enterprisesecuritymag

NOVEMBER 2024ENTERPRISE SECURITY| | 19ZERO-TRUST: IS YOUR COMPANY READY?By Ben Schoenecker, Director of Information Security, Hendrick Automotive GroupCompanies are quickly adopting the Zero-Trust security model. Leaders are inundated with marketing hype around Zero-Trust, and it can be difficult to understand what is real, and what isn't. With hybrid and remote workforces becoming the new norm, companies have started embracing Zero-Trust at a faster rate. The White House even stated the importance of Zero-Trust in the "Executive Order on Improving the Nation's Cybersecurity", in May of 2021. A recent market research exercise conducted by The Demo Forum, found that there are now nearly 300 different vendors offering Zero-Trust security solutions. Why should your company consider adopting Zero-Trust and how can you properly communicate the benefits to your boards and stakeholders?Let us first demystify the term: Zero-Trust is not so much a product, as it is a mindset or paradigm that describes objectives and outcomes. Tools and products that claim to be Zero-Trust can help you evolve in ways to meet these objectives. But what's involved in developing a Zero-Trust strategy?One of the core principles of Zero-Trust is removing the implicit trust that we have within our IT environments. As we design our networks, we have evolved throughout the years as security professionals to think that "outside is bad", and "inside is safe". We protect our networks with firewalls to keep the bad guys out, and we usually assume that if something gets in that we don't want, we have a breach of security. The Zero-Trust mindset removes this way Ben SchoeneckerCXO INSIGHTS
< Page 9 | Page 11 >