Risky Business - Soap Box: Zero Trust(ish) Networks
Episode Date: August 14, 2026In this Soap Box edition of the Risky Business podcast host Patrick Gray chats with Adam Pointon, CEO of Knocknoc, about the failure of Zero Trust as a comprehensive arc...hitecture. Most networks look like they were designed in 1999, and most Zero Trust products look like they were designed for 2049. Instead, Patrick and Adam pitch something in the middle: Zero Trust(ish) networks, where Zero Trust principles are applied selectively where possible. Instead of trying to re-architect entire networks, maybe it’s time we learned to apply Zero Trust principles selectively against risky assets. It’s a better approach than the status quo, which involves liberal use of the “risk accepted” stamp. This episode is also available on YouTube Show notes
Transcript
Discussion (0)
Hey everyone and welcome to this Soapbox edition of the Risky Business Podcast.
My name's Patrick Gray.
For those of you who aren't familiar, every edition of the Soapbox podcast that we publish here at Risky Business Media is wholly sponsored.
And that means everyone you hear in one of them paid to be here.
And, you know, that's the usual disclaimer, but I've got to add an extra disclaimer on today's Soapbox because today we're chatting with Adam Pointon, who's the chief executive of Knock Knock.
And I'm actually on the board of Knock Knock.
So very much involved with this business and yes, clearly, obviously, a very big fan of it as well.
So for those of you who don't know what Knock Knock is, I mean, I've talked about it a million times on the weekly show, but I'll just give you a very quick recap.
The idea behind Knock Knock is it glues SSO to network controls, right?
So you've got Octor, you've got a bunch of Palo Alto networks or Fortinet or, you know, Cisco firewalls, and you've got a bunch of really vulnerable craft.
at the edge of your network that's accessible to everyone,
the idea behind Knock Knock is why not just firewall all of that stuff out,
firewall all of that stuff off?
And then when someone needs to access it,
they log in via SSO as they normally do,
then they can just hit one web app and say,
open a port to this service, please.
And then in the background, Knock Knock goes and, you know,
adds that IP to a list in the existing firewalls,
and all of a sudden the user can access that IP.
There's a few more bells and whistles than that,
but that's the rough idea.
Like there's a grey noise integration.
So if someone's logging in behind a dodgy gateway,
you can stop them from being able to do that
and so on and so forth.
But the idea here is it massively, massively reduces your exposure
to remote code execution from unauthenticated users.
Of course, there's an internal use case for Knock Knock as well.
There's like a Windows agent that can instrument the Windows firewall.
So if you've got a bunch of Windows boxes on your internal network
that are all running RDP,
and you don't think every user should
be able to reach RDP on those Windows boxes, you can just knock knock those ports and people
can't reach them. So this is the idea. It's all about restricting the ability of unauthenticated
users to hit certain network services, both internal and external. And it got me thinking,
like this is a simple idea. So it's kind of crazy that it's taken until like, you know,
2026 for this to become a product that people are buying. And there's a number of reasons for that.
And that's kind of the basis of today's conversation, which is zero trust orthodoxy has kind of failed.
The market has just delivered us platform after platform of zero trust platforms, which aren't really tailored for the real world.
Whereas Knock Knock is kind of tailored for the real world, which is it's very simple.
And it does something very simple.
It's very simple to roll out.
So we're going to explore this whole concept of like how zero trust is best thought of,
as a guiding principle and not as an architecture, which is where I've landed on this since working with these guys.
And yeah, that's the basic rundown of the conversation.
But we're going to start here, Adam, by really looking at, I guess, the drivers behind Knock Knock's growth at the moment,
because things have picked up in a fairly insane way, right?
Things were going okay last year.
Things are going very well now.
And the reason behind that is just the risk that people are experiencing or feeling when it comes to stuff that's exposed to the internet.
And I guess a good way of thinking about that is, you know, it's a big part of this is AI.
You know, AI agents are now able to reverse engineer patches from vendors and have weaponized exploits out there owning stuff on the internet within hours of those patches coming out.
I mean, this is really what's changed and what's driving the urgency behind people signing purchase orders for your product.
Yeah, removing attack surface has always been the same thing to do, right?
Like, it's always been a bad idea to have things exposed on the internet, right?
We kind of went from this early firewall days of having a machine exposed on the internet, all the ports, etc.,
down to let's only allow certain ports through, stateful firewalls, all that kind of thing.
But it was always a bad idea to have any host or service.
us on the naked internet. It just sort of took time for people to find the vulnerability,
exploit the vulnerability. And now with AI, it's a proper mess. And there's no time to respond.
It's too quick. Yeah. I mean, you cited some figures to me recently, which is this thing
called the zero day clock, right? And what they try to do is look at the time between a CVE
hitting a database and that exploit to actually turn up in the wild. And that time is like,
I mean, you know, it's been coming down for 20 years, right?
And now it's like kind of hilariously small.
Scarcely small, same day.
And like predicted to be within minutes next year, 2027.
And that's just the proliferation of AI, reversing a patch, you know, taking the CVE, developing an exploit, and then running around wild.
It's same day is pretty scary.
And minutes next year is out of control.
I mean, you had one when you were, I think when you were at RSA, that was when some Citrix bug
dropped, right? Like it was announced and then three days later, everything was burning down
because of... Yeah, it was RSA this year when I was out there and I think it was 9.31am on the
Monday. I remember looking at it and thinking, okay, and then by Thursday, the same week it was reported
that there was exploitation in the wild. And that's, you know, a couple of days during, you know,
during the week to patch something like that, it's pretty, pretty rough couple of days.
Yeah. Yeah, so we should mention, too, that even some of the like remote access software,
like that's the stuff that you're having to use knock knock to protect so your fortinets your palo Alto's which were you know they're from security companies apparently and they're getting people owned so the idea is they're putting knock knock knock the joke is yo dog i heard you like firewall so i put a firewall on your firewall on your knock knock to instrument the firewall on a palo alto or a fortinet device to restrict itself from being seen uh which is a bit of a concept to get your head around but citrix as well has turned out to be a big uh driver
of sales for knock-knock so I guess that explains why you were paying attention to that one.
Yeah and it's just complicated pieces of software sitting on the naked internet with that sort
of walled garden soft squishy inside but complicated exposure stick attack surface on the outside.
It's just not a good recipe right. So knock-knock's being brought in as you say to add another
procedural layer in the order but it kind of allows them to hide those attack surfaces which
gives them time to respond and all those sorts of things. But the fundamental is hiding assets,
removing attack surface, removing exposure, comes back to kind of zero trust concepts, but just
a easier way to do it without all of the complicated pieces in the chain. Yeah, I mean, I think
where we've landed when we've just been talking about this, you and I, talking about where this is
going, is stuff like, if you're running stuff like Citrix, if you're running stuff like Fortinette
on the edge. You are not going to be able to outrun attackers with patching, right? Like,
that is just not going to happen. So you've got a couple of options. You can try to ditch those
remote access solutions and move to something more contemporary. That's one option. There's some
issues there. If it was easy, everybody would be doing that. You can apply a mitigation like
Knock Knock, which actually is going to extend the life you get out of that stuff. But there are your
options. Patching ain't going to do it. So then you look at, well, what's left in terms of exposure
for the average organization.
And currently it's all sorts of stuff.
It's all sorts of croft.
Weird little admin interfaces for equipment
that should or should not be published to the internet.
File transfer appliances, payroll systems,
all sorts of stuff that just happens to be there.
Some IoT stuff or whatever
that for whatever reason has to be on the internet,
maybe some RDP or whatever.
That stuff is probably going to have to go away
or get mitigated with something like Knock Knock.
because again, patching it just ain't going to work.
Where I think the effort, though,
where the effort is going to go into actually improving something
so that it's something that has to be available,
I'm expecting we're going to see a lot of investment
into things like the primary applications offered by large enterprises, right?
So if you're an airline, you know,
you can't get rid of your online booking system.
You can get rid of basically everything else
from the edge of your network or the edge of your cloud, if you will,
but you can't get rid of your primary application.
Right. So that's where that, you know, there's going to be this twofold effort in security, I think, where you've got people putting massive effort into improving the quality of their primary applications and taking everything that isn't that into a paddock and putting a bullet in its head.
Yeah, it sounds a bit extreme, but yeah, I agree. I think you're going to put all your tokens, right? Think about it in a moment. So you agree with this, but maybe less violence.
Yeah, some tokens will be slayed. And, yeah. Some tokens will be slayed.
some networks, look, there'll definitely be those systems that go to the paddock and get killed off,
but probably not enough of them fast enough, right? We all know there's going to be legacy systems
hanging around for the next 20, 30 years, which is pretty scary to think. But I agree. Put all
of your tokens into like your primary application that's exposed to everything and is complicated
and is like your main thing and everything else, you just kind of hide it, you know, put it in layers
of defenses and yes, they head towards the paddock where they're eventually retired.
cleanly and nicely and all those things.
But I agree with that.
I think securing the primary thing and everything else,
you sort of have to nurse the vulnerability and nurse those systems through to the end of life.
Yeah.
I mean, but this is coming back to this central topic that we're talking about today,
which is that I think zero trust as a rigid architecture,
as a rigid ideology, doesn't really reflect the real world, does it?
Like, you know, we've made efforts over the last, I mean, this started with the, what was it, the Jericho
forum or whatever, and de-perimitarization, and then Operation Aurora, leading Google to do, you know,
beyond trust and zero-trust stuff. It hasn't really worked in the sense that it can't be all-encompassing.
And we've got this weird situation where the market keeps delivering solution after solution,
which is an all-encompassing zero-trust solution, whereas I think you and I would agree,
zero trust is more of a guiding philosophy.
It's something you do where you can,
not everywhere because that's not possible.
Yeah, definitely.
It's a way of thinking, right?
Like systems should be self-defending,
but full stop regardless.
And then how you do that depends on what the system is.
And it's definitely a way of thought, right?
A way of thinking.
It's a discipline.
Sadly, so far, there's no software that's kind of got it right,
I feel, and it's always too complicated.
but that idea of...
Well, they've got it right if you wanted to do everything their way.
They just haven't got it right if you actually just...
Okay, so a great example is there are products out there
that you can put on every single endpoint in a Windows network.
And they're fantastic.
They will really lock down that network.
But, you know, if your primary concern is you've got 100 Windows machines
in a data center that are running RPP,
and you don't think people should be able to access that RDP from the land,
you know, you want to just put software on those 10 machines.
you don't want to have to do the whole network, right?
So that's like one example, right?
And that software, meanwhile, it's fantastic, right?
But again, just the way it's licensed seems a bit weird.
And then you've got other ones where they've just like overthought it,
you know, like, oh, we'll take your applications
and we'll put them in this network sandbox with this and the control and the analysis.
And, man, can we just have an agent that we put on a box that instruments the firewall
to reduce the risk?
Which, you know, you're describing knock-knock there, right?
Back to the kind of, it's simple that just make systems disappear.
a simple way. But I think the other thing, like coming back to the kind of, you know, purest
offensive thinker in me from back of the day, systems should be self-defending,
assume breach, you shouldn't trust anything, et cetera. If you're kind of installing software
and connecting all these systems through this, you know, cloud or through this complicated
system that's doing analysis of everything, where you're kind of trusting that same stack
and environment and, you know, vendor or deployment, right? So, you know, you know, you know, you know,
You know, how we think about it is from a threat model perspective, those systems need to be self-defending still and Knock-Knot kind of operates in that way.
But if you're putting in this all-encompassing layer that you're talking about or glue between everything, that then becomes the risk.
So you're not really taking the self-defending zero-trust thought pattern either.
But, you know, simple.
And actually, if you go back to...
It depends. It depends because some of these products do allow you to actually apply policies and like this bit shouldn't talk to this bit and whatever.
Like, they do do that now.
Like I think earlier iterations didn't, but they do that now.
I don't think that's a fair criticism, if I'm honest.
Yeah, no, it's just more, I guess, the way of thinking.
Having glue between, you know, virtual network layers and things like that isn't simple.
And the Jericho era zero trustee thing is, you know, one of the guiding principles is like, keep it simple.
You know, you should be able to see what's happening and understand.
It should be simple and resilient.
and then as soon as you got all these things that rely on certain pieces.
It gets a bit opaque.
I see what you mean now.
Yeah.
Yeah.
Well, and speaking of that, right, one of the big ZTNA, you know, cloud ZT&A companies,
we won't mention the name, but you play nice with them because there's been these hilarious
situations where right now there is a real sense of urgency out there, right?
People are just desperately trying to get stuff off the internet.
They're desperately trying to lock down their internal networks as well because they understand
that AI enabled lateral movement is fast, right?
So you need to put in some controls now.
So, you know, that's, you know, being great for Knock Knock's business,
but it's also been great for some of these ZTNA companies.
But the funny thing is, there's been some unintended side effects.
When people go in, they do this huge ZTNA project,
and then they're like, oh, now we can't admin these boxes over here
because we've ZTNA'd everything,
and it's not compatible with the way that we were adminning them.
And the interesting thing there is you've gone in, solved that problem with Knock Knock,
and then the ZTNA company has come along and said,
oh, how would you like to come in on some other deals?
Right?
And this is just validation of what I was saying before,
which is I think so many of the zero trusty sort of companies,
you know, there's an ideological purity that doesn't match the real world,
which is, well, hang on, you know, it's good to use this stuff,
but we're still going to need access over here that is,
through this CETNA product.
Yeah, there's the kind of ideal design,
and then when you apply it to a real world network,
it's like, okay, these are all the exclusions,
here's all the workarounds,
these are the things we have to open up
because we locked everything down so hard
that now actually we can't use it.
So rethinking the design in a greyfield's existing environment's too hard, right?
So you have to accommodate
how those environments networks actually operate,
how the business and the humans operate in that.
So, yeah, it's, to your point earlier,
nobody has solved the kind of zero trust everywhere,
everything just magically works in one technology.
Because it's not realistic.
I mean, that's the whole point, right?
It's just not realistic to think that you can do that for everything,
unless you Google.
And even then, I reckon if you hit up the right part of Google's internal network
with NMAP, you're still going to find some gnarly stuff, I reckon.
Well, hitting it up with NMap, I mean, I guess
The brave thing to do would be if Google came out and said, we let a bunch of AI just go wild
internally and guess what it didn't get anywhere? That's the ultimate test. I can't imagine
that would be very irresponsible to do, of course, but it's kind of the driver, as you said,
people are coming to Knock Knock, not coming to ZTNA providers saying the AI thing is here, everything's
lateral movement happens automatically and all those sorts of things. What do we do? We need to control,
We need to hide things.
We need to segment them.
We need to do that fast, though.
We can't do a big, long project to re-architect everything.
And, you know, that's where Knock Knock comes in and does a great job of that.
These three Windows machines, I don't want them always on, always exposed.
Easy. Put Knock, knock, done.
You know, that's taken care of.
Yeah.
Yeah.
Well, this is where we're going to introduce a concept here, which is zero trust-ish.
Right?
Because I think for typical, typical.
enterprise environments, right? Like a lot of them, the networks, once you get inside, they're pretty flat. Like even the ones that aren't completely flat are pretty flat. So you've got option, like you can do a whole network re-architecture, micro segment everything and try to put all of these controls in place. But I think what we're seeing and where Knock Knock is really getting some runs on the board is people come to you and they're like, we've got this flat horror show network. We've identified the 150 riskiest.
assets on it. We want to put knock-knock agents on those assets to seal them off from the rest of
the network. So they're almost treating, you know, they're almost treating their land as the internet
like it's a hostile place and just trying to zero-trust certain things instead of trying to
zero-trust all the things. And as I say, this is why I'm kind of calling it zero-trust-ish networks,
right? Where you're applying zero-trust where you can. You're applying zero-trust principles to the
riskiest stuff, but you're not doing it to everything because it's too hard and you probably
don't need to anyway. Yeah, yeah. And that is the kind of concept around zero trust really is
risk-based, what's the riskiest thing? Let's reduce the attack surface. Let's reduce the exposure.
And it's meaningful. It makes a meaningful difference. It's easy to do. It's not complicated.
They don't need to redesign. And they get wins. And like treating the internal network as the
internet, hostile, external network, like you said earlier, like it's about time.
And the AI, you know, thread is driving that, of course.
But see, zero trust, zero trust says that you treat every asset,
every network connected asset as if it's connected to the internet, right?
And fair enough, but that's hard work, right?
So I think what they're doing is they're like, okay, well,
these things over here can probably get owned.
Like, that's okay.
We can limit the blast radius of that if we are, you know,
paying enough attention and detecting and whatever.
But these things over here, if they get popped, it's the end of the world.
So that's where we're going to, you know, apply those principles.
Yeah, which again, like the zero trust issue nails it because assume bridge, you know, all of the things is like, well, if we assume bridge, these things we actually care about if they're breach, these things over here, you know, lower priority, low, you know, lower impact overall. Let's just close the, you know, close these issues over here and get that out now instead of waiting.
Yeah, if these things over here get owned, it's not existential, right? And this is funny because a while ago you guys released like a proper Windows agent. So now you can tie.
your Windows firewalls to like SSO events, right? So user Patrick at Risky.
not biz tries to access RDP ports or whatever ports on a Windows box on the
land. It just says connection closed, connection refused. I go hit a web app, say open up
that port please and then the agent on that Windows machine will open up that port to
my IP for a set amount of time like say 20 minutes or you know specified by user.
What's interesting here is like is the initial sort of batch of customers for
knock knock are very much around that instrumenting Palo Alto networks and fortinette and checkpoint and
you know all of those sort of big old school firewalls whereas when you released this
Windows agent which is Go based by the way just very modern very modern means it only works so far back
though so you know good luck running that on your Windows 2000 servers but but you release that and I remember
saying to you man there are going to be customers who come along who only want that that's actually
happened. You've had a couple customers who've got these real Windows server heavy internal
environments who've just come along and they're like, yoink, yes, please, we need them yesterday.
Can you help us install them? Yeah. Yeah, it's exactly that. We've got these Windows machines.
We want to hide them. How can we easily do that? Oh, knock, knock. Okay, done. And then they're
looking at, okay, I've also got a power oil. They're looking at this to kind of do both sides.
But, yeah, I think the captive portal for your land is another way of thinking.
about it. Like, I can't get to any of those, I can't see any of those machines. Those Windows
RPP things just aren't there. I have to go to Captive Portal, you know, single sign and whatever,
and then suddenly I can connect to those Windows machines internally, which is, it's pretty simple.
And, you know, the elegance of Knock Knock is that, you know, we don't sit in line,
there's other benefits around the architecture and the threat model. But that's the experience
for people. I used to be able to just see everything and attack everything. And now I just go to
the simple website. And then I now I can go to those.
machines, simple, but super effective. And the Windows, you know, people that have those systems
that want to hide them, it's, yeah, they love it. It's great. It's great. Well, and I will say now,
and this, we might have to edit out if we haven't announced by the time this goes out in a couple
of weeks, but, you know, Knock Knock is succeeding, right? And as a result of that, there's been
another capital raise, proper seed round this time, because it was like, you know, previously,
you're only at a pre-seed round. And, you know, slowly, slowly, then quickly, quickly,
What's been interesting, though, and one of the things that's underpinned this latest capital raise is the variety of organizations that are using Knock Knock, right?
So with a lot of startups, you tend to see success in one vertical or another.
With Knock Knock, what's really interesting is you're seeing, as you say, there's these customers who've got like, oh, man, we've got all these Windows boxes.
We need to take care of them.
There's a global farmer that is using Knock Knock on its big firewalls at the edge.
there are banks, there are hedge funds,
it's just all sorts of organisators,
even small SMEs.
That's what's been really interesting here
is every customer seems to be
from a different vertical
and they all have different use cases.
But it's all using zero trust principles
in non-zero trust networks.
In networks you would not describe
as zero-trust networks.
Universities are a great example though
because they are so good for Knock-Nock
because they have these absolutely
gigantic flat networks full of hostile students. It's so funny. Yeah. Yeah, the university is like the
real testing ground because you've got an open environment. You're aiming for open. You're aiming for,
you know, knowledge. But with that comes complexity. And yeah, I think the reason we're in all
these environments in different industries is because people have said, I have the same, they've just
got the same problem, you know? Like, I want to remove a tax surface, whether it's critical
infrastructure, university, whatever. It's the same thing. I want to reduce my problems. You have
a solution to the problem. Let's deploy. Yeah, but it's a different problem. I mean, it's the same
problem, but it's different. It's like, I want to reduce my exposure. Yes. Right. But it could be
a Windows box running a remote management tool. Like, it could have VNC on it. And it needs VNC on it
because it's some weird ICS thing that they bought 25 years ago, right? It's like, what do we do? What do
with that. So you can do it there. You might use knock knock because you need MFA on a box on your
network to meet some compliance requirement. And knock knock is a way to actually apply
MFA to that thing. You might want to restrict a OT or ICS jump box. Right. It's a way to do that.
But the point is it's all about reducing exposure, reducing network access to risky assets. But
what people are doing with that, like which assets it is. It's like a all the colors of the rainbow,
which is fantastic. It's what you want when you're running a startup. Yeah, absolutely. I think that
comes down to architecture and the approach of taking, which is you can't install a Windows
agent on some ancient, you know, fancy delivered HMI-ish thing, but because Knock Knock can talk to
the firewall that's between the user and that thing, we solve that problem. Or it's a Windows
RDP environment, which we can run on that solves that. Or they've got a pallor on the edge,
and they want to remove some other exposure that they've got there. So they'll look at knock-knock,
and they're like, okay, proper Swiss Army knife, V&C, I can hide that thing by doing this,
and then I can hide my Windows machine by doing that. And it's just easy, right? Which is why
people have, once I understand how it works, then they just like, oh, I can put it there,
I can put it there. And it's just removes the attack surface. It does a simple thing,
does it really well and yeah it ends up going in different parts of the business and solving
different problems which we love because it's it's we get the genuine excitement in in customers
when they're like oh i can put it over here and solve this thing that i haven't been able to
solve before we've all just kind of you know put it on the risk register and assumed that that vnc
thing is just a problem but until now i haven't really been able to do anything about it so this is
this is an alternative to the risk accepted stamp right which is nice yeah
But look, you and I kicking around the idea for this conversation the last couple of days,
we think we're pretty profound by coming up with something that I think most CISOs know,
which is when it comes to zero trust, I think this is where we've landed.
You cannot be ideological about it.
You know, you have to be pragmatic.
You just have to do it where you can with the tools that make sense.
And I think that's where we are, right?
And that's why it's working.
That's why it's working.
That's why people are buying it, which I'm so happy about.
because regular listeners would know that, you know, I certainly have had a hand in helping this business come out to the market.
You know, I've been just thrilled to be a part of this story so far, and it's just so immensely satisfying seeing people actually buy it.
Well, yeah, I agree with that, but I actually really get a lot of, I get a kick out of just seeing it be deployed.
And when people like, you know, I had all this complication and I was trying to work out how to do this.
And then with Knock Knock I can just remove, like just remove the problem.
Like remove the risk, remove the asset.
It's just so simple.
Well, and then there's, you know, what's really funny is there's all these startups that
try to work on their land and expand, right?
They try to work on their land and expand strategy.
And ultimately, man, you don't need a strategy for land and expand.
What you need is a good product.
And that's what happens with Knock Knock is people will buy 20 licenses because they've got
these like mega risky, like absolutely horror show bits of equipment or applications.
they just get a very limited set of licenses.
They roll it out.
It takes a day.
And then they come back and they ask you to quote for like 4,000 licenses,
which is kind of how it goes, right?
Like, it's incredible.
Yeah.
The really nice one is when it's like the CSO's office and then like the networking team
come across.
And then it's like the other, you know, we vibe coded this thing.
Can you also talk to these guys over here and work out how we can solve that problem?
So it depends on the organization's side, but different size,
different people within the business.
coming to us saying, hey, we heard that they bought a thing and it solves their problem.
Can you explain how it kind of solves ours over here?
So, yeah, it's, when you have a good product, a good experience, it actually works, it actually
does the thing.
It's sad that that's the reason why people get a lot of growth and a lot of adoption, but
that's just, that's the reality.
And I love being in that space at the moment, yeah.
Yeah, well, I mean, I think, you know, it was very easy to know that Knock Knock was a winner
when early conversations
was you'd explain people
to people what it does
and they're like,
huh,
nobody's done that yet.
And it's like,
that's a good idea
because it's fundamental,
it's very simple.
And it enables zero trust principles
in zero trust-ish networks.
And on that note,
Adam Pointon,
we're going to wrap it up,
mate.
Lovely to see you.
Lovely to catch up.
Lovely to have this conversation.
I wish you all a success with this,
obviously.
And I'll see you.
see you at the next board meeting. It's a bit of a different sort of sponsorship arrangement
this one. But yeah, I'll catch you soon, pal. Thanks for the, thanks for the chat.
Thanks, Patrick. Great to be here.
