI-enabled defense.
The human and the loop security models becoming obsolete for detection and containment.
When an AI agent is identifying zero days and is executing a lateral movement strategy
at machine speed, the human analyst waiting for a similar to pop-up, it's already too late.
They can't contain what they can't see and they certainly can't contain it fast enough when
the attack structure is automated and effective. So we have to provide our cyber defense
the ability to act with the same autonomy as the attackers and the solutions they use need to
adapt to make their jobs easier. Bear points, how does Akamai approach this concept of AI-driven
segmentation? So Akamai particularly through Akamai Gardeports segmentation takes a visibility
first approach. You can't secure what you don't understand. So we collect and analyze not just
the network telemetry but process level detail and we don't filter out traffic just because it might
be too noisy and we look at the data on an individual workload basis whether it's on-prem, cloud,
or even legacy. AI-driven segmentation is basically about taking the grunt work out of zero
trust. And if you've ever tried to do microsegmentation manually, you know it's a nightmare of
spreadsheets, guessing which IP address belongs to which app. And Akamai solves this by using AI.
So first you have AI labeling and that acts as your eyes of the system. It watches how your
service behaves. Instead of relying on static spreadsheets or manual tags, the AI analyzes behavioral
DNA. It's examining processes, ports, traffic patterns, and says, hey, this looks exactly like
an Oracle database and then it labels it for you. And as your environment changes, new systems
are added or moved, it continues to monitor and make suggestions and updates to keep things current
and prevent security regression. There's no stale labels with this and it even gives you a
confidence score so you aren't just taking this word forward. It's something that's actually
measurable. This simplifies the process of adding context and understanding what's in your network
without the manual research and all the correlation. Following that is the Akamai Gardeports
segmentation's a generative policy engine. This is what automates the process of micro-secondation.
Most segmentation projects stall not because enforcement is difficult but because getting to
enforcement safely is slow, it's manual and it's risky. So Gardecore's new application policies
workflow powered by the generative policy engine changes that starting point. We automatically
discover applications, we calculate the readiness continuously and generate policies from real traffic.
Instead of asking what rules should I write, we ask which applications are actually ready to segment
and why. We don't generate the rules first, we generate confidence first.
Michael, what are some of the key benefits organizations are going to receive from AI driven
segmentation, thinking of reduced risk, increased efficiency? What do you expect to see?
Yeah, I think we're going to see accelerated enforcement. So this is what's going to move organizations
from network visibility to active protection and we're going to be able to do that significantly
faster than manual methods. In addition to that, we have like operational simplicity and improving
the efficiency. So smaller teams are going to be able to manage a massive hybrid cloud environment.
They can parse through tons of complex data sets and derive human readable insights. They're
powered to orchestrate the implementation of security controls with more ease and less friction.
And we're seeing a massive reduction in the man hours required to maintain compliance and
adhere to standards like PCI DSS or Dora. And finally, the precision and adaptability.
We've reduced the risk of human error and writing and maintaining thousands of granular firewall
rules. You have the benefit of tight controls without the burden of manually keeping them up to date
and making sure they're effective. One of the tools the skills enterprises need to really get off
the ground and maximize this. I mean, you need a tool, something like
Akamagara course segmentation to gather the telemetry, process it, and ultimately to do the enforcement.
Skill wise, we need to move security teams from being firefighters to orchestrators. They need to
understand how to govern AI agents rather than doing the manual work themselves. Don't build a
better wall, but build a better internal containment system and governance that work without needing a
human to click OK for every block packet. Well said, Michael, we've covered a lot in the short period
of time. Where can our audience go to learn even more about AI driven segmentation? Check out
akamai.com slash security. And we have some really interesting blog posts that show everything
that we're doing and it's a great way to stay up to date on all the progress. Michael, I was
a pleasure. Thank you so much for your time, for your insight. Thank you. Again, the discussion has
been about AI driven segmentation, how it's redefining customer strategy and financial services.
You just heard from Michael VR is director of field security technology with akamai for information
security media group. I'm Tom field. Thank you for giving us your time and attention today.
