[DigitalToday reporter Chi-gyu Hwang] John Kindervag (존 킨더바그), who created the concept of zero trust, has published a new book arguing zero trust remains valid in the AI era.
Kindervag first introduced the zero trust concept in a 2010 Forrester Research report. Zero trust later became a core principle of cyber security. After 15 years, he received a request to write a book about zero trust in the AI era and has now published it under the title "Machine Speed Cyber Resilience: Zero Trust Models for the AI Era."
Kindervag assigned experts in different fields to write a chapter each on core principles. The experts concluded zero trust is effective against AI attacks, as it was 15 years ago. They said AI threats have become faster, more sophisticated and larger in scale, but their essence is the same.
"AI models seem to acquire new capabilities every 14 days," Kindervag said. "Packets created by AI still have to pass through the networks attackers have always had to traverse, and properly implemented zero trust can block it."
The key is "proper implementation." A policy engine serves as the brain of zero trust. Each organisation must design its policy engine to reflect its own security posture and revise it when that posture changes. If the policy engine does not accurately reflect the security posture, AI agents can find gaps. SecurityWeek reported that it is also important to prevent malicious agents or insiders from manipulating the policy engine. It added that failed implementation can lead to devastating damage at a speed humans cannot detect or stop.