Zero-trust security continued to gain momentum in 2022, with support from governments and the private sector. But what will 2023 bring?
Here are a handful of zero-trust predictions from security and networking vendor executives.
Cloudflare Field CTO John Engates: The Rise of Chief Zero Trust Officer“Over the last several years, ransomware, data breaches, and other cyber campaigns have been hugely disruptive and cost organizations and governments millions. In response, the Biden administration issued an executive order in May of 2021 to implement a zero-trust security architecture across the federal government. While recent reports from the U.S. Government Accountability Office (GAO) show some agencies are on track, others appear to be falling behind. When governments need to move quickly and cut across organizational boundaries, they often appoint a czar to take charge of a particular program and see it through to implementation or execution.
As private sector organizations embrace digital transformation and move their operations to the cloud, they too are looking to zero trust to help provide a robust and secure network infrastructure. Secure access service edge (SASE) has emerged as a cloud-delivered convergence of network access and security services and is a common approach for Enterprise zero-trust adoption. The challenge however is that in many organizations, responsibility for networking and security lives in different parts of the organization and these groups often rely on different vendors in their respective areas. Breaking down the silos between security and networking teams and choosing the right tools, products, and vendors to align with desired business outcomes is critical to implement zero trust in larger enterprises.
As pressure to implement zero trust intensifies, I predict that a role analogous to a 'Chief Zero Trust Officer' will emerge within some large organizations. This person will be the zero-trust czar for the Enterprise and will be the individual responsible for driving a company on its zero-trust journey. Their job will be to bring together siloed organizations and vendors and ensure that all teams and departments are aligned and working toward the same goal. If resistance is encountered, the zero-trust czar should have the backing of senior leadership (CIO, Chief Information Security Officer (CISO), CEO, board of directors) to make decisions quickly and cut across organizational boundaries to keep the process moving ahead. Whether the very bold title of Chief Zero Trust Officer becomes reality or not, an empowered individual with a clear mandate and a singular focus may just be the key to getting zero trust across the finish line in 2023.”
Fortinet VP of Product Nirav Shah: Baking ZTNA Into Security Architecture“Many vendors are operating as if everything is moving to the cloud, but the reality for the majority of the customers we speak to is that their networks are hybrid, a mix between cloud and on-premises, and will be for the foreseeable future. The solutions they choose to support their zero-trust initiatives must enable employees to securely connect and access applications and resources no matter where they are located.
Zero-trust initiatives that comprise disparate products have an incredibly low rate of success and the lack of consistency from a management and enforcement perspective has slowed the adoption of zero trust in the industry. Organizations must choose solutions that are integrated and consistent across on-premises and cloud if their zero-trust strategy is to succeed. This is why vendor consolidation is key to enabling zero trust.
With the recent growth of a work-from-anywhere workforce, zero-trust network access (ZTNA) has received significant attention as part of a zero-trust strategy because it's a way of controlling access to applications regardless of where the user or the Application resides. ZTNA gives organizations the ability to consistently secure access at any time and from virtually any place, making it a critical element of almost every Enterprise security strategy today.
Most companies that deployed ZTNA during the pandemic have likely come to the realization that remote ZTNA policies don’t fully meet their security expectations or standards because it’s cumbersome having one set of policies for on-premises and an entirely different set of policies for the cloud. Choosing universal ZTNA – a ZTNA solution that is both on-premises and cloud-based – ensures universal coverage under a single solution.
A universal ZTNA solution will not only help deliver consistent enforcement but the same user experience and the same security policies regardless of where the employees are located – whether that’s on-site, a campus, working remotely, or anywhere in between. And as ZTNA begins to go mainstream in the Enterprise, we’ll start to see organizations transition away from a pay-per-user model and start to bake ZTNA directly into their security architecture for a more seamless and consistent user and management experience.”
Aruba Networks Chief Product and Technology Officer David Hughes: Built-In Security Replaces Bolt-On“Reducing cybersecurity risk has become a core operational concern. Transformation to a more automated security architecture is an IT imperative. No longer can organizations bolt-on perimeter firewalls around the network to protect against threats and vulnerabilities. Security must be built-in to every aspect of the network infrastructure from Wi-Fi access points to Local Area Network, campus and data center switches, WAN gateways, and extending into the cloud. Zero trust and SASE frameworks will become more intertwined, not only to protect from threats but to apply microsegmentation across the complete IT stack including users, connected devices, applications, network services, compute, and storage platforms.”
Juniper Networks Senior Director and Technology Evangelist Mike Spanbauer: Industry Needs More Guidance“Zero trust and its implementation is going to remain a focused effort for every organization. However, discerning what’s real and what’s vapor is hard with the language blurring between vendors. Fundamentally, organizations need a plan to ensure they can see, manage or control, and deal with connections everywhere. To break it down though, zero trust is a concept that applies to any connection, physical or logical, and the applied behavior or use policies of that connection. Every connection should be controlled and either permitted or denied based on validation and appropriate use. And no, I’m not just referring to connecting to the Wi-Fi, but rather every Transmission Control Protocol or User Datagram Protocol connection, every Hypertext Transfer Protocol/s request, or any transaction that traverses an environment that may compromise a business (yes, that’s pretty much everything, everywhere).
To make it easier for the customers to effectively choose solutions that address various needs in the environment the industry needs more candid and direct guidance from both the technology providers as well as customer success stories that detail how they’ve delivered on the frameworks (the National Institute of Standards and Technology’s, for example). How to, and not 'what could be.'”
Darktrace Federal CEO Marcus Fowler: Attacker Tradecraft Centers on Identity and MFA“It wasn’t just the recent Uber cyberattack in which the victim’s multi-factor authentication (MFA) was compromised; at the core of the vast majority of cyberincidents is the theft and abuse of legitimate credentials. In the case of Uber, we saw that MFA can be defeated, and with Okta that the MFA companies themselves become targets – potentially as a mechanism to reduce its effectiveness in other customer environments.
Once considered a 'silver bullet' in the fight against credential stuffing, it hasn’t taken attackers long to find and exploit weaknesses in MFA and they will continue to do so in 2023. MFA will remain critical to basic cyberhygiene but it will cease to be seen as a standalone ”set and forget“ solution. Questions around accessibility and usability continue to dominate the MFA discussion and will only be amplified by increases in cloud and Software-as-a-Service along with the dissolution of traditional on-premises networks.
Today and in the future, MFA should be viewed as one component of a wider zero-trust architecture, one where behavior-based analytics is central to understanding employee behavior and authenticating the actions taken using certain credentials.”
BlackBerry Chief Information Security Officer (CISO) and SVP John McClurg: Focusing on the Role Humans Play in Cyberspace“This year made it clear that remote work is here to stay – meaning zero-trust measures will become even more crucial and CIOs will need to focus on associated internal threats and mitigating human risk.
For the future of the workplace, zero-trust security measures will only become more important. Zero trust assumes that there is no longer a traditional network edge and takes a more stringent, continuous, and dynamic approach to user authentication, but also does this seamlessly to avoid impacting the user experience.”
Illumio CEO Andrew Rubin: Being a Cyberleader Is Only Getting Harder“Security is a challenging and at times thankless task. The Uber breach verdict re-instigated a national conversation about the responsibility cyberleaders wield and how companies should be held accountable in the age of imminent digital risk. The new year will be a challenging year for Chief Information Security Officer (CISO) around the world who have more work, more pressure, and less help. It will be critical for CEOs to not only ensure their cyberteams are supported but to also get on board with an 'assume breach' mindset. Having the right tools and strategies in place to contain inevitable attacks will be critical for protecting not only an organization’s assets, but also its people in the age of ransomware.”
Raytheon Intelligence & Space Principal Engineering Fellow Torsten Staab: The Importance of Zero Trust in Quantum“Moving into 2023, look for additional zero-trust implementation guidance and recommendations from NIST and the U.S. Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA).
Furthermore, as we head toward the quantum computing era, adopting a zero-trust architecture will become more important than ever. Zero-trust principles such as 'never trust, always verify' and 'assume breach,' coupled with PQC [post-quantum cryptography]-inspired concepts such as crypto agility (i.e. the ability to seamlessly Switch between classical and PQC algorithms and quickly replace compromised crypto algorithms if needed) will apply to any organization and be key for providing future-proof, next-generation cybersecurity.”
iBoss CEO Paul Martini: From ZTNA to ZTA“ZTNA will evolve to zero-trust access (ZTA) and move from being purely a VPN replacement to the concept of a user connecting to commodity Internet and having all traffic secured and encrypted both to the office and to the Internet.
The terms ZTA and security services edge (SSE) will begin their convergence to represent the single concept of unified connectivity and security. The shift to perimeter-less technology will accelerate to a model where users need just commodity Internet to securely connect to everything from the office, at home, at airports, and at hotels. This will greatly reduce costs for organizations and fulfill the work-from-anywhere model and will be powered by zero trust.
Data centers will continue to be decommissioned in favor of SaaS and cloud infrastructure providers replacing firewalls and proxies with zero-trust security service edges that perform the same functions.”
Armis CTO for Cyber Ziv Dines: The Influx of Connected Devices in Public Sector Will Make Zero Trust the Federal Standard“The recent federal spotlight on zero trust through executive orders and White House-backed initiatives is an acknowledgment that the threats to public sector infrastructure have never been greater. But federal agencies can’t meet the zero-trust challenge without first knowing and seeing 100% of their connected assets.
To add to the complexity, the number of connected devices in the public sector is steadily growing, leaving attack vectors for threat actors. In 2023, federal agencies will make great strides in their implementation of zero-trust architecture into their infrastructure to secure their multitudes of managed and unmanaged IT, OT IoT, [Internet of medical things], cloud, and 5G assets, making zero trust the new federal security standard.”
Editor's Note: This content has been lightly edited to meet SDxCentral Editorial guidelines and for clarity.
Comments