THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, September 01, 2023
The adoption of zero trust continues to rise as organizations recognize its potential to address evolving security threats and safeguard critical assets.
FREMONT, CA: Zero trust has become a prominent trend among security leaders, with most organizations already implementing or planning to adopt this security strategy. According to a report, 97 percent of surveyed organizations either have a zero-trust initiative in place or intend to do so within the next 18 months.
Organizations that already have zero trust in place have more than doubled in just one year, rising from 24 percent to 55 percent in 2022, which is an impressive increase. This 55 percent is over three times the figure four years ago, indicating a significant increase in zero trust adoption. This surge in zero trust adoption reflects the escalating security challenges enterprises face. The expanding attack surfaces, especially due to widescale remote work policies and the growing number of endpoint devices operating outside corporate walls, have made traditional perimeter defenses inadequate. Cyberattacks have also increased in both volume and velocity, making organizations need to rethink their security strategies.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The conventional security model relied on perimeter defenses, akin to building a moat around a castle to ward off external threats while granting unrestricted movement to entities within. However, this model assumed that users and devices within the corporate environment could be trusted, overlooking the potential for insider threats and malicious actors to infiltrate and disguise themselves as trusted entities. The traditional perimeter concept became obsolete with the advent of 21st-century IT architecture, characterized by cloud computing and many devices that require remote access to enterprise systems. Consequently, security leaders began pivoting their strategies, moving away from perimeter-centric approaches and embracing controls like data-level authentication and encryption to secure assets more effectively.
Security strategies that rely on zero trust involve trusting no one and nothing and verifying everything. Also known as the zero-trust security model or the zero-trust framework, this approach designs and implements a security program that assumes no user, device, or agent should be implicitly trusted. Instead, any entity seeking access to corporate assets must prove its trustworthiness. Zero trust encompasses a combination of policies, procedures, and technologies. Organizations aiming for zero-trust must have an accurate inventory of assets, including data, users, and devices. Additionally, a robust data classification program with privileged access management is essential. Zero trust also includes comprehensive identity management, application-level access control, and microsegmentation.
A crucial element of UEBA is distinguishing normal and trusted behaviors from abnormal ones that should be denied access using automation and intelligence. Multifactor authentication capabilities, network detection and response tools, and endpoint detection and response solutions play a role in zero trust. However, the multitude of policies, procedures, and technologies required for zero trust can pose challenges for many organizations. Legacy technology is often a significant barrier, as older systems may not be compatible or capable of supporting zero-trust security measures.
Financial constraints and resistance to change are also obstacles to successful implementation. Organizations cannot afford to replace all existing security technologies and modernize legacy systems simultaneously, nor can they swiftly transition workers to new policies and procedures. Many investments have been made over the years, and discarding them all at once is not feasible. By embracing zero trust and overcoming the hurdles, organizations can establish a robust and adaptive security posture for a rapidly changing threat landscape.
More in News