Endpoint Protection Concept
– Getty Images

For much of the history of computing, the concept of cybersecurity was based around a single idea: keeping cyber attackers and hackers out.

It might sound simple at first, but it’s deceptively so. While passwords, firewalls, and anti-virus software were all put in place with the aim of keeping malicious intruders out, they don’t take into account the concept of an attacker who has got inside the system already. Instead, the technology was instructed to implicitly trust a user inside the network, granting them access to systems and data, no questions asked.

It’s something which bothered cybersecurity analyst and practitioner John Kindervag, who back in 2010, authored the paper No More Chewy Centers: Introducing The Zero Trust Model Of Information Security. In it, he argued that computer networks based on implicit trust of users inherently creates security risks.

“I said this is silly,” Kindervag, now chief evangelist at cybersecurity company Illumio, explained to SDxCentral. “Trust is a human emotion that was injected into digital systems for no reason, and we need to get rid of it. All interfaces and all packets should have the same trust level, and that trust level should be zero; that’s where zero trust comes from.”

The key concept behind zero trust is that the network should be treated as compromised, therefore hostile, meaning that the policy of inherent trust should be removed. That means just because a user is connected to a network, it doesn’t mean they should be able to automatically access, modify, or download whatever data they like.

With a zero trust philosophy in place, each request to access data, applications, or services should be authenticated and authorized – and if the user is unable to satisfactorily authenticate themselves with the right username and password or security key, then their connection is restricted or even completely dropped.

Do I know you?

Man removing label-free beer bottle from refrigerator
Example of zero trust: Can I have a labelless beer? No, get the heck out of my house – Getty Images

But even now, 15 years later, one of the reasons hackers can successfully conduct cyber attacks is because once they’ve compromised systems, they’re often still not met with these restrictions: they’re free to move laterally around the network, because the policies put in place suggest that if they’re inside the network, they must be a legitimate user. But would we react like this in the real world?

“I liken it to if I’m sitting in my house and I ask my wife if she knows the guy getting beer out of the refrigerator, and she says no. But then I say, since he’s able to get beer out of the refrigerator, I guess he must belong here,” said Kindervag.

“That’s what we do with computers all the time, we make the assumption that since you’re able to get access to that, you must be approved to have access to it. But the answer should be no. You’d say ‘Get the heck out of my house!’”

According to Gartner, 63% of organizations have implemented a zero trust strategy, citing it as industry best practice. However, for many of these organizations, the zero trust strategy still hasn’t been fully implemented: the same Gartner survey found that for many of these organizations, the deployment of zero trust initiatives only applied to half of their network – or less.

This means that while the crown jewels of the business might be protected, much of the network still remains vulnerable because it’s implicitly trusting users. And attackers are looking to take advantage of that.

“The common denominator of the thing that cyber criminals exploit is trust. So when you think about why folks are experiencing ransomware, often the compromise starts with phishing to gain account credentials, and there’s certain elements of trust to that,” said George Finney, chief information security officer at The University of Texas System and author of the book Project Zero Trust.

“When you think about how some of these tools are configured: if my machine gets ransomwared, if I’ve got trust relationships that allow my laptop to talk to other laptops, that’s going to spread ransomware,” he explained.

With a strategy of zero trust applied throughout the network, in theory, an attacker would be prevented from gaining access to the networks and systems they want to infiltrate or disrupt.

More security doesn’t mean less productivity

Detractors of zero trust would argue that it creates barriers to productivity, that staff are prevented from being efficient if they’re forced to type in their username and password to authenticate multiple times a day. But Finney doesn’t believe it’s a case of one or the other.

“I don’t think security needs to be a trade-off with productivity,” he said, arguing that single sign-on (SSO) combined with multi-factor authentication (MFA) can make the process both streamlined and secure.

“As a single step, I create an incentive to adopt SSO because users are happy, and I get an extra layer of security at the same time. Focusing on trust really does help streamline the process.”

With that in mind, Finney suggested, in order for an organization to successfully apply a zero trust strategy, it’s important that decision makers from across the company are involved, that the initiative isn’t solely controlled by the information security team.

“If the security nerds are the only ones who understand zero trust, you’re going to have a hard time because you need your IT and other colleagues to be able to support you. A lot of the work that has to get done does involve those too,” he explained. “You have to be able to work with department heads, business owners, or your executive team to help tie all those things together, to get everyone working towards the same direction and goal.”

The importance of a well-planned zero trust strategy

Ben Franklin's eyes superimposed for a graphic
'Zero trust isn’t a single tool or technology: it’s a strategy, a cultural change' – Getty Images

Most organizations do see zero trust as the way forward. According to business insurer Hiscox, two-thirds of organizations are actively looking to adopt or expand a zero trust strategy by 2030, to help ensure no one inside or outside the network can access sensitive data without strict verification.

However, while zero trust helps improve security, implementing it isn’t without challenges, such as the need for investment in technology upgrades or network infrastructure changes. And there’s the issue that many still fundamentally understand that zero trust isn’t a product, it’s a philosophy around implementing a cybersecurity strategy.

“Generally speaking, it’s become the new de facto model for security architecture,” said Carlos Rivera, senior analyst supporting security and risk professionals at Forrester. “But zero trust isn’t a single tool or technology: it’s a strategy, a cultural change in which you’re reassessing your architecture to achieve outcomes of least privileged access and implicit denial rather than implicit trust – and maintaining monitoring throughout. One tool will not do it all.”

That means that it isn’t simple to introduce a zero trust strategy. Before you begin, knowing what you have on your network is a must: you can’t set out a strategy for protecting your architecture if you don’t know what it is you’re protecting.

“Imagine NASA launching a rocket with no navigation. Yeah, it might make it into orbit, but if you don’t have a destination for it to go, it’s just another piece of floating debris out in space causing havoc,” said Rivera. “If you’re deploying zero trust controls and you don’t have an intent behind that control, you’re just employing another tool that’s adding more complexity to your architecture, rather than the outcome you want to achieve.”

Zero trust can be a useful strategy for helping organizations to defend their networks. But it’s also vital that the organization has the personnel, the technology, and the structure required to make it work. This sounds challenging, but like any project, breaking it into smaller pieces can help towards a more successful outcome.

“Zero trust is not a product; it is a strategy designed to stop data breaches and make cyber attacks unsuccessful. It’s an idea that allows you to think bigger about cybersecurity and go beyond products by putting the dots together with a systematic approach to cybersecurity,” Kindervag said.

“The first struggle people have is they try to do it all at once for everything – and that always fails. You do it in small, incremental pieces, and in this way, your chances of failure are very small. If you do it one asset at a time, it’s consumable, and you don’t have to be afraid of it.”

This article first appeared in the Cybersecurity Supplement.

To read the Supplement for free, simply register