THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Jeffrey W Brown, Chief Information Security Officer, State of ConnecticutThe COVID-19 pandemic spurred many organizations to close offices and move employees into remote work arrangements. Now, organizations are evaluating whether to stay in hybrid or even completely remote models. Big companies like JP Morgan and Apple are finding it hard to get their employees back to the office full time. No matter which way this drama plays out, the concept of remote work will be the preferred mode for many employees now and into the future, and companies will need to adapt to the fact that commuting to an office may be a dated concept.
Regardless of how you feel about remote work, our job as security and risk management leaders is to ensure we secure this remote workforce. This involves rethinking how we handle security controls in a world of cloud computing, always on network access and data stored seemingly everywhere. The concept of perimeter-based security, which was already on tenuous ground, is now completely upside down. This means our security approach needs to get worker identity correct and make sure we are securing company data no matter where it resides. To address these complexities, many people are turning to the principles of zero trust.
I'm not a fan of the term zero trust, which was first coined by Forrester. It’s becoming yet another marketing term, but I also find it a bitmisleading. Everything we do requires some level of trust. We trust that our hardware and software providers are selling secure solutions, even though companies like Huawei, Kaspersky and Lenovo are suspected of not doing so. We trust that the security solutions we deploy don't have backdoors, even though SolarWinds has shown us that this isn't always the case. While eliminating all trust isn’t practical, you can see how leaning on a simple username/password isn’t enough either. So don’t think of zero trust as a way of eliminating trust issues, but as a framework that requires users to first be authenticated, authorized and validated before granting access only to what they need to do their job. It turns out that this is exactly the framework we need to secure the remote workforce.
"The Concept Of Perimeter-Based Security, Which Was Already On Tenuous Ground, Is Now Completely Upside Down. This Means Our Security Approach Needs To Get Worker Identity Correct And Make Sure We Are Securing Company Data No Matter Where It Resides"
If you don't know where to start on the zero trust journey, start by ensuring all your users have multifactor authentication (MFA) enabled. While not perfect, MFA can make it much harder for attackers to compromise our systems and data. While home workers do represent an increased security risk, we shouldn't assume that just because an employee is physically on site that we should trust what they do or even that they are who they say they are. Malicious insiders, dormant attackers and compromised credentials have always been real threats. In a zero trust model, we assume that everyone and everything is untrusted. This means you should also have enough control over the endpoint and thatEndpoint Detection and Response (EDR) should also be high on your list of controls to consider.
Once users are authenticated, they should only be granted the minimum level of access needed to perform their job function. Role-based access controls can help ensure that users only have access to the data and systems they need to do their jobs, as can micro-segmentation or software-defined perimeters. These are not easy solutions to deploy though and will take time and a well thought out Zero Trust Architecture (ZTA). This also comes with potential end user friction and complaints. New security controls need to be balanced with business requirements, your corporate culture and your risk tolerance. A zero trust model shouldn’t push security for the sake of security but should be aligned with the business value provided.
You can also consider a Security Services Edge (SSE)solution, which makes zero trust simpler to deploy and manage. SSE allows IT to avoid complex network-security architectures, removing the convoluted connections between appliances and users, while providing the highest security through a cloud-delivered model. This is a big advantage over the VPN to the network model many of us are using right now. In fact, many remote users are finding it undesirable to use VPN. Forcing alltraffic through the corporate network, where it can be monitored and filtered, is also introducing major downstream video latency on Teams and Zoom calls. Split tunneling, a longtime pariah in the security industry, seems like a less-than-satisfactory solution to this problem. Others are acknowledging that allowing access straight into the Microsoft, Google or AWS clouds almost eliminates the need for a corporate VPN entirely. Zero Trust makes this last option viable.
Don’t forget that aZero Trust framework also includes elements like systems inventory, secure communications and a security policy that will be enforced throughout the enterprise. This means that policies for remote work and employee security awareness training are also critical components to address. Make sure your zero trust journey factors in people and process, not just software. Train your employees to spot phishing emails, recognize social engineering attacks and report security risks.
There is no perfect trust; we can only limit our trust based on our increasing security risks. Zero trust requires a multifaceted approach using technology, education and policies. Zero trust has the promise of increasing our overall resiliency and adaptability and also enabling our employees to do their best work, regardless of their location.