Skip to Main Content Subscribe

Cyber Experts Highlight Zero Trust’s Role Against AI Threats

Share

Experts share why zero trust principles and cyber hygiene practices are key to combatting the growing threat of frontier AI models.

2m read
Written by:
Lou Eichenbaum, former Interior Department CISO, speaks at GovCIO Media & Research's Federal Zero Trust Forum in Arlington, Virginia, on Dec. 16, 2025
Lou Eichenbaum, former Interior Department CISO, speaks at GovCIO Media & Research's Federal Zero Trust Forum in Arlington, Virginia, on Dec. 16, 2025. Photo Credit: Invision Events

Frontier AI models capable of identifying and exploiting software vulnerabilities faster than humans are forcing agencies to rethink traditional cyber defenses, with experts arguing that zero trust architectures will become increasingly critical as patching alone struggles to keep pace.

The renewed focus on cyber hygiene practices stems from the recent release of Anthropic’s frontier models like Mythos. The speed and relentlessness of these models create an opportunity for them to outpace cybersecurity professionals’ ability to patch vulnerabilities.

“Mythos is showing us what we’ve known for years: we’re always going to have vulnerabilities in our systems. We’re never going to be able to patch them fast enough. Mythos is just reducing the timeline even further,” former Interior Department CIO Lou Eichenbaum told GovCIO Media & Research. “We need to move away of this idea that our only strategy for vulnerability management is patching.”

Eichenbaum, who is now the CTO at ColorTokens, said agencies that prioritize governance and change management will be most successful in preventing cyber attacks. He emphasized that there isn’t a silver bullet, but coupling rapid patching with zero trust and microsegmentation efforts could prevent critical assets from being compromised.

“We still need to do everything we can to prevent it, but start with the zero trust mindset that someone has breached the network or poisoned your agent. That gives you the ability to think of strategies to prevent lateral movement,” he said and added that treating an AI agent like a human user within a network is a part of having secure identity management controls in place.

Federal agencies are already accelerating their zero trust efforts with recent developments focusing more on continuous threat validation led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA).

In June, CISA published guidance as part of its “Journey to Zero Trust” series to help federal agencies transition away from legacy, perimeter-based security. It follows last year’s guidance on implementing microsegmentation, a tactic used to segment networks and prevent threats from moving laterally in an environment.

“CISA continues to support federal agencies and the broader cybersecurity ecosystem with their continued adoption of zero trust network capabilities to meet mission needs and the evolving cyber threat landscape,” CISA acting Executive Assistant Director for Cybersecurity Chris Butera said in a statement.

Earlier this year, NSA released the first in a series of zero trust implementation guidelines intended to “provide practical, actionable recommendations to facilitate” zero trust.

Eichenbaum cited CISA’s zero trust community of practice and the other resources it’s provided to help agencies with their zero trust journey. He added that for workforce integration, it’s important to find a zero trust “champion” who helps educate others about the importance of cyber hygiene.

“At DOI, we built an organization of champions. We got people to understand and believe in zero trust, and they went out and spread the word. It takes multiple people to ultimately adopt new ideas, share new thoughts and help change the culture,” said Eichenbaum. “It can be challenging, but if you find that one person, someone who wants to be innovative and take risks, it can help advance your cybersecurity mission.”

Related Content