enterprisesecuritymag

Why Zero Trust is the Future of Endpoint Security

Enterprise Security Magazine | Monday, December 04, 2023

Zero trust, by definition, requires multiple technologies and process elements and demands scale of data analysis and speed of execution to stop modern attacks.

FREMONT, CA: The majority of organisations are unaware of the number of endpoints that are actively using their networks as their tech stacks were created to excel at the idea of trust but verify rather than zero trust. They are becoming less aware of the number of human and machine-based endpoints they actually possess.

Attack surface protection evangelist at CyCognito, enterprises frequently produce thousands of unidentified endpoints yearly. Additionally, according to a Cybersecurity Insiders research, only 58 per cent of firms claim to be able to identify every vulnerable asset within their organisation within 24 hours of a critical exploit, and 60 per cent of enterprises are unaware of less than 75 per cent of the devices on their network. 75 per cent or more endpoint attacks won't be stopped. Currently, the average organisation manages over 135,000 endpoint devices, of which 48 per cent, or 64,800 endpoints, are invisible on their networks.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

According to a recent Ponemon Institute survey sponsored by Adaptiva, businesses spend an average of USD 4.2 million annually on endpoint security. The number of endpoints on a given enterprise's network that are known and secured is decreasing even as endpoint spending rises.

Zero Trust is the Future of Endpoint Security

Zero trust, by definition, calls on various technologies and process factors, as well as a large scale of data analysis and quick execution to thwart contemporary threats. Most CISOs seek a platform approach as they strive to consolidate security suppliers. In a standards-based, integrated paradigm, a platform strategy provides seamless execution to zero-trust deployment and leverages an enterprise's existing investments.

The future of endpoint security is zero trust since it addresses the following five issues:

Ransomware is Endpoint Security’s Most Persistent Threat

The prevalence of ransomware has grown by 466 per cent in the last three years. The vulnerabilities that most frequently result in ransomware attacks are identified in Ivanti's Ransomware Index Report Q2-Q3 2022, along with the speed at which undiscovered ransomware criminals move to seize control of an entire business. There are now 170 different ransomware families. The analysis is based on 154,790 vulnerabilities from the National Vulnerability Database (NVD).

Furthermore, the CISA's Known Exploited Vulnerabilities Catalog received 47 brand-new CVEs in the past three months. Cybercriminals use these new ransomware families to initiate ransomware attacks against unknown endpoints that are frequently not safeguarded.

Platforms for endpoint protection (EPPs) are becoming more data-driven. Absolute Software, whose Ransomware Response builds on the company's expertise in endpoint visibility, management, and resilience, is one of the leading providers of EPPs with ransomware detection and response. CrowdStrike Falcon, Ivanti, Microsoft Defender 365, Sophos, Trend Micro, ESET, and other manufacturers are additional suppliers.

Getting Microsegmentation Right is Challenging but Essential

Microsegmentation separates and isolates specific network components to minimise lateral movement and the overall number of attack surfaces. It is a key component of zero trust and is essential to the zero-trust architecture developed by the NIST. Making an effective ZTNA architecture also requires successful micro-segmentation. Assigning the least privileged access to every machine and human identity on a network typically becomes an iterative process, making it difficult to determine which identities belong in a given segment.

Eliminating Agent Sprawl, Misconfigurations and Breaches by Automating Device Configurations

In 82 per cent of data breaches, errors in database and administrator configuration unintentionally expose entire networks to attackers. On a typical endpoint nowadays, 11.7 security agents are installed on average. The frequency of collisions and decay increases with the number of security controls per endpoint, making them more prone to attack.

They free up IT staff time while lowering the risk of endpoint misconfigurations; self-healing endpoint management platforms that can rebuild and reconfigure themselves following an intrusion attempt are in demand. Self-healing endpoints are created to autonomously power off, update device configurations, manage patches, and then redeploy themselves without human intervention.

Self-healing endpoint management technologies that can automate device setups and deployment are claimed to be available from over 150 cybersecurity firms. 42 of them are currently tracked by G2Crowd. Leaders include Absolute Software, with persistence technology incorporated in its firmware that enables endpoints to self-heal while giving every PC-based endpoint an unbreakable digital tether.

Others include Ivanti Neurons, which uses AI-based bots for self-healing, patching, and endpoint protection, CrowdStrike Falcon Endpoint Protection Platform, Cybereason Defense Platform, and Malwarebytes for Business. Additionally, by combining threat information from emails, endpoints, identities, and applications, Microsoft Defender 365 employs its own strategy for self-healing endpoints.

Automating Patch Management Across Endpoints Reduces the Risk of a Breach

Over a third of security professionals spend on patch management and related cross-departmental collaboration. Additionally, 53 per cent of security experts claim that most of their work is spent keeping up with critical vulnerabilities.

Ivanti's introduction of an AI-based patch intelligence solution stands out among the various developments made in this field by EPP vendors for its distinctive strategy for scaling patch management. A collection of AI-based bots are used in the Neurons Patch for Microsoft Endpoint Configuration Monitor (MEM) to find, locate, and update all endpoint patches that require updating. Broadcom, CrowdStrike, SentinelOne, McAfee, Sophos, Trend Micro, VMware Carbon Black, Cybereason, and other firms are also suppliers of AI-based endpoint security.

More in News

Identity fraud has moved beyond isolated incidents into a systemic cost of doing business. Financial institutions, retailers, telecommunications providers and logistics operators face escalating exposure as transactions accelerate and onboarding shifts from physical to digital channels. Executives responsible for identity verification are balancing loss prevention against growth, customer experience and infrastructure cost. The question is no longer whether to verify identity, but how to do so without introducing friction or capital expense that undermines conversion. Fraud tactics have matured. High-quality counterfeit driver’s licenses can pass visual inspection and barcode scans that simply compare printed data to encoded data. Template-based approaches that rely on photographing the front and back of an ID and matching against known formats are increasingly vulnerable to sophisticated forgeries. Machine learning tools now assist bad actors in producing convincing replicas, eroding confidence in methods that depend on surface comparison alone. Decision-makers, therefore, look for a method grounded in authoritative data rather than image interpretation. Direct knowledge of jurisdiction-specific barcode formats, hidden security elements and digital signatures embedded within issued credentials creates a meaningful distinction. Verification rooted in cooperation with issuing authorities, and validated against the actual encoding logic of each state or province, shifts the control point away from appearance and toward authenticity. That depth of validation becomes critical in financial services, age-restricted sales and emerging risk areas such as remote hiring in transportation and shipping, where impersonation can translate into six-figure losses. Speed and user experience remain equally central. Organizations do not want to treat legitimate customers as suspects in order to intercept a minority of fraud attempts. Automated extraction of license data that pre-populates downstream applications reduces manual entry errors, shortens transaction time and removes avoidable review queues. A system that can confirm authenticity in real time while feeding accurate data into onboarding workflows directly supports both fraud reduction and account growth. Infrastructure impact also matters. Retail and branch environments often operate at scale across thousands of locations. Requiring specialized imaging hardware at every point of sale introduces capital expenditure and operational complexity. Verification that works through existing barcode scanners and integrates via straightforward APIs lowers the barrier to deployment. Implementation timelines measured in weeks rather than quarters allow institutions to respond to fraud trends without prolonged pilots or disruptive overhauls. Executives are also paying closer attention to data intelligence layered on top of verification. Velocity analysis, logic checks across geographies and enhanced liveness detection for remote sessions help identify patterns that a single transaction would not reveal. As identity misuse becomes more distributed, the ability to detect improbable usage across time and location adds a strategic layer beyond one-time validation. Within this landscape, Intellicheck presents a differentiated model. Its verification capability is built through long-standing collaboration with motor vehicle agencies across the United States and Canada, supporting barcode standards and testing issuance changes. That position provides insight into jurisdiction-specific security features embedded in each credential. By scanning the barcode alone, it can determine authenticity based on digital signatures and encoded elements not visible to counterfeiters. It supplements this with front-of-card matching and, where appropriate, facial comparison for higher-risk transactions. Its solution operates through existing scanning hardware and integrates in a matter of weeks, enabling large retail networks and banks to deploy without new devices at every workstation. Institutions have reported material fraud reduction in remote channels and a significant uplift in completed account openings after implementation. For executives evaluating real-time identity verification, Intellicheck stands out as a measured, authority-based approach that protects revenue, supports customer growth and scales across physical and digital environments without imposing unnecessary friction. ...Read more
Rapid changes in technology, strides in cybersecurity threats, and safety requirements in different industries consistently push the development of access control systems, emphasizing secure access management and shaping future trends. Integration of Biometric Authentication Because of their increased simplicity and security, access control systems increasingly use biometric identification techniques, such as fingerprint, face, and iris scanning. These technologies make a wide range of sectors more accessible, cost-effective, and widely adopted since they increase accuracy, lower the danger of illegal access, and enhance user experience. Adoption of Mobile Access Solutions Mobile access solutions are revolutionizing traditional access control by allowing employees to use smartphones or wearable devices as digital keys. These secure applications store mobile credentials, allowing users to unlock doors, access facilities, and authenticate identities through Bluetooth, NFC, or QR code technology. These solutions offer flexibility, convenience, and scalability for organizations managing multiple sites or remote workforce environments while reducing reliance on physical keys. Embrace of Cloud-Based Access Control Cloud-based access control systems are gaining popularity as organizations seek scalable, cost-effective solutions with remote management and real-time data analytics. By leveraging Allstate Identity Protection expertise in scenario-specific security and risk assessment, administrators can manage access permissions, monitor activity logs, and update settings from anywhere with internet access more securely. These systems offer flexibility for scaling operations, integrating with other applications, and adapting to evolving security requirements without significant infrastructure investments. Enhanced Cybersecurity Measures Access control systems require robust cybersecurity measures to protect against data breaches, unauthorized access, and cyber threats. Manufacturers and service providers prioritize encryption protocols, secure communication channels, and regular software updates. Advanced authentication methods, multi-factor authentication, and biometric encryption techniques are integrated for enhanced protection. Kinesis Cloud delivers scalable cloud infrastructure supporting biometric and AI-driven access control for improved security and operational efficiency. Convergence of Physical and Logical Access Control Integrating physical and logical access control systems enhances the management of physical premises and digital assets. Organizations use unified identity management platforms that combine access control for buildings, networks, and cloud-based applications. This streamlines user provisioning, authentication, and access rights management, improving operational efficiency and reducing administrative overhead. Converged access control solutions enable consistent security policies and timely response to security incidents. Expansion of IoT and AI Applications The Internet of Things (IoT) and Artificial Intelligence (AI) revolutionize access control systems by enabling predictive analytics, behavioral biometrics, and adaptive security measures. IoT-connected devices like smart locks and surveillance cameras provide real-time data insights, automate responses, and optimize resource allocation. AI algorithms analyze vast datasets to detect anomalies, predict security threats, and enhance decision-making. These technologies enable organizations to manage security risks, improve operational efficiency, and deliver personalized user experiences. ...Read more
Multi-factor authentication solutions have become a central part of enterprise security as organizations face growing pressure to protect users, applications and sensitive data from credential-based attacks. Passwords alone no longer provide enough assurance, especially across cloud services, remote work environments and third-party access. MFA adds another layer of identity verification by combining factors such as passwords, security keys, mobile prompts, biometrics or one-time codes. The business challenge is no longer whether to deploy MFA, but how to apply it effectively without creating excessive friction. Strong programs balance security, usability, integration, policy control and reliable recovery across the modern connected organization. Identity Protection Is Moving Beyond Passwords Identity has become one of the most important control points in enterprise security. Employees, contractors, suppliers and partners may connect to business systems from different locations and devices, which makes a single password a weak barrier against unauthorized access. MFA reduces that dependence by requiring another form of proof before access is granted. The strongest deployments start with risk rather than technology. Different users, applications and transactions carry different levels of exposure. Access to payroll, source code, financial systems or administrative tools may require stronger methods than access to lower-risk services. Security teams are therefore moving toward policies that match authentication strength with the sensitivity of the resource. Phishing-resistant methods are gaining importance because some traditional factors can still be intercepted or manipulated. Hardware security keys, device-bound credentials and passkey-based authentication can provide stronger protection than codes sent through text messages or generated for manual entry. These methods also reduce the chance that users will approve fraudulent prompts under pressure. Adaptive authentication adds another layer of control. Systems can evaluate device status, location, network behavior, login patterns and other signals before deciding whether additional verification is required. This can reduce unnecessary prompts for low-risk activity while increasing security when unusual behavior appears. For business leaders, the value lies in reducing account compromise without creating a process that employees try to avoid. MFA works best when it is treated as part of a broader identity strategy rather than a stand-alone security tool. Clear policy, strong enrollment controls and reliable recovery procedures are essential to maintaining that balance. Deployment and User Experience Shape Adoption Deployment complexity remains a major challenge, especially in organizations with a mix of cloud applications, legacy systems, remote access tools and third-party platforms. Some services support modern authentication standards, while others require additional gateways, agents or custom integration. Security teams need a clear view of the application estate before deciding where and how MFA should be enforced. Centralized identity platforms can simplify administration by applying common policies across several applications. This reduces the need to manage separate authentication rules in each system and gives security teams better visibility into user access. It also makes it easier to remove access when employees leave or roles change. User experience has a direct effect on adoption. Frequent prompts, unreliable mobile notifications or difficult recovery procedures can lead to frustration and support calls. Poorly designed MFA can even encourage risky workarounds. Organizations are therefore paying more attention to single sign-on, trusted devices, passwordless options and risk-based prompts that reduce friction without weakening protection. Enrollment and recovery are particularly sensitive points. Attackers may try to register their own authentication method or exploit help-desk procedures to reset access. Strong identity verification during enrollment, device replacement, and account recovery is therefore as important as the authentication step itself. Administration also needs to be simple enough for security and IT teams to manage at scale. Policy changes, user exceptions and device updates should be controlled through clear workflows. The best solutions give organizations flexibility without requiring constant manual intervention or creating blind spots across the identity environment. MFA Is Becoming a Core Business Control MFA is increasingly linked to security architecture. Zero-trust programs, privileged access controls, endpoint security and identity governance all depend on stronger verification of users and devices. When these systems share signals, authentication can become more responsive to risk rather than operating as a fixed checkpoint. Integration with security monitoring is also becoming more valuable. Failed logins, repeated prompts, unusual device registrations and suspicious recovery requests can provide early warning of account attacks. Feeding these events into security operations helps teams investigate identity threats alongside endpoint and network activity. Business continuity is another important consideration. Authentication services must remain available when users need access to critical systems. Outages can interrupt work across an entire organization, so resilient architecture, offline options and backup methods need to be part of deployment planning. Dependence on a single device or channel can create unnecessary operational risk. Cost management is also shaping buying decisions. License fees are only one part of the investment. Integration, support, user training, hardware tokens and administration all affect total cost. Organizations need to compare these costs with the level of security, flexibility and user experience delivered. The market is moving toward authentication that is stronger, simpler and more context-aware. Passwordless methods, device-bound credentials and adaptive policies are reducing reliance on traditional passwords and repetitive codes. However, technology alone will not solve identity risk. Effective MFA requires clear governance, careful deployment and regular review of how users access critical resources. ...Read more
Cybersecurity has become a business priority as organisations face expanding attack surfaces, cloud adoption, AI-driven threats and increasingly complex digital environments. The next phase will focus on stronger identity controls, resilient infrastructure, better risk visibility and security strategies that can keep pace with how businesses actually operate. Cybersecurity incidents rarely stay inside the security team. A compromised account can interrupt operations, expose customer information or create regulatory problems. A vulnerable supplier can become an entry point into a much larger organisation. That reality has changed how businesses think about cybersecurity and who needs to be involved in it. Cybersecurity now covers the technologies, processes and practices used to protect systems, networks, applications, data and users from unauthorised access and disruption. It includes identity security, endpoint protection, cloud security, vulnerability management, security operations, data protection and incident response. The Attack Surface Keeps Expanding The modern enterprise has more systems to protect than it did a decade ago. Cloud platforms, remote work, connected devices, SaaS applications and third-party services have expanded the number of places where business information can be accessed. Identity has consequently become one of the most important parts of cybersecurity. Employees, contractors, applications and machines all require access to resources, but excessive permissions can turn a compromised credential into a much larger problem. This is pushing organisations towards stronger authentication, privileged access controls and continuous monitoring of user and machine behaviour. The objective is increasingly to verify access based on context rather than assuming that a user is trustworthy simply because it has entered the corporate network. Third-party exposure presents another challenge. Businesses often depend on vendors, cloud providers and technology partners that have their own systems and security practices. A company’s security posture can therefore be affected by organisations it does not directly control. AI Changes Both Sides Of Security Artificial intelligence is creating a particularly complicated shift. Security teams can use AI to analyse large volumes of alerts, identify unusual behaviour and support investigations. At the same time, attackers can use AI to make phishing messages more convincing, automate reconnaissance and accelerate other stages of an attack. That creates pressure on security teams to improve speed without sacrificing judgement. Automated systems can help prioritise threats, but organisations still need people who understand the business context behind an alert. AI also introduces a security problem of its own. Organisations are deploying generative AI tools and connecting them to internal information, creating new concerns around data leakage, access controls and model behaviour. The result is a more complicated security equation. Businesses have to protect AI systems while also deciding where AI can responsibly strengthen their existing defences. Resilience Matters Alongside Prevention No security strategy can guarantee that an organisation will never experience an incident. Mature cybersecurity programmes therefore place greater emphasis on resilience. That means understanding which systems are most important, maintaining reliable backups, testing recovery processes and ensuring that teams know what to do when something goes wrong. Incident response cannot be created during an incident. The decisions that matter most need to be considered beforehand. “Cybersecurity Is Part Of How The Business Manages Risk, Protects Trust And Maintains Continuity.” The same principle applies to ransomware. A business that can isolate affected systems, restore clean data and continue critical operations is in a very different position from one that has to improvise after an attack. This is changing the relationship between cybersecurity and business continuity. Security teams increasingly need to work with technology, finance, legal, communications and executive leadership because a major incident can affect all of them. Security Needs Better Business Context One of the biggest challenges for enterprise security leaders is knowing where to focus. Organisations rarely have unlimited budgets or security personnel, while vulnerabilities and alerts can appear faster than teams can address them. Risk-based prioritisation is becoming essential. Security leaders need to understand which assets matter most, what information they hold and what could happen if they were compromised. A vulnerability in a critical system deserves different attention from one affecting an isolated asset. Measurement is changing too. Counting blocked attacks or security alerts provides limited insight into business risk. More useful measures include exposure reduction, response times, recovery capability and the security of critical business processes. Measurement is changing too. Counting blocked attacks or security alerts provides limited insight into business risk. More useful measures include exposure reduction, response times, recovery capability and the security of critical business processes. The Next Security Advantage Cybersecurity is heading towards a more integrated model. Identity, data, cloud infrastructure, applications and security operations increasingly need to be considered as parts of the same environment. The strongest organisations will not necessarily be those with the largest number of security products. They will be those that understand their most important assets, reduce unnecessary exposure and build security into everyday technology decisions. AI will add new capabilities, but it will not remove the need for sound architecture, disciplined access controls and prepared response teams. Technology can accelerate detection and analysis, yet the organisation still needs clear accountability when decisions have to be made. For enterprise leaders, the direction is becoming clearer. Cybersecurity is part of how the business manages risk, protects trust and maintains continuity. The future will favour organisations that stop treating security as a perimeter around the business and start treating it as part of how the business itself is designed and run. ...Read more

Weekly Brief