SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Containment 'Essential' for cyber resilience in the model driven era

Containment 'Essential' for cyber resilience in the model driven era

Wed, 16th Sep 2026 (Today)
Shane Hill
SHANE HILL Interview Editor

Asia Pacific CISOs are facing attackers moving at machine speed and require greater, more risk informed containment if they are to safeguard business value. 

That's the main takeaway from Illumio World Tour event in Melbourne this September. Marking the start of its global tour, the "breach containment and microsegmentation" provider's representatives were joined by industry luminaries and enterprise and government customers.

Time and cost to exploit tends towards zero

By now we've all grasped the effects of the Apr 2026 Mythos breakout: a sandboxed agent that produced a remote code execution exploit overnight. Zero-day exploits may now cost attackers under US$50 and convert vulnerabilities to exploits over 70% of the time. Many other recent public examples show cyber crooks' rewards escalating faster than their diminishing costs. 

High consequence attacks that move fast compound the cyber risks for Australian organisations. Those are illustrated in the most recent cyber threat report from the Australian Cyber Security Centre (ACSC). According to the report, the ACSC receives incident reports every 6 minutes on average. Cybercrime costs to large businesses are rising by over 200%. 

Cyber threats will become more nefarious from here. Masters of the dark arts now use model driven tools to design an accelerated cyber kill chain from reconnaissance to digital trickery, intrusion, elevation, movement and ultimate exploit. But let's get real: the CISOs role hasn't changed, the urgency for cyber resilience has. Safeguarding organisational crown jewels still requires the fundamentals. Supplementing continuous asset and network visibility with operational and behavioural telemetry still illuminate the safe from the suspicious. Deeper segmentation and secure-by-design modernisation remain relevant when locking down vulnerability. And unindented insider threats still require cyber hygiene with a zero-trust architecture (ZTA). 

Illumio Chief Revenue Officer John Lens spoke about the urgency for visibility. "We need clearer and more understandable visibility across our networks," he said. "[Prioritise] assets and workloads, application deployment, east west flows, [all informed and directed by] business context." In his view, this "can't take years," as the time for attackers to convert intrusion to exploit collapsed from "2.6 years on average to 1.6 days in 2026." Or, in the case of Mythos, just a few hours. 

Containment can prevent breaches becoming disasters

Amidst this urgency and a constant state of intrusion we must contain. This mission aligns with that shared by Illumio Vice President for Solution Architecture Brian Pitta: "to prevent breaches becoming [business-ending] disasters."

Microsegmentation has existed for over a decade but problems in organisational application remain. Illumio's views on the segmentation imperative suggest architectural issues as the root cause of many well-publicised breaches. Flat or insufficiently segmented topologies enabled attackers to move laterally at will. CISOs are facing a perfect storm when this is coupled with insufficient ZTA maturity, hybrid multi-cloud arrangements and the modern model driven era. Cloud and models expose the organisations to diverse risk vectors at massive scale and velocity. Topology failings are made worse with privilege.

While breaches are accelerating, containment with zero trust can be the difference between an isolated subnet being unavailable and executives' names plastered across the news, or worse.

Containment starts with the right architecture. "Attackers move in seconds and so should containment," according to Lens. "Resilience is what you have when breach [is] assume[d] and … [you act] to reduce the consequences. Flat networks can't survive the [inevitable] breach."  It also requires granular visibility. Those insights start with posture, spans topology and, crucially when trust is unreliable, regards identity as a delineating factor. Never trust, always verify access requests – and this mantra is of redoubled importance for non-human identities. Think of those associated with operational technologies (OT), smart devices and agents. Often these are orders of magnitude higher in volume and risk than those associated with humans. 

Industry luminary and CyberCX founder Alastair MacGibbon shared his identity risk concerns. In his words, "survivability and resilience are becoming harder through the proliferation of connected devices." In other words, OT like lathes can be actuated by cyber crooks, connected vehicles can facilitate state sponsored espionage, and smart meters can be hacked to disconnect organisations from utilities or bring entire grids down. These non-human identities thereby become critical threat vectors at massive scale. Containing the blast radius is essential for organisations wishing to avoid regulatory scrutiny.  

Grasp the new Essentials as a business resilience play

The final takeaway from the event is that we've needed to go back to the future. While controls like the ACSC's Essential 8 were designed as a baseline, many local organisations remain mired in the effort to realise these cyber hygiene basics. MacGibbon put it like this: "we knew the basics were important. But the problem is you've heard me say this many times before and [yet] we're still in this situation." 

So, what's the solution to these forever problems? While organisations will still need a layered approach commensurate to the size and complexity of their organisation, some help is on the way. In one example described by Australian Signals Directorate Head of Cyber Security Resilience Chris Horlyck, the Essential 8 is evolving into the Australian Cyber Essentials (the "Essentials") as part of a modern defensible architecture

Australian organisations now more commonly consume technologies from third parties. Some Essential 8 protections may therefore be ineffective as they were designed for an era where technology was largely owned and operated in house. Recognition for how the market has changed is seen in the Essentials. Thankfully, prior Essential 8 investments have value as Essentials documentation and baselines. By applying a thematic orientation (like seen in the NIST Cybersecurity Framework 2.0) the Essentials may be more aligned to the risk-informed discussions required with Board directors. Ultimately it can help organisations continually evolve posture against evolving threats. 

Containment with ZTA can form part of the essential, reasonable steps required to mitigate cyber risks. Deterministically orchestrating enforcement with the right context helps build that posture over time. As Pitta described: "attack is an occasional problem, posture is an everyday need." By focusing on the repeatable core, our overburdened cyber champions can deliver more impact in a secure-by-design operating mode. And while there is a place for probabilistic when deciphering model driven chaos, surety must prevail. Illumio's experience helping a hyperscaler secure its operations led, according to Pitta, for it to "look for ways to deliver the same outcomes without agents." 

Illumio's containment platform pillars align with some of the Essentials. Those pillars are designed to harness contextual observability for policy enforcement across the organisational tech landscape. That spans cloud, containerisation, integration, models and IT/OT. Dashboards help operators see and prioritise vulnerability exposure, network segmentation and identity. The risk scoring offers decision useful information for business stakeholders. 

In an already elevated threat landscape, containment with visibility and zero trust are imperative to maintaining business resilience. The time to prepare and survive is now.