The Great Inversion: When Zero Trust Finally Reaches the Data | Booz Allen + Virtru
Virtru and Booz Allen break down how Zero Trust Data Exchange is securing the mission in an AI-driven threat landscape.
AI has made one thing undeniable: building walls around systems isn't enough anymore.
Virtru's Angel Smith (President, Global Public Sector) sits down with Booz Allen's Kelly Rozumalski (EVP, National Cyber) and Imran Umar (SVP, Defense Cyber Operations) to talk about why the future of security follows the data — not the perimeter.
They cover real-world federal deployments, AI-driven threats, and how Zero Trust Data Exchange (ZTDX) is already changing the mission.
Read transcript Hide transcript
Kelly Rozumalski: It's a great question. AI is creating a ton of new ways to connect data. At the end of the day, as data and information moves, unfortunately, sometimes the controls that are governing the AI don't move with it. We really need to make sure that we have capabilities that are protecting our data at all the points. Query, data generation, data storage, all of those points. That's exactly why Booz Allen, in partnership with Virtru, developed the Zero Trust Data Exchange capability. Imran, do you want to talk a little bit about that?
Imran Umar: Yeah. Listen, data security was the biggest challenge that each organization faces. When you start implementing your zero trust security, you can implement the users pillar, the device pillar, and the network pillar. But when it comes to data security, it's always been the challenge. AI has made that so much more challenging, exponentially. We knew that our customers were looking for a very robust solution that allows them to do things like data discovery, data tagging, and encryption in a standardized format. The Virtru solution made perfect sense for Booz Allen. Combined with our customer knowledge and domain knowledge, partnering with Virtru, we have built this capability called Zero Trust Data Exchange that we are deploying for multiple federal customers today.
Angel Smith: A follow-on question to that one. A lot of government customers really do have a difficult time keeping pace with the security threats that are coming in. They just have a persistent, nonstop pummeling of cybersecurity threats coming at them. If we were to think about zero trust from a perspective of always assuming you've got an adversary or someone that's in the network that's not supposed to be, what are some of the impacts to the mission that we think we would see in either one of those scenarios?
Kelly Rozumalski: Well, I think first, you're 100% right. In the world that we live in right now, advanced threat actors are leveraging AI-driven, agent-based approaches, and the result of that is attack timelines are decreasing from months and weeks, to hours, and now to minutes. As defenders, we need to accelerate the implementation of zero trust. We need to really fight AI with AI, and we also need to have the ability to test our controls against AI attacks. Things like persistent data control really help with that because it accelerates enforcement and decreases attack surfaces. The most important thing with persistent data control is that, at the end of the day, it really helps limit who has access to sensitive data, and most importantly, it's doing that on a continuous basis.
Imran Umar: Yeah, Kelly, you touched on it. Essentially, we're seeing people using artificial intelligence to basically turn vulnerabilities into campaigns, and they are using that to continuously attack customers. You need advanced zero trust capabilities to put in place mechanisms to slow down your adversary, to prevent and block your adversary. I think zero trust controls are just a lot more important now, especially with the threat of AI autonomous attacks.
Angel Smith: Absolutely. To expand on that concept, when you think about the pivot towards a more data-centric zero trust approach, you start to realize that you have the ability to add policy that travels with the entire lifecycle of the data. When you think about that new perspective, knowing it's more difficult, to me, it's a game changer. What are some of the ways you're starting to see with your customer base how that actually changes the mission space dramatically? It's a pivot away from—Imran, I've heard you talk about the front door. If you stop thinking about the front door as the only access point and start to think about the security of the data layer, what does that look like for the mission user?
Imran Umar: The data moves with individuals and moves with the organization, so it's not static. It's not behind some perimeter. The biggest concern that customers have is how to protect that data. AI models are hungry for data. They want to go and get access to your data to train their models on it. How do you protect that? I think the capabilities of Zero Trust Data Exchange provide that security layer on your data. No matter where your data moves, it is encrypted, and only the people that are authorized based on their credential and their identity are able to access that data. Zero Trust Data Exchange provides that data security layer against traditional threats and modern AI-based threats.
Angel Smith: It seems like by adopting this approach, you also start to simplify some of the problems that we've been crippled by a little bit. Interoperability between nations, interoperability between primes and subcontractors, it's a completely different perspective on how you look at our ability to communicate between places like the IC to DoD. The ground starts to become incredibly fertile whenever you start to think about that pivot.
Imran Umar: There are different types of data use cases for us. Some customers are worried about collaboration, emails, and Word documents. But there are certain customers that are interested in protecting C2 data. One of the big use cases we are seeing is how we engage with mission partners. When we talk about sharing data with mission partners, let's just say we're sharing some kind of a C2 feed with them. Traditionally, we have built net-centric networks for each mission partner. So if you are talking to a partner like Japan, for example, we are building a very network-centric architecture that allows us to communicate with them and share data with them. But that's no longer necessary as a new paradigm. As long as we can take the data, encrypt it with Virtru, and package that data in a way that only authorized users are able to see it, that's a big game changer. Now you can actually share data at the speed of the mission and still provide the protection and security that is necessary.
Angel Smith: So, Imran, pull the thread on that a little bit. I know you've done a lot of ZTDX deployments already, and there have been some meaningful challenges, probably because this is a new perspective and a new way of doing business. Can you talk us through a couple of the challenges and maybe some of the obstacles you've been able to overcome with the customer?
Imran Umar: I think there are both technical challenges and cultural challenges. From a technical perspective, the big concern is around who owns that data. Multiple customers have different types of data. Where is the data stored? How are you going to tag that data to some kind of a common standard? How are you going to label that data? And then there are cultural changes because people are not used to that kind of environment. They are used to being able to share files without providing the right tags and without doing proper encryption. It's a combination of both technical and cultural challenges that we are seeing customers have to overcome.
Angel Smith: I'm going to take it in a little bit of a different direction now to talk about AI and the emergence of AI in the mission space. There's a classic garbage in, garbage out scenario. What are some of the ways, at least from the vision that you see for your product suite that's coming out, that ZTDX can possibly help in an AI world by making sure that the outputs are incredibly secure based off of whatever data is actually feeding it?
Imran Umar: I can start. I mentioned this earlier. Step one is people want to just protect their data because they don't want random frontier models or any kind of open-weight, open-source models coming in and absorbing your data. So step number one is, how do we protect that data? If you encrypt your file using something like ZTDX, you can then ensure that only the AI model or the AI agent that you want to make that data available to is going to be able to absorb it. That's providing protection. Number two is, let's just say you're using AI and you have a RAG pipeline that's feeding into your AI ecosystem. How do you ensure that that data pipeline is secure? How do you ensure that the information your AI model is getting is from an authoritative source? This is where ZTDX becomes extremely powerful.
Kelly Rozumalski: I think the other piece too is making sure that there's integrity and accuracy around the data and that it's trusted. At the end of the day, what ZTDX allows us to do is ensure that trust and integrity exists, and then we're able to make faster, better, more credible decisions.
Angel Smith: We were at a conference recently, and there was actually a nation talking about on-orbit satellites that were providing data that they couldn't validate as trustful data because of spoofing from adversaries. I'm constantly thinking about the fact that in some ways, what ZTDX gives in return for some of this is actually trust.
Kelly Rozumalski: At the edge and across the enterprise, it's important in both states.
Angel Smith: For sure. Well, I would say Virtru on our side is ridiculously excited about the partnership with Booz Allen, and we're already seeing massive impacts with how we can go to customers together and really bring immediate mission value to them. Is there anything about the excitement of working with Virtru, pat us on the back. We really love working with you and love to hear you talk.
Kelly Rozumalski: The partnership has only started. We're incredibly excited. We've already developed best-in-class tech for some of our customers' most critical missions. The fact that we're securing some of the most sensitive data, and we're doing it anywhere at all times, is really important. We're incredibly excited and really value the partnership that we have with Virtru.
Imran Umar: 100%. I like our partnership, and I like the fact that we are integrating you into our tech stack that Booz Allen is building. We're taking that tech stack across our commercial customers. We're taking it across our Intel customers, our DoD, and federal civilian customers. The technology that we're building is repeatable and scalable across multiple different client spaces.
Angel Smith: I think the one big takeaway from working with Booz Allen is that this has seemed like a very scary space entering into AI, and the sanctity of the data continuously comes into question. But working with Booz Allen, I think we see a really positive light at the end of the tunnel, and we see a way where we can have a differentiator as a nation. Thank you so much for the partnership.
Kelly Rozumalski: Thanks, Angel.
Related Resources
Get expert insights on how to address your data protection challenges
/video%20-%20booz%20allen%20billington/Virtru%20+%20Booz%20Allen.webp)
The Great Inversion: When Zero Trust Finally Reaches the Data | Booz Allen + Virtru

Virtru Platform Demo: ABAC for Outlook, SharePoint, and Beyond

Zero Trust File Sharing with the Virtru Platform

The Virtru Platform: Extensible Security and SDKs for Mission Apps

How It Works: Virtru Collaborate

Virtru Collaborate: Eliminate the Tradeoff Between Compliance and Collaboration

Introducing Virtru Collaborate

Virtru Collaborate: Securely Store, Organize, and Share Sensitive Files

Google E2EE vs. Virtru for Gmail: Sender and Recipient Experience

Virtru Data Security Platform: Email Workflows

How to Use Virtru for Gmail

Virtru Secure Share for Microsoft OneDrive, SharePoint, and Teams
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.