Zero trust offers organizations an approach that can help to significantly improve security posture and help to minimize risk.

But what would happen if, let's say, an organization had fully implemented zero trust and yet at some point several years into the future had a breach? What would be the likely reasons?

That's the question that Wolfgang Goerlich, advisory CISO at Cisco explored in a session at the RSA Conference 2023 this week, in a session aptly, "Conducting a Pre-Mortem on the Next Zero Trust Breach." Goerlich explained that a pre-mortem is a way to imagine a future where operations have failed in some way and there is a process to work backwards to determine what went wrong.

"If we assume we're going to fail, we can come up with some good scenarios and good strategies," Goerlich said.

What is a breach in a zero-trust world?

While the term zero trust is widely used, it can mean different things to different people. Goerlich defines it as a dynamic trust boundary that is short-lived, tightly scoped, enforced by policy, informed by trust signals and telemetry.

Goerlich emphasized at the outset, that just because there was a breach, doesn't necessarily mean the technology is not useful. One potential reason why a future zero trust breach could occur is due to a lack of continued enthusiasm for zero trust.

In the beginning of nearly any new technology effort, organizations tend to be invested and enthusiastic, but that changes over time. Goerlich commented that a reason for a potential future zero trust breach could occur because the people stopped being excited about it, and stopped holding each other accountable because it stopped making progress.

[ Follow SDXCentral’s complete RSA Conference 2023 coverage ]

Another root cause for a potential future zero trust breach has to do with scope. Zero trust doesn't always include every single item within an organization as part of the scope of deployment.

"Our out of scope is in scope for adversaries," Goerlich said.

There also can be a risk of technical debt that has impacted the design, deployment and implementation of zero trust, that could be a risk in the future.

"I think one of the things we forget is that the modern enterprise is 10 to 20 years of technical depth, pulled forward by the latest cloud, blockchain, AI/ML thing and it's only the AI/ML thing that we are scared about," he said. "One of the concerns from a people, process and scope perspective is making sure that we haven't over rotated, ignoring the existing oftentimes much larger technical base."

Zero trust controls deployed today will be bypassed tomorrow

A critical part of the model are controls and policies to allow authorized actions and prevent attacks.

Controls include multi-factor authentication (MFA), which in the future, could potentially be bypassed due to any number of reasons, including technical vulnerabilities that could be discovered or misconfigurations. Goerlich expects that existing controls will be bypassed in the future.

"Whenever a control reaches critical mass, the control will be bypassed," he said. "Another way of saying that is all a better mousetrap does is breed better mice."

Zero trust is also often seen as providing 'end to end' security, which Goerlich said will inevitably lead adversaries to attack the 'end' targeting entitlements, abusing OAuth security authentication and attacking API endpoints.

Taking steps now to prevent breaches in the future

Goerlich commented that the simple truth is that it's hard to know where the security landscape and threat adversaries will be in the future.

He suggests that organizations deploying zero trust today, look at their roadmaps and make sure they have plans to sustain support, interest and engagement for years to come. Goerlich also recommends that zero trust implementers shore up out-of-scope areas to help reduce the attack surface.

In the final analysis Goerlich noted that even if there is some hypothetical future potential for a breach in zero trust there are good reasons to deploy it now.

"Even badly implemented  zero trust today will stop a lot of attackers," he said. "Start there and iterate."