zero trust sdx crop
– sasha85ru/Getty Images

In 2023, Dell Technologies aims to be a thought leader for demonstrating the reality of zero trust, a “Switzerland” in organizing the zero-trust ecosystem, and a partner to customers that can help them adopt and implement zero-trust strategies, Global CTO John Roese told SDxCentral.

“Most people honestly don't believe it's real. There's a lot of people that are like: ‘yeah, nice theory, [but] I've never seen one. It's an idea that will never happen.’ And we disagree,” Roese said. “We think it can be built and we're demonstrating it.”

Dell plans to open a "Zero Trust Center of Excellence" this spring at DreamPort, the U.S. Cyber Command’s cybersecurity innovation facility.

The center is designed to provide a secure data center for organizations to test configurations and validate zero-trust use cases, which allows organizations to test configurations based on the Department of Defense (DoD) Zero Trust Reference Architecture before deployment into their own environments.

This zero-trust center built “racks of gear sitting at DreamPort that are a real zero-trust infrastructure with 151 controls implemented that meets the DoD specifications, that doesn't exist anywhere else in the world,” Roese touted. “Over the course of the year, we'll continue to do that incubation work to demonstrate zero trust is actually real.”

And he noted this public and private sector partnership creates the reference architectures to pull the ecosystem together.

Dell last October rolled out a suite of services called Identity & Endpoint Protection with Microsoft Zero Trust to integrate Dell’s security expertise with Microsoft security tools to protect its customers’ Microsoft ecosystems with zero-trust principles.

Zero trust should be a collection of companies working together, Roese pointed out. “So we will play more [role] of that ecosystem builder, the integrator.”

Dell will continue to work with 25 to 30 companies to build a big zero-trust ecosystem and plans to beef up the partnerships in 2023, he added. “We're Switzerland. People come to us and we can work together and we can organize the ecosystem.”

Dell CTO: Orgs should define their zero-trust control plane

Also for this year, Dell aims to be involved on the front end of helping customers figure out their zero-trust path, according to Roese.

“There's a knowledge gap both in terms of implementing zero trust but also even understanding how to do it,” he said. “Trying to quickly get to a zero-trust behavior in a brownfield environment that's been doing things randomly for 20 years, that's hard.”

To that end, Dell last year introduced cybersecurity advisory services to help smooth the adoption hurdles, which include a vulnerability management service and more advanced services building on basic security practices and giving customers additional guidance on their zero-trust journey.

The starting point for the journey should be to get the control plane in order over the multicloud environment, Roese argues. “Unfortunately, after 20 years of people building security architectures, they didn't really do identity management or policy or threat management well, it was very fragmented, very chaotic.”

To do zero-trust properly, organizations need to have an authoritative identity management, policy management, and threat management framework, he added. “And in the multicloud world, that control plane has to sit above all of your clouds.”

“Security is not going to get better, the threats are not going to get less. And now there's a lot more mindshare around zero trust being the right answer. There isn't really another path forward. It's just a question of how do we get there?” Roese concluded. “We'll be talking about zero trust a lot for the next few years.”