What does breach readiness look like when attackers can operate at AI speed?
In this episode of Breach Ready Dialogues, Agnidipta Sarkar speaks with Tim Brown, former SolarWinds CISO and Dell Fellow, about building cyber resilience for a very different threat environment.
They discuss microsegmentation, security architecture, lateral movement, identity security, agentic testing, critical asset protection, and why reachability may be one of the most important security metrics to watch.
Tim also shares practical priorities for security teams: know your internet-facing assets, test your defenses like an attacker, understand your most critical systems, and strengthen monitoring before an incident occurs.
Explore the full episode and more conversations on cyber resilience at the ColorTokens Media Hub: https://colortokens.com/breach-ready-dialogues/
Agnidipta Sarkar: Hi. Good morning, good afternoon, or good evening, wherever you are listening in. Today is another episode of the Breach LD Dialogues. In fact, it’s the 16th episode, hopefully. And as usual, we will be talking about breaches. We will be talking about how practitioners can prepare better. And I have the most exciting, invited person that I have on my– that I ever had so far, which is Tim.
But I’ll let Tim introduce himself. So Tim, over to you.
Tim Brown: All right. So Tim Brown here. I was the CISO for SolarWinds for eight years. So through our incident that happened in 2020 all the way through our saga with the SEC and finally ended in ’25. Before that, I was a CTO for a number of different corporations.
I was an engineering leader an inventor with 18 patents large and small companies. So long career in a lot of different areas
Agnidipta Sarkar: Oh, thank you. And before this, obviously we met, Tim and I discussed, and what we’re going to focus on is are breaches. And as we see around us, there are a lot of breaches happening.
A lot of them are human-made, a lot of them are machine-made. And I think one thing after another is just tumbling out of the closets. There are AIs that ran rogue. I think rogue is the wrong word. They did do what they’re supposed to do. It’s only that they did not decide to accept any organizational boundaries or something to stop them.
But what Tim discussed the other day, and I want to take it back to him, Tim, why don’t you tell us about your analogy of the avocado and the pomegranate?
Tim Brown: Okay, yeah. So it– really when we think of the ne- network, people, you often hear talk about the network and the network. And in the past, we used to have really a castle and a moat.
That was the way we considered the the, the network. So we equate that to the c- the avocado, right? Big seed in the middle, gel coating around the outside to protect that, that big seed in the center. And that’s the way we used to be. But in reality, our enterprises are more of an avocado. So when you think about an avocado, they– it has a collection of little tiny seeds with little gel coatings.
Our enterprises are actually a collection of those seeds, and that is what our enterprise is. And so your Salesforce is a seed, your O365 is a seed, your internal network’s another seed. Your– So each of those seeds make up what your new enterprise really is. When we think about protecting that enterprise, we have to think about it as those collection of seeds, not of, as a, as the avocado, just one big seed.
It really changes the way we think, changes the way that we connect, changes the way that each one of those seeds communicate, changes the way that we look at threats to that enterprise, different in, you know, the way we can visualize it and truly think about it
Agnidipta Sarkar: Yeah, that’s more of a pomegranate.
Tim Brown: Absolutely.
Agnidipta Sarkar: And I love that. In fact a- any recent breaches that caught your attention that you think-
Tim Brown: Yeah. Yeah so many of… we see breaches of different kinds happening, and, one of the things I think we have to, when we look at breaches, we have to think about what is getting reported and whether it’s truly a breach of any consequence or not.
Press s- team seems to say, “Oh, a database with all of my email address and my, my home address was compromised.” And is that really anything that matters? Public information can be looked up anywhere. So often things don’t necessarily matter, and then they get put into the press as, “Oh, a million records were exposed.”
So we have to be able to filter through those and determine, what is significant, what is a significant sign of something. So they don’t all… They’re not all created equal, right? One of the, absolutely concerns, right? The, the case with, Hugging Face there very interesting, right?
To see that the AI did what it was supposed to do. It found a way out and it was able to find a way to compromise. So when we look at something like that, that’s really a wave for us and a wake-up call for us for the future how do we rethink about what our protections are in this, this day and age?
How do we rethink about the adversary in a different way, that the adversary, will go into, extremes to be able to get inside of environments? And that says that we have to make sure that our protections from the outside are different than what they were, that our good hygiene that we had before is different than what it what it has been for the last five or ten years.
Yeah, so we have to take different approaches than what we’ve taken in the past. And not so much different, but additional approaches, I would say. So we really do need to rethink how we protect, what we test for, how often we test for those things. It’s not the end of the world, it’s simply that we need to have…
make sure that we’re aware of what’s there, make sure we’re aware of before, the adversary’s test against it. So all of those things come into play. So more agentic pen testing more modeling, more microsegmentation, more hardening of that perimeter shell around the little seeds more checking of our configurations to make sure they’re good, more patching of systems extreme awareness on anything that’s internet-facing.
So all of those types of things make up the good hygiene of today, which will help us be more prepared for kind of the agentic age that’s, at our doorstep.
Agnidipta Sarkar: In fact if I go back, one of the things that I know about you is that you are one of the six Dell fellows around. And could you tell us a little bit about that?
Because- … I don’t think many people know that honor and what comes with it, and the pain that went behind it.
Tim Brown: Yeah. So I was honored to become a Dell fellow. So Dell fellow is our yeah, highest technical achievement essentially within, within Dell. IBM has had fellows Dell has had fellow, Microsoft has fellows, others have had fellows.
And yeah, I joined the Dell Software Group new organization within, inside Dell. We built it up from scratch, went from zero to four billion in four years. So really, yeah, put a footprint on the ground. The I became a fellow after about three years within Dell. I’d been a distinguished engineers multiple times at different companies.
Ran architecture and strategy for Symantec and other places. So did a lot of different things through the career. And in order to be a fellow, you need to be interviewed by your peers and you’re interviewed by the other fellows then finally by Michael. And yeah, as a fellow, you’re responsible for none of the technical direction and processes for your unit.
So our unit, just like a server unit, a PC unit, ours was a software unit within Dell. So we got to work on a lot of, really interesting projects to be able to say, what do we see for the future? Where do we see our- ourselves going? How do we drive our architects and engineers to that future?
Agnidipta Sarkar: I think the last part is the one that I have to take away, and I believe that in the modern world where we are, everybody’s talking about security governance, AI governance, et cetera, et cetera, I think one of the most important thing that we are not keeping up with is architecture. I think architecture is the foundation on the basis of which governance has to sit.
And considering the modern threats, you talked about hugging face if Hugging Face was, I don’t know, or any other organization was structured in a manner s- or architected in a manner that attacks remain confined to specific areas and don’t just roam about all over the impact of such an attack would be very different.
I see all the time, and I think you do too, about companies coming up and making a statement that we’ve had an unprecedented cyber attack, and we are shutting down all our operations in order to protect stakeholder interests. And my point of every of those events are that why– could we have avoided that?
Could we have des- defined an architecture where we know where the attackers will walk and what we can, afford? I remember you and I talking earlier and you talked about being the crumple zone, right? You talked about zoning and conduiting and how I preach that. And you said you t- you talked about a crumple zone.
Y- H- how relevant do you think architecture is-
Tim Brown: Oh, architecture extremely important. And really truly thought and thinking about, okay, if I’m an adversary, what am I going to go after? If I’m an adversary, what would I look for? What’s the most important thing to my business? What am I willing to give up?
Crumple zones essentially are w- what you’re willing to give up. Crumple zones from the automotive industry, right? Cars crumple all around you to save the humans, because the humans are the most important thing. So what’s the most important thing with your environment? And then, you really do need to do thought exercises around the outside to determine, okay, here’s where things are going to try to come in.
Here’s what they’re going to try to do. Here’s how they’re going to circumvent my security. What am I willing to give up and what am I not? And then you really do need to test at the level of, what AI is testing today to be able to determine how strong your defenses are and w- what the barriers are going through different things.
And it’s important to think about, how great those barriers are, and I’ll give you example for SolarWinds. What we did is redefine a new build system, and I didn’t just use technical controls to be able to protect the build system. I used human controls, right? Basically, we did multiple builds and had three different builds did that at the same time, digitally compared the results at the end.
But the key is that no one person had access to all three builds. So they would have to collude, physically collude in order to affect the builds. And that’s another barrier, right? Oh, you want collusion between people, not just one rogue user, but at least two rogue us- users, if not three rogue users, to be able to affect the build system because of hardened, vast collusion necessary models.
That was an extreme case of protection on the outside edge, but how can we do those extreme cases to other areas within different environments? How do you make sure that your environment can stand up to an insider threat or to other things? I love the analogy of the safe and the convenience store, right?
The the store, clerk only has access to what’s in the register, and it’s only twenty dollars. They don’t know how to open the safe. They can’t get at it. So they’re safe from attack in many ways because of that kind of simple physical model. How do we use those types of models to protect environments?
So first thing we need to do is understand what our environments look like. We need to understand what those things that are most at risk. We have to understand what’s most important to us. Then we have to examine the routes to those things, and then we have to make sure the routes to those environments are as difficult as possible to get at.
And, truly understand that environment and you create resilience. That’s what we really need to get to
Agnidipta Sarkar: In fact there is then there’s the question of identity as well. We also need to know which identities have access to which systems, and what is a dead giveaway that the identity is no longer being used by the person who was supposed to use it.
Normally valid user should be coming into the organization, no matter where he comes in from, goes to an SAP system, fills up a form, executes a few other tasks, and gets out. Now, if we find someone who’s into the SAP system and is trying to find a way to ping the SAP system or trying to do something which a normal human wouldn’t be expected to do, that’s a dead giveaway of a potential malicious user in the ranks.
Tim Brown: Yeah. And- There’s a lot of hiding in the noise though, right? Yeah I do think user analysis, and not really just not human user analysis, but human, agentic, non-human identity, all of those analyses of what they’re doing and whether they’re doing something that is appropriate, doing something that is normal.
Still the case is if you can take over the account that it is, you need to act in a way that it normally acts. So you’re just you’re just using it as a… You’re just being an imposter to that. So using credential and rights and activity, harder, right? It’s harder to discover what those things are and harder to be able to implement that type of attack, but it’s still possible.
But absolutely a starting point is, are the users and identities doing what they want, th- what they should be? Are the systems doing what they should be? Is there some trigger that went out of scope of the activity that it was supposed to do that should be triggering a yellow alert for you? And very few companies have that level of inspection going on.
And, it’s one of the things I’ve thought about a long time of, how do you get to that level of inspection? How do you anticipate somebody being coerced into doing something? How do you make sure you’re taking it seriously for those who have, stronger account and privileges than other people?
How do you make sure that they have that protection like the grocery store clerk does or convenience store clerk does? And, yeah it, it- We’re quickly entering a time where it’s going to be easier to be able to, coerce somebody and have an insider threat being coerced than it is to enter malware into an environment.
That’s when we get really scary, right? Because, bottom line, if you threat some- threaten somebody’s family, they will do whatever you need to have done. So very important that you understand that and give them protections, right? Like what we protected the clerk with, that they can’t do the things somebody asks for So it’s overhead, it’s things that we need to think about.
And it’s really things that we need to design and say, “Okay, if I want a truly resilient environment and I want to be truly resilient in this area, I’m gonna segment it off. I’m gonna make sure it’s segmented in, that it can’t get access from a, rogue user. The lateral movement won’t come into that area, that those who have privilege to get into those areas are appropriately vetted for every control that’s go- every control that’s going on, every access that they’re doing.”
And keep layering on those protections that say, “Okay, if I’m gonna come after this, it’s gonna be even more difficult than I could, imagine to get there.” So hence the thought, the design, the architecture, the, the knowledge to be able to define those sy- those systems. And, this doesn’t happen in a three-week sprint, right?
That’s the other part of it. It doesn’t. That we have to be able to break out of the sprint model for- Yes … true architecture resilience.
Agnidipta Sarkar: In fact that’s what I was going back to, the whole question of the architecture. Like we discussed before and earlier, that I have a zoning model that I profess, and I want to divide…
Again, this is a suggestion. Anybody can divide the organization in many different ways. But I think a good way to do that is to keep the most core of those systems that you really can’t shut down. It could be OT systems, it could be mainframes, it could be X-ray machines it could be IOTs or medical devices.
But those things which if you shut down, your cost of bringing it up is very high, or maybe the support that you need for restarting that machine doesn’t exist. That’s your core, and then you have another core, and I believe there should be two cores. The other core are those machines which you can shut down, but you don’t want to shut down because your business depends on it.
You probably shut them down once a year, or you have failover testing done, you have high availability mode, you… all those things, but that’s your core. And then because you talked about access and privilege access, I would carve out three more zones. The first one would be suppliers.
Tim Brown: Yeah.
Agnidipta Sarkar: Each supplier different from other, but that’s one zone for me.
Then one zone for privilege access, and I would put my SOC in that zone with people who have access to take decisions on the security events as they happen. And then the other part of that would be a temporary access given to privileged user on demand because they need to solve a very real technical problem.
And then I would have a DMZ where I have all those systems that are in between, and I am not talking about the traditional way we think DMZs are, because as I explained the other day, my zoning depends on material impact. So I would create those in between systems in the Z- in the DMZ where you need to rest before you get onto the actual system.
That’s where I’m going to have a direct access to my SOC so that should I need to disconnect someone, I should have a conduit that I can disconnect. And everything else, I would put them in what you define as the crumple zone And in that way, I probably am. This is just one model. There could be many other models.
Organizations could define multiple ways in which they could, create those values that you talked about.
Tim Brown: I think there’s good guidelines around the outside, and then how do you tweak those guidelines, right? Yeah I’m a big fan of super id- dynamic identity as well, so having really truly dynamic access.
I was at a meeting with Cisco a little while ago. I was really surprised. They’re looking at, truly dynamic network access, and, their protocols exist to be able to do that now. So as opposed to just source destination, they can take attributes in to determine what, connections exist or don’t exist.
So doing it at that layer is actually very interesting.
Agnidipta Sarkar: Granular.
Tim Brown: Yeah. Exactly. The So those types of things for dynamic nature. The other part is that, we have to start considering what we do f- with AI from a defender perspective. Why haven’t we had microsegmented systems and environments?
Because it was hard for the humans to understand those. AI, not so hard for it to understand any longer. So can we apply AI for us to embrace some complexities within our environment and then make them manageable?
Agnidipta Sarkar: Yes. E- especially… Sorry, I interrupted. Especially context. Yeah. Because one of the hardest things for humans to understand is context of where- Yep
you are going to put the control. Humans understand control, but we don’t understand context to the very level of detail that is essential for today’s environments. All that you do is you tell the AI, “Go and get this done.” And the AI figures out that, “I can break out of this, and I can get that thing done.”
Because at the end of the day, that’s the objective, that’s the goal. Unless we are able to use AI on the defender side on a, let’s say, a microsegmentation platform to determine what context needs what kind of rules, and this is not about threat intel alone. Threat intel is one part of it. It’s, there’s also behavioral int- intel- Yep
which means let’s say picking up data from EDR as to how the organization is structured. Absolutely. Picking up data from, yeah, some old data where you can pick- figure out how traffic was formed, how it was shaped what were false positives earlier, what were true positives, and stuff like that. That becomes part of your analysis.
Tim Brown: Yeah. And we’ve had go back to some of the dynamic identity stuff. We’ve had the OAuth protocol. It’s been around for a long time. I helped with that years and years ago, 10, fif- wow, almost 20 years ago. And it’s defined with attribute providers to help us be able to take input from many different sources to be able to determine should you have access to something again dynamically.
So it’s built into the protocol, it just hasn’t been used enough.
Agnidipta Sarkar: Yes.
Tim Brown: So when we start looking at the ideal environments, we start saying, how do we really structure the ideal environment, not so much with management ease in mind, but in, practical how do we protect environments in a better way?
Again a single identity provider, which I’m, one of the ones promoted to have that and do that way back again 20 years ago. We were just too successful. We enabled lateral movement between environments because of a single identity provider. How do we eliminate lateral movement?
Maybe we stand up a separate identity provider for our critical systems as opposed to using a shared one. We do physical separation, we do other things. Yeah, this one is not, fully baked, right? It just has… The ideas that we had of staying away from complexity, I think need to be lessened and say maybe I absorb complexity.
I expect the fact that I can’t understand this myself, but I can ask an AI what my models are, and I can ask an AI should something have access to something else, and can I do next generation technology that’s really going to make me much more resilient and make me see more? Yeah, make me see signs of attack better than what my, non-AI SOC is doing.
Let me test more and test like an adversary and see what I’m picking up.” R-really, I think that’s what we’re going to need to do.
Agnidipta Sarkar: Yeah, I think I fully agree with you. Indicators of attack have got more value from an AI perspective of building in defense- Yeah … than than indicators of compromise, because compromise is post-factor.
One of the things that I tell people is to do not threat modeling, but defense modeling. See, if you are able to have your AI tell you, “This is what is happening.” CSA has done a good job of publishing attacker and their techniques on their website. All that you need is to understand the MITRE framework and build that into your defense model in saying that, “Okay, here we go.
If Ransomhub were the attacker, and this is my exposed web server, then these are the ways Ransomhub attackers would ha- would go in, and therefore, I need to build defenses here. I don’t need to activate them. I need to build my defenses, create templates in microsegmentation that can get disconnected on demand.”
And tomorrow you can even… Sorry. Yeah. Tomorrow you can even train them to look at AI at- attacks or- Exactly … or AI movement.
Tim Brown: So that’s gonna be the key, right? The models of the, the past are still valid, they just have changed a great deal. So you can’t just take what exists and say, “I’m gonna defend against it,” because there’s so much more, so many different training- Yes
so many different m- models that we didn’t think about. Just wait till, the, the AI start social socially attacking an environment to get appropriate rights to be able to then compromise environment. So we have to remember those things that are possible-
Agnidipta Sarkar: Yes …
Tim Brown: in our defense, which the, today, you know, MITRE and others don’t go into that saying, “Oh they have to get access to a privileged account.”
Oh, they’re just gonna ask for it, and they’re gonna social engineer their way in to be able to get access to the account, to be able to do the right or do their attack. So we have to take into account a number of different factors when we’re kinda thinking about what defense looks like what early warnings look like, and what, what we need to have in place.
We still have to do business, right? And we still have enough kind of control around what we allow for, public interfaces, so it’s not an insurmountable problem. So I’m not a I’m not one of the people saying that the world’s gonna end, right? I think that we just need to be able to take it in the right way, and be able to define the systems before we have some really bad things occur, right?
We need to bump up our defenses. Yes … and just realize that anything that’s, internet fa- facing, if you haven’t tested that, significantly with equivalent models or at least close to equivalent models, you’re gonna go out there and get popped. So we need to be able to be prepared for that.
So not a naysayer, it’s just a, a caution that we need to get to, pretty quickly from a defender perspective because, the world’s not gonna be the same in six months as it is today.
Agnidipta Sarkar: It was not same six months ago. No. That brings me to TeamS8. W- so what are you doing there?
What’s the new agenda?
Tim Brown: Yeah. So yeah, new agenda is really trying to have people bump up their good hygiene. So bump up your good hygiene means, yeah, m- means agentic testing of everything, means being able to understand where your weaknesses are. At a minimum, you’re needing to be able to apply patches a lot quicker than what was there before.
The other part is knowledge within your environment. That’s not something that… you can use AI to help, but we need people thinking about, “Hey, how am I gonna get after this? What would I be doing from the outside? What would it look like from the outside?” Lots of good companies out there thinking about this and really trying to move towards it.
The other part is it’s really, some of the AI models are thinking about it as well. How do I get here? What will I do? What’s the best way through? The Hugging Face attack on Hugging Face, right? It wasn’t it wasn’t novel-novel in that, could a good human have done that same attack?
Sure, right? It wasn’t inventing new attack things, but it was doing stuff that was unique. But nothing that was, nothing that a, a smart, a, a smart set of individuals may have gone after that same target if you put them together in the right way. It did it automated, it did it by itself.
It did it so that you can put that model in the hands of lesser people, and that’s what it’s going to… That’s our new world and what it’s looking at. So how do we defend against that new environment? Just patching everything important, but it won’t be good enough, right? Yeah.
Agnidipta Sarkar: And you won’t have the time, the right time- No
to finish doing it. Time is definitely
Tim Brown: not on your side.
Agnidipta Sarkar: Yes. In fact, since we’re talking about Hugging Face, one of the incidents that I thought was important, though I haven’t heard about it lately, is the exercise that University of Toronto did, and they came up with a AI worm. I am petrified if a worm which has the capability of, Claude Miktos-
Tim Brown: Yeah
Agnidipta Sarkar: And other agentic capabilities be… they likely collapse the economics of cyberattacks, and that’s scary. Which means I need to work doubly hard, probably faster, to develop these defenses and, like you said correctly, and try to do this I would say as of yesterday
Tim Brown: So again, a lot of things still exists that existed before.
Yes. If you’re not reachable, right? If the vulnerability is not reachable, is it really a vulnerability? Now, that says a lot of reachability. Starts with outside, but once I get inside, who can then reach it, right? So reachability is not just a simple shut down all my access from the internet and I’m good, because, I might be able to find a way in.
But starts with the outside and the drive-bys from the outside without thought, right? And then start building up the internal defenses. And, we talked about the pomegranate, right? How do the seeds help us? How does the non-interconnectivity between the seeds and the gel coating help us define the appropriate protections that I need for each one of these?
Often what you’ll find is some of the most critical systems are a collection of a couple of seeds, or maybe it’s just one seed. So then I think about that from a different perspective. I’m not protecting everything. I’m protecting a handful of my seeds that have certain capabilities. So what are those capabilities, and are there some that I can, shut down access to my identity provider, and then it needs something different?
Can I put double checks in place for things? Can I limit the exposure that I might get between, one seed to the next, right? All of those things start making you think about what you can define from a resilience perspective. But you just don’t go at it blindly, and I think we have a lot of discovery to do within our enterprises.
And, then some invention around the outside, some new products and new teams and new ideas on how to protect ourselves in this new world all coming up very quickly. So they all take a, a kind of a different shape, but it starts with, if you’re tasked with presenting, provec- protecting an enterprise, it is really critical you understand that enterprise.
You understand all the pieces, you understand w- how it flows, you understand the map of it, you understand what’s most important. And then you understand some likely attack patterns and then some unlikely ones. Once you have that, you can start defining what safeguards would be in place. But it is…
many folks have been able to do this but a lot of folks have, Still have
Agnidipta Sarkar: a long way to go …
Tim Brown: still have a long way to go, and it’s simply- So- … the exposure may not be there
Agnidipta Sarkar: Tim, I think I may have to do another one with you because I’m not able to stop my questions. So I’m just trying to wrap up for the amount of time we have.
I have a, a, a very customary question. If you were to advise practitioners, what are the top three things they should be looking at as they look into their organization? What would they be?
Tim Brown: Yeah. First is their internet-facing assets, really truly understand what they are really truly understand what gaps they have.
That’s one no question. Next is, after understanding, truly start doing, agentic testing of your environments, and especially the, what’s exposed from the internet. That’s gonna be the first thing that gets, just gets readily popped. Firmware, really worried about firmware.
And, OT devices that haven’t been updated in a long time those will be one of the first types of things attacked, so worried about those environments. Next is, truly understand what the most important assets within your environment are, and try it, try to test them, try to access them.
Use these systems to be able to, attack them because you don’t want the, the bad guy to be the first one to do that. Then the monitoring side. How are you gonna tell whether you’re under attack or not? How are you gonna tell whether your first lines of defense have been compromised?
So understand that. Microsegmentation in a lot of places. Use the good hygiene that we’ve built, just put that good hygiene onto another level so that you’ll, you can become as resilient as possible. So the other part, it’s not the end of the world. We’ve been through these types of transitions before, so this is another transition for us but we have to be diligent and really, get it done.
So that’s words of advice.
Agnidipta Sarkar: Thank you so much.