Skip to main content
John Kindervag

John Kindervag

Oct 8, 2026

16:26
What, what was it in sort of the evolution of your thinking that made you think, "I need this term, because without zero trust, it's just a good idea"? What was that, John?
16:38
Well, I mean, it was because, first of all, I, I, you know, step one of zero trust was originally to find your data, and I was looking at it from a purely holistically data perspective.
16:48
And then people said, "Well, I wanna use it for my assets.
16:50
Uh, I wanna use it for my IOT." And I started doing a lot of that stuff.
16:54
And, and then I thought, okay, Warren Buffett's partner Charlie Munger has a st- saying, "Invert.
17:01
Always invert." Right? So when you have a problem, invert that problem, and I was thinking about the problem of the attack surface, which is, to me, uncontrollable.
17:10
It's constantly growing like the, the universe, right? So it's expanding, and everybody's talking about controlling the attack surface, and I thought, "Well, that's pretty, pretty difficult." And I, I had this e- example that a lot of people have seen of protecting the President of the United States, and I thought, "Oh, that's the exact opposite of the attack surface, is the protect surface," right? So I can shrink the attack surface down orders of magnitude to something very small and easily known.

16 MINS LATER

33:14
I don't know how that aligns.
Fung-Tee NguyenCORRESPONDENT
4:44
What do you think is the main idea behind the book?
4:46
The thesis is that attackers think in graphs, but defenders think in lists.
4:52
And Chase's view, he goes back into the creation of graph theory back in the 1700s by Leonard Euler.
5:00
He talks about how attackers think in graphs, think in flows, think in...
5:04
this resource and how can i get to it and how is it connected to everything else and how can i move from that resource to this other resource that's really important as you think about how you're applying zero trust policy because zero trust policy is all flow based And Chase goes into some of his work that he did when he was at the NSA and even before that in the U.S. military, looking for physical attackers fighting the global war on terror and looking at the interconnections around that and seeing how they connected with each other, which gives you an idea of how the attack is either happening or might happening and how you can get in front of it.
Fung-Tee NguyenCORRESPONDENT
5:43
So it's really about understanding how attackers operate and using that knowledge to strengthen your defenses?
5:48
I mean, Sun Tzu, the main thesis of his art of war is know your enemy.
5:55
And to know your enemy, you have to think like your enemy.
20:09
How do you define it, and why do you think it's become such a, uh, it's come to the fore in the way that it has?
20:16
Well, because, you know, as Chase says, we, we, we assume that, that a, that an organization probably has been breached.
20:26
They're- They've got, you know, malicious actors inside the organization.
20:30
That's dwell time.
20:32
They're sitting there learning everything that they can do, and they're deciding what they're gonna attack, right? And, and so what, what resilience is, is the ability to withstand an attack and, and get revert back to a good state, you know, and not completely go down.
20:54
And so, um, I even talk a little bit about going beyond resilience into anti-fragility 'cause one of the things that zero trust can do is make the environment stronger and stronger over time when there's a lot of load.
21:08
And so resilience, you know, and robustness is a, is another thing people talk about, but, uh, what it, what it means is that the, that our environments won't just fall over when there's an attack.
26:20
Yep

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.