Vue International

Zero Trust: Attainable or Just a Pipe Dream?

Much is made about zero trust in today’s complex IT networks. In theory, it offers the ideal solution to the post-pandemic borderless boundaries of an organisation’s digital footprint that we now live and operate in. With collaboration, availability of data, out-of-the box cloud-based services, and seamless user experiences driving the desire to integrate more freely, information security teams have the unenviable task of policing all of this traffic, authenticating users, and securing the most sensitive assets of the business.

Is it possible—or maybe a more relative question—is it worth the effort to try and achieve zero trust in the real world of business, with competing priorities, limited budgets, and the imposing cultural hurdle of trusted networks?

We should first understand where we were before determining where we are going. Historically, networks have been built on a “trust but verify” model. This is fine when networks are small, manageable, and governed within the boundaries of a corporate LAN and data centre. However, this model also had one crucial flaw. If you got “in,” a user was then trusted and free to roam across the IT landscape, leaving little room for defence in depth. As networks have evolved and services have become more autonomous and the boundaries more blurred, zero trust or “never trust, always verify” has become an appealing model to enforce.

" It is prudent to consider culture and foster an understanding of information security risks at the highest level of business as part of the overall methodology and not simply jump straight into the solution if we want zero trust to have the biggest impact "

Zero trust, however, is simply a methodology; it is not a solution. The solutions come from the architecture and design of an IT network. Crucially too is the change in behaviors and cultures of an organisation, reimagining how we build, monitor, implement, and harden all aspects of our IT processes, from identification to asset management to network design, 3rd party integration, service support, etc. The list is endless.

This then takes us to the culture, the first hurdle in getting any strategy off the ground. Is the business involved enough in information security in the first place to understand the present risks and, subsequently, the benefits of zero trust as a methodology for change? Are IT professionals willing to invest significant amounts of effort, resources, and time in redeveloping their ways of working? It is prudent to consider culture and foster an understanding of information security risks at the highest level of business as part of the overall methodology and not simply jump straight into the solution if we want zero trust to have the biggest impact.

This education then begins with the assessment, determining what is at risk, what is important to us, such as data, services, and assets, and what we can realistically do about those risks. Next is mapping the data, not just where it resides but where it goes, who consumes it, how it is accessed, how it is maintained, and crucially, how is it secure yet available?

It seems then that zero trust may not be for everyone, practically. Smaller or newer organisations will have fewer obstacles to overcome in realising the potential of zero trust, but older, more complex organisations should consider the effort required to implement a zero trust methodology effectively. If the appreciation for or appetite for cyber risks in a business is not understood throughout the entire organisation, then any subsequent solution intended to implement zero trust may end up being an expensive investment and, by design, return ineffective results.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.