Implementing a zero trust policy

Understanding how to implement a zero trust policy has become essential for all businesses
Understanding how to implement a zero trust policy has become essential for all businesses

The world of work has been thrown into various formats, including hybrid and remote working. With this massive change comes the fear of major cyberattacks due to vulnerable devices and networks. Marc Lueck, CISO EMEA, Zscaler has stated that in the current digital age, many organizations have had to rapidly adopt new ways of managing network security, as traditional approaches become outdated and no longer sustainable in the era of the cloud.

Attacks are advancing both in volume and sophistication. CyberEdge’s 2021 Cyberthreat Defense Report revealed that 86% of organizations had a successful cyberattack landed on them by the beginning of 2021 – up from the 62% of organizations that were hit in 2014.

The idea that cyberattacks could come from within and outside a business’s network has become a major concern for CIOs. Using zero trust is one of the most proactive responses a business can take to mitigate potential threats and decrease the number of potential actors within its systems. As a result, zero trust is slowly becoming an essential component of every cybersecurity strategy.

The zero trust theory effectively means that no one using a network is automatically trusted; everything must be examined, and rights are granted and confirmed on a constant basis, depending on the access needed. Lucek added, “by considering a cloud-first zero trust approach to security and connectivity, organizations will not only be able to reduce the risk of attacks, but they will also be able to stay competitive and embrace digital transformation further down the line.”

Altaz Valani, Director of Insights Research at Security Compass, recently provided TBTech with some tips to implement zero trust into a business. Valani explained, “the pre-requisites for building a zero trust architecture are to be clear about the business objectives; zero trust will involve change and you need business buy-in for this. It’s also important to educate yourself, as most security paradigms are network-based, whereas zero trust is asset-based. Additionally, identify an important application to the business and start from there; don’t do everything at once.”

He added, “there are also some ‘non-negotiable’ components of a zero trust architecture, such as automated asset security and explicit trust validation throughout the asset’s lifecycle. However, organizations must also recognize that zero trust is a continuously improving security model and not an end state.”

READ MORE:

Looking for more advice on implementing a zero trust policy into a business? Then, join us on the 22nd of February 2022 to join our panel of experts to discuss the benefits and challenges that businesses will face while implementing a zero trust policy and how to implement it into a business’s cybersecurity strategy successfully.

Register now here 

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Luke Conrad

Technology & Marketing Enthusiast

Cheltenham MSP is first official local cyber advisor

Neil Smith Managing Director of ReformIT • 23rd April 2024

ReformIT, a Managed IT Service and Security provider (MSP) based in the UK’s cyber-capital, Cheltenham, has become the first MSP in the local area to be accredited as both a Cyber Advisor and a Cyber Essentials Certification Body. The Cyber Advisor scheme was launched by the Government’s official National Cyber Security Centre (NCSC) and the...

How we’re modernising BT’s UK Portfolio Businesses

Faisal Mahomed • 23rd April 2024

Nowhere is the move to a digitised society more pronounced than the evolution from the traditional phone box to our innovative digital street units. Payphone usage has dropped massively since the late 1990s/2000s, with devices and smart phones replacing not only communication access, but the central community points that the payphones once stood for. Our...

How we’re modernising BT’s UK Portfolio Businesses

Faisal Mahomed • 23rd April 2024

Nowhere is the move to a digitised society more pronounced than the evolution from the traditional phone box to our innovative digital street units. Payphone usage has dropped massively since the late 1990s/2000s, with devices and smart phones replacing not only communication access, but the central community points that the payphones once stood for. Our...

What is a User Journey

Erin Lanahan • 19th April 2024

User journey mapping is the compass guiding businesses to customer-centric success. By meticulously tracing the steps users take when interacting with products or services, businesses gain profound insights into user needs and behaviors. Understanding users’ emotions and preferences at each touchpoint enables the creation of tailored experiences that resonate deeply. Through strategic segmentation, persona-driven design,...

From Shadow IT to Shadow AI

Mark Molyneux • 16th April 2024

Mark Molyneux, EMEA CTO from Cohesity, explains the challenges this development brings with it and why, despite all the enthusiasm, companies should not repeat old mistakes from the early cloud era.

Fixing the Public Sector IT Debacle

Mark Grindey • 11th April 2024

Public sector IT services are no longer fit for purpose. Constant security breaches. Unacceptable downtime. Endemic over-spending. Delays in vital service innovation that would reduce costs and improve citizen experience.

Best of tech to meet at VivaTech in May

Viva Technology • 10th April 2024

A veritable crossroads for business and innovation, VivaTech once again promises to show why it has become an unmissable stop on the international business calendar. With its expanding global reach and emphasis on crucial themes like AI, sustainable tech, and mobility, VivaTech stands as the premier destination for decoding emerging trends and assessing their economic...