Skip to content
TrackPodcasts
businessFeb 10, 2026

Why Banks Need AI-Driven Segmentation Against Ransomware

About this episode

Discover how AI-driven segmentation is reshaping customer strategy in financial services. Learn how adaptive microsegmentation helps banks contain threats faster and strengthen resilience against modern attacks.

Get every episode summarized

Each time Credit Union Information Security Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

108 searchable segments. Every word is indexed and playable.

Why Banks Need AI-Driven Segmentation Against Ransomware

Credit Union Information Security Podcast

0:00
0:00

Full transcript

Credit Union Information Security PodcastWhy Banks Need AI-Driven Segmentation Against Ransomware. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hi there, I'm Tom Field. I'm Senior Vice President of Editorial with Information Security Media Group. Please welcome to the conversation today where I'm talking about how AI-driven segmentation is redefining customer strategy and financial services. Joining me today is Michael VR, is the Director of Field Security Technology with Akamai. Michael, thanks so much for taking time to speak with me. Thank you for having me here, Tom. So give me some background here. What are some of the ransomware trends that you're seeing in financial services and how would you say they've evolved over the past year? Yeah, honestly, it's a completely different battlefield than it was even two years ago. We've moved past that era of manual ransomware and what we're seeing now is kind of the rise of AI-driven predator swarms and the speed is quite honestly, it's alarming. The volume of attacks, they've increased year over year and the entire kill chain from reconnaissance to initial access to data transportation as condensed from weeks to days to minutes.

And the real kicker is the barrier for entry as completely vanished. You don't need to be a nation-state hacker anymore. AI allows low-level expertise affiliates to use agents that perform complex tool calls and deploy malware that actually learns and adapts to your network defenses and it does it in real time. We've also recognized that there's an evolution in the tactics. Basically, banks have gotten much better at playing defense. They're stopping hackers mid-axx so often that only about half of the encryption attempts really work and since that lock your files trick isn't to pay the day that he used to be, attackers are getting creative and quite honestly, they're a bit more aggressive since they can't always lock your data, they just steal it instead and they'll threaten to leak private coin information or shut down the bank's apps with a lead-off attack until somebody pays up. So it's kind of less about kidnapping the data and more about blackmail and what's pretty well is that ransomware groups are now head hunting. They're

looking for actual employees to sell their logging credentials and it's easier to walk in through the front door with a real key than it is to pick the lock. Now this is why adversaries say or people say adversaries aren't breaking in their logging in, right? That's right. Where do you find that institutions are most challenged to detecting contained ransomware today in this environment? So the challenge is that financial institutions are often sitting on a legacy architecture with complex hyper clouds and a constantly shifting perimeter. Many times the enforcement of security is done asymmetrically or it's fragmented and only portions of the infrastructure are supported by subsets of the solutions. The sheer number of breaches that attackers are getting through the perimeter defenses, it demonstrates they can pretty much do that at will. And once they're inside, they find a relatively flat network where your assets are virtually unguarded and they've rushed and the rush to the cloud has also multiplied the attack surface as well. There's a lot of

complexity there. And without high communication controls, every single server essentially becomes its own attack surface. Attackers are also focusing on living off the land and they're leveraging legitimate protocols to blend in. They're moving laterally, they're staying invisible and they do that while they're exchanging your data to sell or ransom a bit later. Once an attacker penetrates the perimeter, detection and containment become a nightmare. It's less about breaking in now and more about a quiet high speed takeover. Michael, talk to me about AI driven segmentation. How is it different from traditional segmentation as we know it? And of course, why is it needed now more than ever? So you can think of traditional segmentation, kind of like building a stone wall. It's static, it's manual and once it's up, it's kind of a nightmare to change. If you misconfigure one rule, you risk impacting an entire network segment. Dynamic environments, they are pretty difficult to accommodate, especially if you're crossing multiple boundaries. AI-driven

segmentation is more like a high-tech living armor. And at the risk of over simplifying it, it's a matter of analyzing your network and infrastructure and how it communicates and taking the guesswork out of policy creation. Instead of engineers deciding if an application is ready, AI should answer that automatically and continuously. This makes your rules adaptable, it makes them dynamic and it improves your time to value and risk reduction, but also is improving your accuracy in reducing the operational burden. And we need it now because AI-driven offense requires an AI-enabled defense. The human and the loop security models becoming obsolete for detection and containment. When an AI agent is identifying zero days and is executing a lateral movement strategy at machine speed, the human analyst waiting for a similar to pop-up, it's already too late. They can't contain what they can't see and they certainly can't contain it fast enough when the attack structure is automated and effective. So we have to provide our cyber defense

the ability to act with the same autonomy as the attackers and the solutions they use need to adapt to make their jobs easier. Bear points, how does Akamai approach this concept of AI-driven segmentation? So Akamai particularly through Akamai Gardeports segmentation takes a visibility first approach. You can't secure what you don't understand. So we collect and analyze not just the network telemetry but process level detail and we don't filter out traffic just because it might be too noisy and we look at the data on an individual workload basis whether it's on-prem, cloud, or even legacy. AI-driven segmentation is basically about taking the grunt work out of zero trust. And if you've ever tried to do microsegmentation manually, you know it's a nightmare of spreadsheets, guessing which IP address belongs to which app. And Akamai solves this by using AI. So first you have AI labeling and that acts as your eyes of the system. It watches how your service behaves. Instead of relying on static spreadsheets or manual tags, the AI analyzes behavioral

DNA. It's examining processes, ports, traffic patterns, and says, hey, this looks exactly like an Oracle database and then it labels it for you. And as your environment changes, new systems are added or moved, it continues to monitor and make suggestions and updates to keep things current and prevent security regression. There's no stale labels with this and it even gives you a confidence score so you aren't just taking this word forward. It's something that's actually measurable. This simplifies the process of adding context and understanding what's in your network without the manual research and all the correlation. Following that is the Akamai Gardeports segmentation's a generative policy engine. This is what automates the process of micro-secondation. Most segmentation projects stall not because enforcement is difficult but because getting to enforcement safely is slow, it's manual and it's risky. So Gardecore's new application policies workflow powered by the generative policy engine changes that starting point. We automatically discover applications, we calculate the readiness continuously and generate policies from real traffic.

Instead of asking what rules should I write, we ask which applications are actually ready to segment and why. We don't generate the rules first, we generate confidence first. Michael, what are some of the key benefits organizations are going to receive from AI driven segmentation, thinking of reduced risk, increased efficiency? What do you expect to see? Yeah, I think we're going to see accelerated enforcement. So this is what's going to move organizations from network visibility to active protection and we're going to be able to do that significantly faster than manual methods. In addition to that, we have like operational simplicity and improving the efficiency. So smaller teams are going to be able to manage a massive hybrid cloud environment. They can parse through tons of complex data sets and derive human readable insights. They're powered to orchestrate the implementation of security controls with more ease and less friction. And we're seeing a massive reduction in the man hours required to maintain compliance and adhere to standards like PCI DSS or Dora. And finally, the precision and adaptability.

We've reduced the risk of human error and writing and maintaining thousands of granular firewall rules. You have the benefit of tight controls without the burden of manually keeping them up to date and making sure they're effective. One of the tools the skills enterprises need to really get off the ground and maximize this. I mean, you need a tool, something like Akamagara course segmentation to gather the telemetry, process it, and ultimately to do the enforcement. Skill wise, we need to move security teams from being firefighters to orchestrators. They need to understand how to govern AI agents rather than doing the manual work themselves. Don't build a better wall, but build a better internal containment system and governance that work without needing a human to click OK for every block packet. Well said, Michael, we've covered a lot in the short period of time. Where can our audience go to learn even more about AI driven segmentation? Check out akamai.com slash security. And we have some really interesting blog posts that show everything

that we're doing and it's a great way to stay up to date on all the progress. Michael, I was a pleasure. Thank you so much for your time, for your insight. Thank you. Again, the discussion has been about AI driven segmentation, how it's redefining customer strategy and financial services. You just heard from Michael VR is director of field security technology with akamai for information security media group. I'm Tom field. Thank you for giving us your time and attention today.

More episodes

More from Credit Union Information Security Podcast

View all episodes →