FireMon Tackles Network Security Policy Complexity
Network Security Policy Gets More Complex
Alan Shimel speaks with Dan Rheault, director of product management at FireMon, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on network security policy and why it remains difficult for enterprises to manage. Rheault explains that networks have become more complex across firewalls, cloud environments, SDN, identity systems and microsegmentation platforms.
FireMon has been working in this space for nearly 25 years. Rheault says the core challenge has not gone away. Organizations still need to understand their networks from the inside out. They also need to know which connections exist, which policies are active and which controls are creating risk.
Firewalls Are Only Part of the Story
The discussion looks at how network security has changed since the early days of firewall policy management. Rheault notes that FireMon is not limited to firewall management anymore. Enterprises now operate across many enforcement points. That includes traditional firewalls, cloud controls, SDN, microsegmentation and other security policy layers.
This expansion creates operational pressure for network security teams. Cloud teams may deploy services quickly, but network security teams often inherit the responsibility for keeping policies consistent. Mergers, acquisitions and changing vendor stacks add even more complexity. Without a shared control layer, teams can lose visibility into what is actually allowed.
AI Raises the Stakes for Defenders
Alan and Rheault also discuss how AI is changing the threat landscape. Attack velocity is increasing, while infrastructure complexity continues to rise. That combination makes context more important. Teams need to understand which risks are material, which changes matter and which policies create the broadest blast radius.
Network security policy becomes more valuable when teams can connect policy decisions to business risk. Rheault says organizations need better ways to understand exposure and prioritize action. The goal is not only to manage rules. The goal is to help defenders see where policy, infrastructure and threat activity intersect.
Security Teams Need a Control Plane
The conversation positions FireMon as a broader control layer for modern enterprise security policy. Rheault describes a need to support security policy across hybrid and multi-cloud environments. That includes reducing drift, improving consistency and giving teams a clearer view of what is happening across the network.
For security leaders, the takeaway is clear. Network security policy is no longer a narrow firewall task. It is a core part of managing risk across modern enterprise infrastructure. FireMon’s approach is aimed at helping teams reduce complexity, improve visibility and make better decisions as networks and threats keep changing.
Transcript
Hey everyone. We're back here at Black Hat, continuing our coverage. This next company is a company that I have been working with and following for 25 years.
I think they're coming up on their 25th anniversary. Yeah, we got the birthday balloons. Yeah.
I remember the product when it was still part of FishNet Security before it was spun out. And then, after I had left the company I co-founded, Still Secure, I actually wrote some papers for Firemon, white papers, and position papers back in the day. This is before Techstrong.
Anyway, I want to introduce you to, well, he's there a year and a half, but to me, he's new, a new fellow from Firemon. His name is Dan Roe. We got that name right, Dan?
Nailed it. Excellent. Dan's running product- Yeah ...
at Firemon. So what's exactly the title? Director of Product Management.
Okay. So I work with Jody, the CEO, and Jeremy, the CTO, and we figure out what's next, what makes sense, and there's certain fundamental assumptions we're making that we can challenge and be a little contrarian. Excellent.
Dan, before we jump into Firemon and what you're doing there, give people a sense of your journey in security. Sure. So I started in ethical hacking at a penetration testing company.
Ended up at a fintech company after that for six years, then worked at Tufin for six years. Had a startup with a couple buddies in the Chasm space. We exited that, and now I'm at Firemon.
So I have rounded pretty much every specialization within security- At one time or another ... to understand how they all need to mesh together. And it's funny because one time Tufin and Firemon were head-to-head competitors.
Yeah. Back when just managing firewalls and policy was everything. So it's funny that you complete 360.
Well, networking is one of these funny things when the company's been around for 25 years, and you're still introducing the concept to companies. Yeah. " Yeah.
" You could do that? Yeah. Yeah.
And it's still a problem. It was a problem then, it's a problem now, it'll probably be a problem in- And it's so complex, and I think that's one of the reasons we haven't had a lot of emerging competitors in the space because the investment to support all the complexity of the different vendors and routing constructs in the cloud, micro-segmentation. So that was always the biggest thing, was just the sheer, to get your arms around that whole, what works here is going to work there.
Am I using AWS? Am I a hybrid? Am I multi?
Am I just on-prem? Am I a Cisco shop? Am I whatever it was.
Yeah. The permutations were like Rubik cube kind of stuff. And then things get swapped out.
Vendors get brought in. Organic acquisitions, M&A. Yeah.
Well, and now it's more complexity, right? The original networks of 20 years ago might have two firewalls, and it was very simple. But then you think about firewalls, next-gen firewalls, cloud, SDN- Cloud ...
identity, all this stuff, micro-segmentation. What happens is that companies buy into this. They're all very helpful to solve problems, but then network security ends up operating that, right?
Right. " And so they put a firewall in, but then the cloud teams don't want to operate the firewall, and the firewall has to be operated consistent with all the other firewalls. Right.
" Something else for you. Well, because you have nothing else to do. Yeah.
But I think suffice to say, Dan, that Firemon isn't just about firewall management- No ... or policy management. Not certainly anymore, and not for a long time.
So let's pivot and talk about what is Firemon doing now. Yeah. We've been growing to meet the demands of customers and that complexity of the network.
And so you're right, Firemon has fire in it, and so it's very easy to just limit it to firewalls. But we've been expanding our support for all the different security policies across an organization. So as I mentioned, it's the firewalls, the cloud, SDN, recently micro-segmentation policies.
Yeah. Because all these things together are critically important for enterprises now, more so than ever before. Because what we're doing is we're increasing more complexity, and then parallel to that, with the threats that AI now pose in a very real way, what's happening is that the velocity of threats is increasing.
Meanwhile, the complexity is increasing, too. So unless we can actually address the complexity on the network security side, provide context to actually understand these threats, and actually figure out which ones are more material and real with a broader blast radius, organizations in the current network really weren't built to support the current threat landscape. I don't disagree.
100%, I agree with you on that. So Dan, when we look at this, though, look, we're probably seven minutes into our interview. We haven't mentioned agentics and AI yet.
Yeah. We have to. Otherwise, they'll throw us out of here.
Yeah. How is that complicating things? Well, I don't know if it's really complicating things from our perspective.
From security teams, it is triaging a lot more stuff early on and bubbling up the information for humans to still make decisions. Maybe not the low-lying stuff, but- Some of the conversations I have with customers that are implementation of it and trying to understand how we fit in have been pretty interesting because the tonality of these conversations have fundamentally shifted in the last three months. Right?
More zero-day exploits in the last two months than we had in the last two years. It's making organizations really rethink how they do things. " Right?
Or, "The business has been disrupted. " Yeah. And so where I've seen us fit in is really in that core intelligence that makes us so unique and special that very few organizations can achieve, which is the actual context of the network.
Right? So when you think about all the different tools out there that tell you different things about different controls or agents or identity and stuff like that, they all operate independently. And so what we do by actually understanding the network and how it connects is bring that context so that way we can actually understand what these things are and where they are and how risky they are, and whether or not that access available can be exploited.
Now, we can provide that intelligence to AI. We sit very nicely in a tool chain because what we do is the hardest possible thing, which is actually understand the network connections. Yeah.
And so as organizations are building out their agentic tool chains and whatever tools that they do have, we end up being a very distinct and enriching value add for that. So from a SOC perspective, an alert, okay, well, how did ingress occur? Does it have access to my crown jewel environments?
These are all things we can understand throughout the understanding of all the routing enforcement technologies. So we really sit, I think, in probably the refinement and intelligence layer that allows AI to actually be successful, because you have to have good data for AI to be successful. Yeah.
And line of sight. " And that brings me to my next piece, which is I was having a conversation with a fellow from ADAP that runs AWS agentic security. Mm-hmm.
And I remembered something I used to say about cloud security when cloud first came out, which is you can't leave your common sense at the door when you come into this conversation. You can't throw away 25, 35 years of security best practices just because something has AI in front of it now. Yeah.
Well, the fundamentals are actually more important than ever before, right? Absolutely. Think about typical use cases for Firemon is someone failed an audit, or they were breached.
And it's like, okay, well, what was used? And it's a bull in the environment that everyone's afraid to touch because they didn't want to break anything. And so that's like a day one table stakes use case for us.
But as we've gone through this evolution or at least accelerated maturity, and the adoption of AI and where it fits, I think the really interesting thing is we've talked to our customers, too. " Right? No.
Humans still own outcomes. Right. AI should be able to accelerate their decision-making capabilities.
" Because AI makes mistakes. AI makes a mistake, who's accountable? Right.
" Yeah. But that's right. Yeah, you're right, Dan.
Yeah. You will do it better. Yeah.
I love when they tell me that. But I think that's an important piece of this, too. We read the HuggingFace thing and the Anthropic thing has got loose.
It's not that these agents are malicious, or they want to hurt you. They're programmed to do a job. They're going to do that job.
It's still the people who are responsible. It's still the people who tell it what job it is. It's still the people whose job it is to keep it within the guardrails and everything else.
" Yeah. And I'm afraid we're going to see some of that. Well, in the context of business, you can't.
Right? So let's say you're a pharmaceutical company and all your production operations are shut down. Mm-hmm.
Right? Because AI made a change to respond to something, doesn't have the context of the business, right? Okay.
Well, now you're out tens of millions of dollars, sometimes hundreds- Yeah ... based on the different customers that we interact with. And the real problem is that by removing the human from the equation, not only are you losing accountability, but you're actually losing the people that actually understand the business- Yep ...
that are most capable to make those decisions, understand the risk and impact associated with them. And it's a problem. So as we chase the AI hype scale, as I'm seeing it within our customer base, it's incremental, it's very important, but at the end of the day, AI is just feeding off very good intelligence, like our product.
Right? And then aggregating that information, providing the context to humans to make decisions. Absolutely.
That's the most important thing. But it's still the humans making these decisions. Humans have to make decisions, and they have to own outcomes.
And if a human wants to abdicate the decision-making process to an AI, don't blame the AI for a decision it made. You're the one, you know what I mean? You abdicated your responsibility.
I'm afraid we're going to see that, too. Yeah. " Right.
And I don't know who's going to be held accountable for that, but if it's not a human, the human that made that choice to do that is probably the accountable one. So I call that the difference between what they call human in the loop, we all hear this human in the loop, and human at the helm. So you may not have a human at the wheel of every decision being made.
AI's going to do it. But ultimately, it's the human who's steering the ship here. It's the human who's setting the course.
So it's human at the helm is what I call it, and I think that doesn't change anytime soon. No. And honestly, it can't.
No. Just for accountability reasons, compliance reasons, attestation. There's so many downstream complexities that occur from autonomous operations.
Yeah. And I think until we actually mature and fully understand the impact of that, as you said, human in the loop is always going to be critically important. Absolutely.
Dan, we got to wrap up. For people who want to get more information about Firemon, what's the best route for them here? com.
Just go to it? Just go to it. It has all of our information.
If you're here at Black Hat, you can come find me. Yep. Well, but this isn't live, so by the time they see it, God willing, you'll be back home.
I hope so. Well, with the way flights were getting out here, I'm not counting on anything going back East either. August is no travel for me.
Yeah. It's a tough month with thunderstorms. Anyway, hey, man, a pleasure.
Yeah, likewise. I'm glad we got our first Firemon interview with you under our belt, but hopefully- Yeah ... we'll be doing more soon.
Yeah. Appreciate the time and the conversation. All right.
com, go check them out. We're here at Black Hat. We've got more of our Black Hat coverage coming up soon.