You’re preparing for the next cyberattack. But what happens when it actually hits?
Can your teams keep critical systems running? Can you contain the damage before it spreads?
In this episode of Breach Ready Dialogues, our Chief Evangelist Agnidipta Sarkar speaks with cybersecurity policy expert Tatyana Bolton about what real cyber resilience looks like.
They explore how organizations can protect their most critical assets, limit lateral movement, secure legacy environments, and respond at machine speed without relying on humans to make every decision in the moment.
Because being secure isn’t just about stopping every breach.
It’s about staying operational when one happens.
Agnidipta Sarkar: Welcome to the Breach Ready Dialogues, the show that focuses on all aspects of a cyber attack. We assume that a bad day is coming, and we focus on whether we should survive with dignity because we were breach ready or collapse in disarray because we were not. So if you’re a CISO, security leader, a policy maker, or a board member, you already know that the rules have changed.
It is no longer whether we will be breached or not, but it is what– when it happens and how fast can we contain it, withstand its effects, and then keep the critical businesses unaffected. On this episode, we will be talking about that exact shift from traditional perimeter heavy defenses to genuine cyber resilience.
Not just more tools, but better decisions. And as I keep saying, at the end of the day when you have a breach, it is all about decisions. It is about what you protect first, how you are architected for failure, and how you explain all of that in, in simple English to, to your stakeholders, to your regulators.
And my guest today is Tatyana Bolton, who is a policy expert. She’s a board member and a public speaker who works on security issues including security by design, artificial intelligence and connected devices security, and of course the cyber workforce. So whether you’re listening on your way to the office or heading into a risk committee or just trying to step one, one step ahead of the next incident, listen to it.
Let’s get into it right away. Hi, Tatyana. Welcome to the Breach Ready Dialogues. Why don’t we begin with an introduction to yourself and, how you react when you hear the news of breaches all around us?
Tatyana Bolton: Yeah. Hi thanks for having me. It’s a pleasure to be here. My name’s Tatyana Bolton, and I am the I am the principal at Monument Advocacy, where I run their cyber practice.
I also happen to be the executive director of the Operational Technology Cybersecurity Coalition. And in that hat, I see a lot of work that’s… all of the work that’s happening around our ecosystem, around resilience particularly across critical infrastructure. And so this is a a very timely discussion.
To your question about what do I think when I see breaches, I think everybody sees the news all the time, and there’s a breach that’s happening in a cloud environment, or you- we hear about yet another yet another breach in a some state, Michigan or Baltimore or, what what have you.
So many different sectors and types of companies and organizations, governments are being breached all the time. At this point, I think most people understand that it isn’t atypical to get breached. I happen to think that’s unfortunate, that we have become so so jaded and accepting of breaches because I think that we need to get to a better place.
I think we need to get to a place where we are more prepared, more resilient, more ready to defend our networks. Which is why I think your comments at the beginning about perimeter defenses versus defenses within our networks is so relevant. And so I’m eager to have that conversation with you today.
Agnidipta Sarkar: No, thank you. Thank you. But a- as you correctly said it is… we are living in a world where it’s no longer enough to think that, perimeter breaches are… perimeters are what need to be emboldened. And as… And you correctly said that it’s been, it’s become commonplace. I remember when the first LinkedIn breach happened, and they lost, what, 150 million identities were lost.
There was a huge hue and cry in, when was it, 2022, 2021, somewhere around that period. Yeah. Everybody was so bothered about it, including the regulatory authorities. They came down heavily on I think it was Microsoft. They had acquired LinkedIn by that time. It was a big thing. Today whenever there is a breach- There’s not much that is said about…
Nobody’s shouting from rooftops, “Oh, we- they got breached. They got our personal data.” Though in reality, it is affecting our lives.
Tatyana Bolton: Yeah. It really, it needs to really reach a, an incredibly high threshold for anyone, especially the public, to actually care, right? The last time that I can remember that the public really re- like a breach resonated with the public was probably SolarWinds.
Or if we’re being… Like, where they really cared was, like, Colonial Pipeline. That was the breach that kind of really struck a chord with Americans because it actually impacted their day-to-day lives. And it– at this point, it has to be s- one of the mo- kind of the most significant breaches.
And but others are happening all the time across schools and hospitals and, those are becoming, like you said, commonplace. People are used to it.
Agnidipta Sarkar: Yeah, and you talked about hospitals. Very recently, in fact, the breach is still going on. There was an attack on hospitals.
I think it was Minnesota. University of Minnesota hospitals. And and that, that is affecting that is affecting people. And you’re also right about the fact that most of the attacks that have resonated with people are those which have affected people people’s lives, their livelihoods.
And, a- and therefore… And we are seeing more and more of these incidents affecting the normal human. I mean our da- daily lives, right? And for example, deepfakes. People’s identities are being lost, they’re copied, and then you have all these all these individual attacks that are reaching out to people.
That’s what I’m saying. The whole the whole e- epicenter of the cyber attacks is no longer going to be only an enterprise, only a hospital. I think it was in… Yes, it was University of Minnesota who have confirmed that a breach has happened and it affected their hospital.
It affected people’s lives. The good news is that in the US especially, and likewise in many other countries, they have… and I think it’s only true to the hospital system, that they have laws that say you just can’t shut down if the digital system is not working. You need to offer the care of life to- through other means.
But the fact is that while it is possible to some extent in hospitals, it may not be possible in other industries. Manufacturing, for example. If there was a breach which led to an OT incident, there would certainly be… There could be loss of life. I remember that there was this gas pipeline that got damaged sometime back somewhere in Europe, which caused…
There was a blast, and it was all because someone got into the system, and they were able to obfuscate the monitoring of the amount of gas that was going through a pipeline. And- Yeah … and it was blocked, so it blasted and people died. These are things that, that are really, worth considering.
In fact the University of Medical Cen- Medical Center at Uni- at Minnesota, I think UMMC or what is it? I… Let me get some data on that, but I think that’s the one that I’m really bothered about now because they had everything. They were guarding- Yeah … the doors. They still had the cyber attack, which crippled them.
They had to reschedule a lot of
Tatyana Bolton: surgeries. Yeah …
Agnidipta Sarkar: surgeries. They called in FBI and I think I saw a media briefing by FBI and the medical director of that hospital.
Tatyana Bolton: Yeah. I… The hospital the hospitals obviously bother me as well. I- it’s a critical lifeline sector.
It’s one of the top five sectors that CISA, the Cybersecurity and Infrastructure Security Agency in the US, is most focused on right now to build resilience around. But I think, it’s not the only one. We also saw in Europe not only that incident you mentioned but also the incident where there were rolling blackouts across Spain and other countries this summer.
And th- and that, that happened, We don’t actually know exactly what happened. But- That actually brings up another point. Not only do we have, not only do we have incidents that are happening in schools where where students’ data is getting either encrypted or stolen, hospitals where they are locking administrators out and, ransoming their administrators in order to bring systems back online.
Casinos, we’ve seen hackers go after go after casinos in order to get money or, states and localities. But in many of the… But the issue is that in many of those situations, one of the issues, is that people can’t always tell what has happened because they don’t have the logs from before the incident turned on in order to do sufficient sufficient forensics to figure out whether it was a breach or whether it was something that happened because of, like in the case of Europe some some natural phenomenon that, that resulted in rolling blackouts.
There are assumptions by some that it was caused by a hack. But mo- in most situations, if the organization doesn’t know I… Maybe I shouldn’t say most. In some situations, when the organization doesn’t have the logs, they revert to just saying, “Oh, no, it wasn’t a cyber attack,” because people are concerned.
They don’t wanna, they don’t wanna think that a cyber attack can turn off the power to an entire country, right? We aren’t… We want to push off some of these much more significant concerns and much more significant impacts because we aren’t humans just aren’t set up to accept such bad outcomes.
We don’t wanna hear it. And we see this in water right now as well. There are really significant concerns about the investment in resilience across the water systems across the United States. There’s more than 50,000 water utilities around the US and obviously multiply that by the number of countries that there are and their size, of course.
The US is huge, and so therefore has a lot more has a lot more of a footprint to protect. But, you know- Imagine trying to protect 50,000 utilities, right? And that’s just one sector. It be- it’s very difficult. That’s where kind of my work comes into play. I work at the national level to to think through policies that would enhance security across sectors and across across sizes of organizations to create to create smart policy to encourage organizations, cities industry to increase their level of security.
And there’s a lot of different things that are th- that are working right now. We are thinking about how to how to structure recommendations and policy around AI and security. How to incorporate AI, but to do it in a responsible manner that acknowledges that AI isn’t necessarily fully mature, and putting it on OT systems, for example, right now, should absolutely have very strong guardrails around it.
We’re also thinking about how to build up resilience and islanding. CISA is working a lot on this right now. S- it’s a project called CI Fortify, where CISA is thinking through, how do we how do you operate systems and networks when you know that the in preparation for an incident, you know the telecom will go out.
You won’t have connection to the internet. You won’t be able to communicate with anyone in your system. You might not be able to call in the FBI, or in a large scale incident, the FBI might be busy, and that n- it won’t be… they won’t be able to have enough resources to help everybody. How can each individual organization build enough resilience and island themselves and work in, individually to bring themselves back online to think through how much energy they’ll need in order to run their operations if you’re a hospital or a water treatment facility or, a rail hub, right?
How much energy do you actually need in order to survive for a few days before support can come? And, and what else do you need to make that happen? We’re thinking through all of those things. We’re also thinking through what does the what does the Defense Department or the DOW have to have to defend in terms of critical infrastructure for the for their mission readiness.
It’s a pretty wide range of policies that we’re thinking about right now, and it’s challenging. It’s challenging from any number of levels.
Agnidipta Sarkar: Yeah. And I can agree. It’s a mammoth amount of work that you’re doing And and I think I heard you say that you talked about earlier about moving from cybersecurity to cyber resilience, and that’s the…
Given the quantum of work that you’re talking about, it’s humongous. And it, the ex- the challenges are not only setting policies, the challenges are also executing those policies in a manner that’s cost-effective, that’s, valuable to the stakeholders who are there for that particular utility, and so on and so forth.
Because adoption of a policy are twofold, right? There is, one, a penalty if you don’t follow it, and two, there is a incentive if you follow it. And so that makes a lot of difference. And that brings me to another point that you raised, and that was about use of AI. Because what I’m increasingly seeing, and I’m sure you’re seeing too, is that there’s a whole lot of this AI-based pseudo intelligence that’s floating around.
People are under the impression that if they get in some agentic AI guys they would probably replace the operator in a PLC system somewhere in, in a factory and so on and so forth. But in reality, like you said, AI is still full of errors and hence a human governance is so essential.
But the point that I’m really thinking that, policies should be driving is the focus on remaining unaffected. Because you can invest as much security as you want in tools, but unless you, let’s say, build something like a foundational capability that is focused on the ability to, face a breach and remain unaffected when the breaches happen.
Because the reality is that if you’re not prepared, if you’ve not thought about it, then when the cyber attack happens, like what I read about the hospital about the Minnesota hospital that has been attacked right now it could be weeks before they can get back on, on the rails. But ideally, the messaging should be different.
If you’ve followed the po- If you’ve built a policy around remaining unaffected, then when the attack happens, you go around and tell the world, “Yes, we got affec- we got attacked,” because really you can’t stop that, “But we’ve got cyber experts who are looking at the part that has been affected. However, guess what?
We’re online. We’re working. We’ve not shut down. Our facilities are really a-aff available. Though we are affected in a very small part of our organization, cyber experts are looking at it. We’ve invoked our business continuity plans to take care of how we can run that program.”
I think that is probably the future of of where the world should go because we need to get to a stage now with, you know- With whatever ColorTokens is doing and we are bringing in foundational microsegmentation, I think this is a reality that we can achieve
Tatyana Bolton: Yeah, I think if you take the entire sort of expanse of the of the ecosystem and you take a look at how wide the attack surface is, it’s very difficult to assume that y- it will, a breach will never happen, right?
I don’t think anybody, while they personally may believe that they won’t get breached, they will acknowledge at a minimum that certainly someone will get breached, right? So the, like the… Nobody wants to say, “Oh yeah, I’m, like my networks are vulnerable.” But I think they acknowledge that in general s- the networks are vulnerable.
And so I think if we can move to a place where we take that attack surface and we at least reduce it by breaking it down into smaller segments and protecting protecting each of those segments from each other and at a minimum protecting like the crown jewels of each organization, you significantly reduce the, that attack surface, right?
So just by making sure that it isn’t for example the entire pool that gets poisoned, right? If you imagine our attack surface as a pool right now where all the water is connected, right? If it can flow, if there’s poison in one end, it’s not like you can say like the other side is safe, and that’s what you see a lot with, across everywi- network at this point.
Most networks at this point right? Hospitals, schools, like running on sometimes outdated equipment, sometimes running things like Windows 95 still, and you’ll see that in various critical infrastructure organizations now. They’re older. It’s harder for them to to put in place the newest kind of tools because they just, it just doesn’t interoperate.
But if you take that pool and you break it down into segments, right? Like you create you create certain portions that are separated from each other, so if one part gets poisoned The rest of it is still fine, right? Where if you can ident- if you can create situations where our attack surface is broken out like that, where the water doesn’t necess- one part of the water doesn’t necessarily touch another part of the water, then you have at least portions of your network that are secure.
And I think that makes a lot of sense. I think it, I think, y- it’s protecting your valuables at home in a locked safe. You might not be able to protect your entire house, but if you know that the most likely place that an attacker’s gonna go is to go after your jewelry and cash and, whatever, if you have gold in your house or something like that, and you protect it inside of a safe that is impossible to move, then at least you have some security.
And I think, that in an era where the threats are only increasing from nation state attackers like China and Russia and Iran especially as we get into, geopolitical tensions with those countries, right? It makes… It, it improves our ability to defend ourselves or at least our ability to get going again after a breach, right?
I am a huge proponent of things like secure by design, where you build the network in such a way or you code in such a way that you are building resilience immediately into your system. I think it’s I think the way that we generally built the internet was entirely open.
And now a lot of what we’re doing is trying to backtrack that and figure out ways that we can create pockets of security where it’s where it’s n- not all one kind of interconnected plane that is really easy to, to transition. But if you get into one place, you can get into another. Chrome works this way as well.
The browser only allows only a- allows an at- if an attacker were to get in and like Chromebooks, for example, have actually never been ransomwared. But if you take one tab and you have one tab open, the attacker gets into that tab. You can’t actually… They can’t transfer to the other tab.
It’s all sandboxed. And so I think expanding that concept across all networks across the US and across the world, we’d create a much more defensible posture.
Agnidipta Sarkar: I think I liked your swimming pool example of getting poisoned and about creating se- compartments where you can do that. And I wanted to bring up one more topic that, that you touched upon.
You said that it’s difficult because you’re thinking about the scale, and now you’re thinking of what tools do I need to buy. And I think that is where agentless come in, concepts come in, and they’re very useful because as you also said that there are organizations who have outdated systems.
Now, a business decision to remove those outdated systems and buy something new is not easy because it requires extensive amount of investments. But a business decision to create a microsegment and use an agentless appliance and and thereby, cordoning off that microsegment from the other parts of the organization allow…
make sure that it doesn’t get poisoned, to, to your, to use your language. And that means if, even if the IT enterprise, some servers there get affected, this will not and therefore you are going to take care of that part. And on the IT side also, with the EDR integration that we are doing with CrowdStrike, SentinelOne, and with Microsoft Defender, the adoption is very quick.
There used to be a time when microsegmentation was assumed to be a two-year project. Right now, we are doing it in days because every organization who has an EDR, and I’m sure most organizations have an EDR today. We are in 2026. We are no longer thinking about, I still am hearing organizations that don’t have multi-factor authentication, but they’re not many.
They’re few and far between. But the attackers in, in, in… are actually trying to get in and move very quickly. I was reading about the latest CrowdStrike report, and I think it has dropped down to 30 seconds. The– Which, which it used to be 78 seconds two years ago, has now come down to 30 seconds.
That’s a very fast time for people to move within your enterprise because lateral movement was open. So-
Tatyana Bolton: Yeah
Agnidipta Sarkar: If you are trying to get into that mode of what you just said, creating micro-segmentations and zones where you have critical systems that you don’t want to get affected if there’s a cyber attack then the best way of looking at it is to create a micro-segmentation as a foundational capability, and doing it secure by design.
I was at an event and somebody asked me, why do you feel that this is how it needs to be?” And I said, “Look, everyone, when you go to, when you think of cybersecurity, you ask anybody, they’ll give you a diagram, which is more of a network diagram overlaid with cybersecurity tools saying that this is my security diagram, but that’s not really a security diagram.”
Your security diagram should indicate which part is more secure than others, which is the one that you can really depend on because you’ve invested in abilities to to, to become ready for the next breach. So which means, I know what you talked about thinking secure by design, and I think this is a very important consideration to think about that this is my business, this is how I’m going to design cyber resilience into it and become breach ready so that tomorrow, if an attacker were to come in, they will face first a problem that they won’t have too much of elbow room to move around.
Two, they will have the next problem is that they would get detected very fast because they are going to show up as an, as behavior, which is not expected of normal users. And three, once they’re detected in the area, in the micro segment where they’ve attacked, we will have the capabilities to do it at the click of a button and keep them there only.
Tatyana Bolton: Yeah. And if, and we’re, if we’re talking about 38 seconds in which you have to be able to contain a breach, organizations need to acknowledge that’s not a timeline on which any of their SOCs or security personnel can work. No human, barring some, like some magical ability to like- No,
Agnidipta Sarkar: not even AI
Tatyana Bolton: one out of, one out of every million people maybe would be able, would happen to be in the exact right place, in the exact right time, and staring at their screen and see something pop up and immediate- and make the analysis or do the analysis and make the decision to block Right? A particular action or an attacker.
Because it, so many of these attacks, like it’s not like it looks so different from regular traffic or from regular network traffic. And people, like a human, right? You are going to have to do some looking at the details of this traffic. You’re gonna have to do some analysis and then make decisions.
So many times those organizations also have decision trees where the person who sees it isn’t the person who makes the decision to make the to block a particular particular traffic or segment off a particular part of the network. So we have to acknowledge that the only way that you can do this is if you are prepared and you have some kind of functionality to enable the blocking
Agnidipta Sarkar: Maybe a modern playbook.
Tatyana Bolton: Exactly, you need to have… You need to be able to do this without the hu- a human in the loop doing it, right? Because this isn’t something where AI is making decisions, risk decisions for you, or turning off water or turning off electricity somewhere. It’s just the ability to block off particular segments of your network.
And I think given that the speed of the attack, we have to work in in, we have to work in this new reality, and that means we have to we have to be ready before the attack happens, right? And for me, it makes a lot of sense that you are that organizations are thinking about their risk posture, thinking about, what are my crown jewels?
How do I protect them better? How do I make sure that my network isn’t just, isn’t just open across the entire network, that if someone can get in, which they often do through phishing or, Or poor or weak security in one part of my network, that it affects the critical pieces and the critical aspects of my system, right?
If you’re a hospital and you have a lot of people logging into your system, a lot of different credentials the chances of credential theft are high. And so the ability to protect your record systems or your scheduling systems for sur- surgeries or your machinery that’s in on… that’s attached to the network, like MRI machines and CT scans and everything else monitor, fetal monitors in pediatric wards.
If all of those things are on separate and protected systems, then they can keep running even if one part of your IT network has gone down because a credential theft happened from one of the nurses or doctors who who weren’t necessarily thinking about security in their day-to-day life. Which it- it, quite honestly, we shouldn’t expect them to.
We shouldn’t expect them to be security experts. We should enable networks to be as secure as possible so they can go about their daily lives and do the jobs that they were trained for. And we, on the security side, are, have thought through w- how we can protect those networks without without the people in the loop.
So I, I think w- we’re gonna have to get there for all of our critical infrastructure, and I think it starts with risk conversations at the board level. It starts by changing the culture around the way in which we think about security and the investment in security. And, and just additional conversations about the sec- about how we what is s- what is standard and what is typical for network security.
I think, just like fire doors, right? Now we think of those as standard. They didn’t used to be. In, in Taiwan I was there a couple years ago talking to the government about cybersecurity. And, I saw the way in which they have now built all their new buildings with elevator shafts that don’t go up the entire building.
They’ve offset them to enable fire retardancy across buildings, so an entire building can’t go down because an elevator shaft has allowed fire to go across every single floor of the building. We have to think the same exact way about security.
Agnidipta Sarkar: In fact one of the key points that you raised is about time, and I think and of the challenge today is you can have AI, you can have…
A- AI actually accelerates almost everything that we do. But that’s where the challenge lies because there is a decision that needs to be make- taken because of the number of false positives that land up on a SOC analyst level. So you correctly put it that way. I think what we should do is use AI more effectively to pick up information from around the world.
CISA, for example, has a treasure trove of information about profiles of cyber attackers. MITRE, for example, has a treasure trove of information about attack techniques. If we are able to combine that, and that’s what we’re trying to bring to the table, we have AI systems that can combine these with the context of the organization, right?
You talked about shutting off, let’s say, 30,000 water pumps. The digital system has to recognize that this is the context where I need to consider what will happen if an attacker attacks, and then build models and playbooks which can be initiated by that person the moment he’s given a trigger that says, “Okay, if this happens, then click this button.”
It’s as simple as that. If we can get there, I think that would be a great place to be. And- Yeah.
Tatyana Bolton: Or, and I think at some point it’s gonna have to be no one clicking any buttons, that this happens automatically. Yes. Where the networks are just segmented, and those are always up allowing only particular types of traffic.
I also another analogy for that is I actually think that our Social Security numbers and our ability to open credit should actually be in an, in a closed position as the standard, and open only when you need to use your credit. That creates a system where it’s a lot it’s a lot harder for identity theft and for people to open credit cards and other loans on your behalf.
I think networks should be in the same kind of closed posture, that you assume only this trusted traffic can go through. And then if you want something else, you have to request additional access. Again, this is, the concept of least privilege that needs to be adopted more widely across all networks and organizations.
Just like multi-factor authentication, while everybody understands the concept the misconfigurations are, like, the number two reason for breaches. Because this of- it often happens that people think that they’ve configured something for least privily- least privilege, least access, but in fact haven’t, right?
Or have left something open. And we need to get into a, we need to get into a posture where this is all done automatically as AI becomes more prevalent, as- And at least it gives you an alert.
Agnidipta Sarkar: At least this gives- … give you an alert that, look, your SSH is open. Your- Something is happening
your- … rDP is open, and you need to contain that. And give it a decision platform that says, okay, if you click here, it’ll get contained and you can do that.
Tatyana Bolton: Yeah.
Agnidipta Sarkar: And if there is, if that is how your artificial intelligence is working, and it is able to, A- and I think I like one more thing that you said about identities.
If there were mechanisms to determine deviation of behavior of identities, and if there were, and I know there are mechanisms to have identities connected to micro-segmentation. So it means if you are not the user who’s allowed to go to a certain micro segment, you wouldn’t be allowed to go in. And if identities get poisoned, if that information travels to the micro-segmentation engine, then immediately that access of a valid user can also be contained.
Tatyana Bolton: Exactly. Yeah. I think, again, we’re just moving towards a faster implementation and more automatic response to breaches given that they’re so prevalent and we already know s- we already know the way that attackers get in. In some ways, it doesn’t even really matter if it’s a nation state or if it’s a criminal actor, they’re using similar techniques.
And it’s, I think we need to get to a point where we are doing a lot more to fail safe rather than fail open. I like that … and, I think that’s when we will really get to true security.
Agnidipta Sarkar: Okay. It’s… I love talking to you, and I think it- we’re having a great discussion, but I think we’ve, we’re almost done on time.
One last question to you because you are sitting at a place where you’re driving changes in policy. How do you… how are, leaders and policymakers responding to the fact that we need to move away from thinking tooling to thinking becoming breach-ready or cyber resilient?
Tatyana Bolton: I think particularly in the last year or two we’ve moved policymaker thinking towards that type of resilient posture, the resilience conversation. That in CISA, right? They’re working on the CI Fortify concept that i- that also is happening in Australia. We see conversations about this happening in Europe and in in APAC at Sing- in Singapore.
So I really think that there is an understanding among the policymaker community certainly in the highest levels of leadership that there are things we can do. I think the challenge is the scale of the problem and the number of organizations that need to implement these changes. And obviously paired with with legacy tech debt, those are some of our biggest problems.
But I think it, it isn’t the policymakers. I think I’m seeing a lot of I’m seeing a lot of people that really understand what the challenge is, and we’re hopefully now rowing all in the same direction.
Agnidipta Sarkar: Thank you, Tatyana. That was great conversation.