The Segment

Illumio

Attackers are smarter, more sophisticated and move more quickly than ever. If your organization hasn’t been breached yet, odds are you will be. On The Segment, you will hear from industry experts about the latest cybersecurity trends. We will unpack how modern organizations can reduce risk and curtail impact with Zero Trust - a “never trust, always verify” approach to cybersecurity. Join us for The Segment: A Zero Trust Leadership Podcast, brought to you by Illumio.

  1. Sep 9

    The Human Attack Surface: What Cybersecurity Can Learn from the Secret Service | Hazel Cerra

    What can 25 years of protecting the President teach the cybersecurity world?  In this episode, Raghu Nandakumara sits down with Hazel Cerra, Director of Digital Security Convergence at BlackCloak and a 25-year veteran special agent of the U.S. Secret Service, to explore what protective intelligence can teach cybersecurity about defending the human attack surface. Hazel draws on her path from investigating counterfeit and credit card fraud, to protecting President Clinton, to pioneering critical systems protection for presidential visits, sharing how she came to see the Secret Service's layered "zero fail" security model as a direct parallel to Zero Trust, and why understanding an adversary's motive, means, and opportunity is as critical in cyber as it is in physical protection. Raghu and Hazel discuss: How the Secret Service evaluates and prioritizes threats using motive, means, and opportunityWhy "zero fail" protection is the same discipline as Zero Trust securityHow cyber convergence changed physical protection, from hackable elevators to compromised camerasWhy executives' home networks have become the new "path of least resistance" for attackersBalancing security with usability, without creating unnecessary frictionHow deepfakes and AI impersonation are changing verification and executive riskHazel closes with a practical tip for spotting a deepfake on a video call, and a reminder that as executives become as visible as presidents once were, protecting them has to extend far beyond the corporate perimeter. Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com

    The Human Attack Surface: What Cybersecurity Can Learn from the Secret Service | Hazel Cerra
  2. Aug 5

    Hackers Don't Break In. They Log In. | Keren Elazari

    Hackers don't break in — they log in. That's the refrain cybersecurity researcher, TED speaker, and self-described friendly hacker Keren Elazari keeps coming back to, and it sets the tone for a conversation that cuts through a lot of the current AI hype. Host Raghu Nandakumara sits down with Keren to talk about why, despite the constant headlines about AI-discovered zero-days and autonomous attack tools, the overwhelming majority of real-world breaches still come down to the same fundamentals: stolen credentials, unpatched known vulnerabilities, and social engineering. Keren points to Verizon's DBIR data showing that over 80% of web-facing attacks are credential-based, and to the CISA KEV catalog, where under 30% of known exploited vulnerabilities are even patched — numbers that make the "AI supercharges vulnerability discovery" conversation feel a little beside the point. The two dig into what Keren calls the widening asymmetry between attackers and defenders: AI is getting good at finding vulnerabilities and writing exploits, but not nearly as good at patching them or getting fixes into messy, real-world production environments. She describes AI as "a time machine for attackers" — compressing weeks of reconnaissance and tooling into hours — and argues defenders need that same acceleration applied to mitigation and containment, not just detection. The conversation also covers: Shiny Hunters' evolving social engineering playbook — from impersonating employees to get help desks to reset access, to now impersonating the help desk itself to harvest credentials via fake SSO resets, SIM swapping, and deepfake voice tools The GTG-1002 incident referenced in Anthropic's late-2025 report, where a nation-state actor used an AI model as an active accomplice in an orchestrated attack, and why Keren thinks the sophistication was in AI-driven orchestration, not novel exploit creation Shadow AI as a new attack surface, using the rapid, often misconfigured spread of local "Open Claw" installations (many left listening on all ports) as a cautionary example Jade Puffer, an early example of agentic, largely human-out-of-the-loop ransomware, and why Keren wasn't surprised given how much ransomware groups already reinvest in R&D A malicious-package incident on Hugging Face, and the broader pattern of attackers targeting trusted open-source "watering holes" like GitHub and model/skill hubs Keren closes out by introducing her reframed security fundamentals — Identity, Visibility, and Containment (IVC) in place of the classic CIA triad — and makes the case for "proactive paranoia": preparing for breaches before they happen rather than scrambling once they do. She and Raghu wrap with a shared hard truth: for all the AI conversation, security is ultimately about serving the humans on both sides of the equation, including the fact that attackers are humans too, and often know an organization's environment better than its own defenders do. Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com

    Hackers Don't Break In. They Log In. | Keren Elazari

Ratings & Reviews

5
out of 5
17 Ratings

About

Attackers are smarter, more sophisticated and move more quickly than ever. If your organization hasn’t been breached yet, odds are you will be. On The Segment, you will hear from industry experts about the latest cybersecurity trends. We will unpack how modern organizations can reduce risk and curtail impact with Zero Trust - a “never trust, always verify” approach to cybersecurity. Join us for The Segment: A Zero Trust Leadership Podcast, brought to you by Illumio.

You Might Also Like