Gartner states zero-trust security is not a silver bullet to all cyberthreats and organizations need other security measures to complement it, especially when less than 1% of large organizations have a mature and measurable zero-trust program.
“Zero trust is at this peak of inflated expectations, so we should see some rationalization of the hype this year,” Gartner VP Analyst John Watts told SDxCentral.
“If there's too much focus on zero trust and not enough on things like compliance, and data security, and identity management, and security operations, and the other parts that are important, then there will be a disappointment because if someone's expecting zero trust to kind of be that magic solution that will solve all of their security problems,” he added.
Watts explained that zero trust has a limited scope, which is typically an extended workforce, including contractors, suppliers, and internal employees. It excludes public-facing applications and citizen-consumers who can access enterprises’ external services but might have a weak identity capability. “Zero trust becomes very difficult when you have less assurance of an identity,” he explained.
In some cases, zero trust can be extended to managed and unmanaged devices and the users, but not to IoT and OT devices and other business realms, Watts added.
Gartner predicts that more than half of cyberattacks over the next several years will target areas that zero-trust controls cannot cover or mitigate.
"Zero trust can help reduce the impacts of [an] attack, but it doesn't eliminate it,” Watts said. “The primary risks that zero trust mitigates will be things like lateral movement and malware.”
He used phishing attacks as an example. Zero-trust strategy can help minimize the damage by requiring higher levels of trust or access, but “it doesn't actually address the phishing risk itself.” Zero trust cannot prevent threat actors from phishing the victims or stealing their credentials.
“In a zero-trust architecture, the two primary residual risks that you would encounter will be insider threats and account takeover attacks,” Watts said, adding attacks still can occur if the threat actors have legitimate access to data.
To complement zero-trust security, organizations should build a layer-of-defense model, and security operations and analytics that can monitor and alert abnormal behaviors and data transfer, he recommended.
Several security vendors echoed Gartner’s predictions and warned that zero trust and shift-left security approaches might fall short in social engineering and API exploits.
“Where zero trust will struggle to help is where you have machine-to-machine or cloud-to-cloud communication using APIs. API access is often quite permissive so the theft of an API token or key can lead to bulk data theft,” Tanium CISO Christopher Hallenbeck told SDxCentral in an email.
The need for mature and measurable zero-trust programs
Gartner also finds large organizations typically lack zero-trust maturity and measurability. Despite being one of the hottest topics in the security industry, Gartner only saw a few companies who publicly talked about or could demonstrate their mature and measurable zero-trust programs, including tech vendors who sell zero-trust products and large and well-funded financial institutions.
“It’s rare to find,” Watts said.
A majority of zero-trust programs are not fully-implemented, which means “they can't tell you exactly what their risk posture is if they have an optimized risk posture based on the zero-trust controls.”
“A mature program is one that has the architecture in place, has a reasonable set of zero-trust controls that can be managed operationally, they would understand the amount of risk reduction that's been applied to the organization, and they would also be able to test their zero-trust architecture and explain if they still have that implementation that they expect to have in place,” Watts argues.
Additionally, zero trust is a years-long journey, and many large companies are having trouble measuring the outcomes of their zero-trust investments on reducing the risks and impact of the breaches.
“This is tied to the outcome-driven metrics concept. The board of directors and leadership of companies will want to know what they're getting, what their return on their money is,” Watts explained, adding that organizations need to learn how to communicate security programs’ business value based on metrics.
Gartner sees zero-trust moving into reality
Gartner forecast 10% of large enterprises will have a mature and measurable zero-trust program by 2026, jumping from less than 1% today.
“We think that will improve primarily because the leaders of those large organizations are going to want to know and see data to understand if they optimize the risk posture,” Watts said, adding that the desire to increase security and reduce risk will continue to drive zero-trust implementations, and remain a strong trend.
Comments