✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
How Zero Trust Was Born
John Kindervag, creator of the Zero Trust model, joins host Doug Merritt on In Progress to trace Zero Trust's origin story — from LAN parties and firewall configurations to federal security mandates. John explains how getting fired for adding outbound rules to firewalls eventually led him to develop the framework at Forrester Research. The two dig into why trust is a vulnerability, how to protect what matters most, and why better policy — not more products — is the real fix.
Stay in the Loop
Get exclusive access to the latest conversations with cloud leaders, industry pioneers, and technology changemakers.
Subscribe and stay ahead of what's next.
Zero spam. Unsubscribe at any time.
Key Summary
- Trust is a human emotion, not a network concept — and treating it as one creates the vulnerabilities attackers exploit.
- Focus on "protect surfaces," not everything at once. Defend your most critical assets individually, and Zero Trust becomes incremental and non-disruptive.
- All bad things happen inside of an allow rule. If something bad happened, a policy somewhere permitted it.
- Stop buying products and start building policy. One consistent policy construct — who, what, when, where, why, and how — can apply across your entire environment.
- Security won't improve until CEOs change how cybersecurity is incentivized. CISOs need real authority, not just accountability when things go wrong.
The Speaker
Doug Merritt is Chairman, Chief Executive Officer, and President of Aviatrix. Most recently, Doug served as Splunk President and CEO from 2015 to 2021. During his tenure as CEO, Doug led the transformation of Splunk from an on premise, perpetual license software company with the equivalent of $220 million in Annual Recurring Revenue (ARR), to a cloud-based SaaS company with ARR of $3.12 billion. In his first year at Splunk, Doug served as the Senior Vice President of Splunk’s go-to-market functions including sales, marketing, support, business development, partners, and other customer facing functions.
The Guest
John Kindervag is one of the world's foremost cybersecurity experts and the creator of the Zero Trust model. As Chief Evangelist at Illumio, he drives awareness and adoption of Zero Trust Segmentation. Previously, John led cybersecurity strategy as SVP at On2IT, served as Field CTO at Palo Alto Networks, and spent over eight years as VP and Principal Analyst at Forrester Research. In 2021, he was named to the President's NSTAC Zero Trust Sub-Committee and was a primary author of the NSTAC Zero Trust report delivered to the President. He also received CISO Magazine's Cybersecurity Person of the Year award and advises organizations including the Cloud Security Alliance and NightDragon.
Never Miss
an Episode
Join thousands of cloud professionals following the stories, strategies, and hard-earned lessons from the architects driving enterprise transformation. Be the first to know when new episodes go live.
Zero spam. Unsubscribe at any time.
Join cloud engineers and modern architects already tuned in.
Keep exploring
Related Episodes

The New Physics of Cyber
Doug Merritt · Chief Executive Officer
- AI security M&A is moving at unprecedented speed. A category that didn't exist two years ago jumped from 10 deals last year to a projected 50–60 by year-end, as companies like CrowdStrike, Palo Alto Networks, and Akamai spend hundreds of millions to fill AI roadmap gaps. - The mega deal era is accelerating. Cybersecurity M&A is on pace to exceed last year by 10%, yet most deal values remain undisclosed, making the market harder to read than it appears. - Detection without prevention is a dead end. The industry excels at seeing threats but struggles to stop them. Investors are responding, backing prevention-oriented companies with outsized funding rounds. - Security needs to go back to first principles. Three runtime control points — identity, compute/endpoint, and network — are the foundational layers where organizations can stop attacks in progress.

Cybercrime Runs Like a Fortune 500 Company
Doug Merritt · Chief Executive Officer
- Cybercrime is organized like a business. Roles are specialized and clearly compensated, from malware developers to money launderers, making these networks resilient and hard for law enforcement to dismantle. - Ransomware economics are shifting. The cost of storing and servicing stolen data has led many groups to abandon encryption entirely in favor of extortion alone. - Lateral movement, not initial access, is the real threat. Incidents like Colonial Pipeline and Stryker show that how fast attackers spread internally matters more than how they got in. - Preparation is non-negotiable. Boards should know who's responsible for which decisions in the first 24 hours of an attack, well before one happens.
Assume Containment, Not Breach
Doug Merritt · Chief Executive Officer
- Why Nick argues the industry should shift from "assume breach" to "assume containment" — and what that changes about incident response - The guardrails-not-gates philosophy that lets developers move fast without becoming security experts - How Nick's team found a workable path through an "impossible" secure-SDLC mandate on SpaceX's Falcon codebase - Applying Elon Musk's first-principles reasoning to break security problems down to their core "whys" - Why Nick sees cloud security footholds as a societal and economic risk, not just a technical one

Chris Hughes: Not Prevention, But Resiliency
Doug Merritt · Chief Executive Officer
- CVEs are exploding — over 40,000 in 2025, with 2026 projections near 60,000 (some estimates up to 100,000) — while AI makes vulnerabilities easier to find and exploit. - Patching capacity has long lagged below 10% of the backlog; broken production risk and competing business priorities keep it there. - Security should shift from trying to prevent every incident to containing and recovering from the ones that happen. - "Human in the loop" doesn't scale against AI-driven attack volume — defenders need to fight AI with AI. - Security teams that act as collaborators, not blockers, avoid the shadow-IT workarounds that punitive policies create.

