Network security providers Appgate and Illumio announced an integrated zero-trust network access (ZTNA) and zero-trust network segmentation (ZTS) solution to protect network connectivity and prevent breaches from spreading across hybrid infrastructures and applications.

John Skinner, VP of business development at Illumio, explained that while ZTNA contains breaches from accessing certain areas of the network, ZTS prevents breaches from moving throughout the network once inside.

Illumio Core can be installed for East-West traffic to label all workloads in the network with contextual data like role, application, environment, and location. Appgate SDP applies ZTNA to North-South network traffic and creates per-user, per-session, user-to-workload access controls based on Illumio Core’s contextual metadata.

To eliminate excessive levels of workload-to-workload interconnectivity, Illumio Core creates microsegmentation barriers. This prevents security teams from having to rewrite permission rules as IP addresses change, or as applications move from development to production phases, according to Skinner.

Is Segmentation the Missing Piece of the Zero-Trust Puzzle?

Illumio research found over the past two years 76% of organizations have experienced a ransomware attack. The company said the industry is adopting an “assume breach” mindset, accepting that breaches are inevitable and “building policies that proactively contain cyberattacks to minimize their impact,” like zero trust.

Although the industry has done well to move quickly toward ZTNA, many organizations are still missing the ZTS piece of the puzzle, Skinner said.

He compared the concept of ZTNA to the security practices in most office buildings, where there is often a desk that requires visitors to provide identification and an explanation for where they’re going in the building, and why.

Sometimes, in higher security buildings, a security guard even escorts visitors to the room they are going to that day, to ensure they don’t roam the building once their meeting is over. This, Skinner said, is what ZTNA does for users in a network.

When users need to access data or an application within a network, “Appgate will create a cloaked private pathway and will personally escort you up to wherever that database or application resides in the internal network,” he explained.

But Skinner said once inside these theoretical network rooms, there can be backdoors that the security guards (or ZTNA) cannot protect. “You don't want to assume that that person in that conference room is trustworthy,” he said. “You want to put in place controls that prevent them from going places. They don't have authorization to go where they shouldn't be going.”

Applications excessively connected to other applications is how ransomware spreads inside of organizations, Skinner added, and ZTS — the segmentation of that network of conference rooms and hallways — is what prevents attackers from finding the backdoors.

“What we do is we create those sort of locks on the door between application A and application B, and between B and C, and so on and so forth,” Skinner said. “Because in a data center, you may have hundreds, maybe thousands of these applications.”

He added, “Everybody who's a candidate for ZTNA should be aware that they need this complimentary piece also, not just as an add on, but also ideally in a way where they're actually sort of helping each other.”