When it comes to zero trust, many organizations start the journey yet struggle to complete it. Here, security expert Dan Raywood identifies the most important next steps you need to take.
The concept of zero trust was born from the knowledge that perimeter security, no matter how sophisticated, cannot keep out every bad actor. As soon as you assume your security will be breached, trust is no longer implicitly conferred. Instead, identities must be continuously verified whilst granting least-access privileges.
John Kindervag, then an analyst with Forrester, claimed in his initial 2010 white paper that network professionals “built yesterday’s networks at the edge, with the internet connection, and then built inward” with the starting point of the router and routing protocols. Almost a decade later in a 2018 interview, he admitted that zero trust is “still at the baby stages” and he was still trying to get people to take on the idea, but once they grasp it “the idea sells itself.”
Some seven years on, zero trust has evolved into a series of principles and a strategic architectural framework. In times of increasingly sophisticated attackers who have an eye on maintaining a presence in your network, as well as a dispersed workforce, the concept of “trust nothing implicitly, verify everything” is the best option.
Treat with suspicion
As HPE says, zero trust is an security strategy that treats every user, device, and network flow with suspicion, regardless of its location relative to the perimeter.
Speaking to TechFinitive, Forrester Senior Analyst Tope Olufon says that there is too much hype around zero trust, which causes confusion for buyers. “The principle is valid, but hype makes it harder for CISOs to know what will actually reduce risk,” he told us.
Olufon was positive on how zero trust reduces reliance on logins and VPNs, as “when implemented properly it streamlines access.”
Is it clear what technologies are involved in deploying a zero trust strategy? “It’s clear at a control level: strong identity, device checks, segmentation, data controls, and monitoring,” said Olufon. “What’s not clear is which vendors to use since it is not a single tool or technology.”
Steps for implementation
Which steps are required for a zero trust strategy to be implemented? Perhaps the first one is to take a phased approach. Zero trust implementation shouldn’t be a complex, network-wide overhaul. Instead, it’s a targeted approach that should reduce complexity – and yield tangible security improvements.
“Ideally, you should be able to answer a few questions of every user or device on your network,” said Jon Green, Chief Technology Officer and Chief Security Officer, HPE Aruba Networking, Hewlett Packard Enterprise. “Who are you? What should you be allowed to do on this network? And how can I enforce that through policy control?”
Those are big questions, but HPE’s guide to zero trust listed these initial steps:
Identify all devices, including IoT and remove devices, by discovering and profiling all devices using ML algorithms
Eliminate network blind spots using same methods
Verify identity using Identity and Access Management (IAM) services, as well as emerging AI-powered techniques for IoT devices.
Compare endpoint configuration to compliance baselines and remediate as needed.
Establish least-privilege access to IT resources by segmenting traffic based on identity-based policies and reduce the attack surface.
Secure access to SaaS and the internet using SASE, to protect sensitive data and users from malicious activities on the web.
Continuously monitor the security state of the user and device, and bi-directionally communicate with other elements in the security ecosystem. Establish policies to revoke a user or device’s access rights in cases of compromise or attack.
According to Hiscox’s 2024 Cyber Readiness Report, two-thirds of firms plan to implement a zero trust architecture by 2030, as interest in zero trust increases by 11% year on year.
In a LinkedIn poll I asked what the reasons were for not deploying a zero trust strategy. The majority cited cost, with Dre Johnson, Head of Technology Services at 40fi, stating that most places he has worked like the concept of zero trust, and would like to deploy, but the roadmap can be a long one with an endgame that isn’t always visible.
“I think if you’re going to deploy it, it’s a commitment especially if you hold a lot of legacy because you need some pre-requisites in place, especially if you’ve got a risks list as long as your arm,” he said.
“Implementing it closes a lot of holes, but not always as quickly. Most companies I deal with (and they’re not hugely mature) will focus in on base level security fixes to reduce their risk profile before they deploy a zero trust strategy.”
Johnson also says that the deployment of zero trust can be a hard sell to the wider business, and CISOs are usually keen, “but normally the guy screaming about zero trust is the head of IT, who reports into a Director who isn’t necessarily up to speed on it.”
When assessing an ability to adopt zero trust, the steps for implementation are worth considering as much as the business’s need for it. If you’re pitching the idea to a CISO or a head of IT, consider the business benefits from having a zero trust strategy: a reduced attack surface, better visibility of risks, and better support of remote and hybrid working environments.
Zero Trust is now essential for securing all users and devices across remote, branch, campus, and data-center environments, including third parties, unmanaged IoT and BYOD – far beyond just remote access.
This paper explains the evolution of ZTNA and universal ZTNA, outlines two pathways for expanding Zero Trust from edge to cloud, and introduces HPE’s edge-to-cloud Zero Trust platform that unifies single-vendor SASE with advanced network access control.
Challenging steps to zero trust
The steps to implement zero trust can be challenging. Paul Holland, Security Leader and former Head of Research at the ISF, says that some elements will require effort but that the basis of implementing zero trust boils down to getting the core basics right for cybersecurity as a whole. He places particular emphasis on identity and asset management.
“The fact we have known these are important as an industry for years and we still have not got it right shows that it must be challenging,” he said.
What are his recommendations on the first steps to take? “You need to completely rethink how you architect your environment; we have traditionally taken an ‘outside in’ approach – start at the perimeter with firewalls and then work your way into the middle,” Holland explained. “With zero trust you have to start at that central point, determine which are the smallest elements – your resources and data – and protect those first, and work your way outwards adding in the other elements of your security arsenal.”
For those companies who are more mature – perhaps they have already rolled out MFA, perhaps they have deployed firewalls and SASE – we asked if there was a “short hop” to achieving zero trust? His short answer is no, that it is a large scale change to environments and thinking, but there is good news.
“You do not have to go into a full implementation, in my opinion, if you focus on the data and systems you want to protect and restrict access to those with the least privilege principles, and segment the network into discrete areas then you put yourself in a position where your security posture will be pretty strong,” he said. “It will be resilient against so many threats like that, without going full zero trust.”
And it’s worth emphasizing that the options to adopt zero trust far outweigh the reasons not to. As well as the benefits for risk reduction and a more secure workforce, there are also benefits for better data protection and compliance.
Asked if he feels that zero trust is the best action to take to be more secure, Holland says that using zero trust logic is a very good approach to security, as you will be working on the key assets within your organization and adding the appropriate level of security against each.
“That said you still need to do effective implementation, updates and monitoring to make sure that what you have done stays relevant, effective, useful and is accurate for the business needs,” he added.
Whilst not a new concept, zero trust has escaped the overcoat of hype to become the best strategy to secure a business in these times of external connections and operations, and attacks.
Dan Raywood
Dan Raywood has spent 25 years in B2B journalism, covering areas as wide as minicabs, garment decoration, mortgages and cybersecurity. As a cybersecurity journalist he covered IT and information security for SC Magazine, IT Security Guru and Infosecurity Magazine.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.