A new federal strategy moves U.S. government agencies toward a zero-trust approach trailing President Biden's cyber executive order. Security professionals expect the private sector will follow suit.
“High-profile attacks from SolarWinds to Colonial [Pipeline] were really a wake-up call that we needed to start doing something very different,” said Bill Wright, senior director of North American government affairs at Splunk.
Additionally, the remote workforce and migration to the cloud, both accelerated by the pandemic, “pushed the concept of zero trust forward,” Wright added.
Splunk recently joined the Cybersecurity and Infrastructure Security Agency's (CISA's) Joint Cyber Defense Collaborative as an industry partner. The vendor will continue working with federal customers and offering data, automation, and logging services, Wright said. “Data is absolutely essential in zero trust … Splunk is at the center of an effective zero trust strategy that's relying on data and helping make decisions on that data in real time.”
‘Unfunded Mandate’ Comes With ChallengesThe Office of Management and Budget (OMB) memo requires federal agencies to submit a zero-trust implementation plan in 60 days. However, before agencies adopt these plans, they will need to address a long list of challenges, Wright said.
One of the major challenges is funding. “Many agencies are viewing this as an unfunded mandate,” he added. “Not only that, we find ourselves in a continuing resolution based on priorities that were set almost two years ago now.”
Funding from the Technology Modernization Fund might help, but “part of the executive order encourages agencies to reprioritize funding and to put funding into some of these areas where we really need to enhance the cybersecurity awareness and address some of these mandates,” said Bill Harrod, public sector CTO at Ivanti.
Cultural change presents another challenge. “Zero trust as a concept really doesn't come naturally to IT teams, cyber teams that have been trained on decades of perimeter-oriented strategies that allow pretty unfettered access once a user is inside,” Wright said.
Plus, government agencies have relied on legacy infrastructure and systems for many years.
Will Private Sector Follow Suite?“The Log4j vulnerability is the latest evidence that adversaries will continue to find new opportunities to get their foot in the door,” the White House wrote in a statement about the new zero-trust push. “The zero-trust strategy will enable agencies to more rapidly detect, isolate, and respond to these types of threats.”
It “is about ensuring the federal government leads by example,” acting OMB director Shalanda Young said in a statement.
As government agencies move in this direction, “you will start to see private sector follow suit, which a lot have already started studies in doing so,” Justin Fier, director of cyber intelligence and analytics at Darktrace, told SDxCentral.
“President Biden's executive order and the OMB directives have put a very fine point on zero trust and cybersecurity protections,” Harrod concurred. "I think there's a real understanding that we need to be proactive about it.”
But it's not just a problem for public agencies. The private sector is also facing increasingly sophisticated adversaries and threats.
“Recent cyber threats -- from SolarWinds to Colonial Pipeline, to Log4j, and mounting tensions surrounding geopolitical tensions, don’t just affect governments or industry – they affect all of society,” Wright said. “Zero trust has applicability not just in the government, but private sector companies need to start thinking about defending this way as well,” he added.
Wright also expects to see more cyber guidance from the federal government, especially from CISA.
There are “increasingly more proactive government moves to advise state and local governments, but also critical infrastructure” including the water and energy sectors, the majority of which are in the hands of the private sector, he said.
Comments