Trend Micro added zero trust capabilities to its security arsenal today and teased a future secure access service edge (SASE) service to kick off its annual customer event today.
Zero trust isn’t one technology, but rather a framework to ensure that only continuously verified users and devices are allowed access to corporate resources and restrict data on a least-privilege basis.
A handful of technologies support zero trust, and Trend Micro’s builds on its extended detection and response (XDR) Vision One platform, which collects telemetry across email, clouds, networks, and software-as-a-service (SaaS) applications to hunt for and respond to security threats.
“We’re highlighting the value of really effective risk-insight calculation,” said Eric Skinner, VP of market strategy at Trend Micro. “And that’s really a foundation for anything that anybody wants to do with zero trust inside their organizations. Because with any of the solutions that you might buy from any vendor, you have to make a zero-trust decision on the basis of assessing the risk of the device, the risk of the identity, the risk of the application.”
And while zero trust has become somewhat of an industry buzzword of late — Trend Micro VP of Cybersecurity Greg Young calls it “zero-trust washing,” — Trend Micro’s approach is different in that it gives customers the comprehensive visibility and context needed to make tough decisions about whether or not trusted devices and individual identities are secure, Young said.
This is important as an increasingly remote workforce uses a variety of devices and networks to access corporate resources hosted in several locations, from a corporate data center to public clouds or SaaS applications.
“When somebody logs in through a VPN, it’s very binary: this is a good identity or a bad identity,” Young said. “And one of the big differences is that zero trust looks at it through a lens that says what’s the posture or the health? Your identity may be authorized, but if you’ve been involved in some really shifty stuff in the last 10 minutes such as sending out a lot of malware and ransomware — well, that’s a different kind of decision to make from risk perspective about that identity you’re using to log in.”
Trend Micro Zero Trust Build on XDRThis risk insight “is an expansion on top of XDR,” Skinner added. “XDR provides a ton of really valuable insight with respect to threat, which is one aspect of risk. But for risk insights for zero trust, you need to do more than that.”
To this end, Trend Micro’s zero trust offering continually assess the user, device, application, and content using telemetry from Trend Micro and third-party products. “Is your application properly configured? Is your device patched? Does your device have the right security settings enabled? What data is being accessed? This isn’t XDR per se, but it’s certainly relevant with respect to assessing risk,” Skinner said.
This risk and security health assessment supports automated access control and flags incidents for alert investigations.
It establishes a secure connection based on the health assessment each time a device or user attempts to access the corporate resource. This includes a cloud access security broker API integration to SaaS apps, network enforcement points in front of company resources, and support for blocking access to specific applications using existing endpoint agents, and visibility into email usage.
It All Comes Back to RansomwareThis is especially important because phishing activity could indicate that user's identity has been compromised, which can be an early indicator of an ongoing ransomware attack. “About 50% of the ransomware attacks out there leverage email as an entry point,” Skinner said, citing Trend Micro’s incident response team data.
Additionally, after the initial attack vector, more than “97% of attacks involve email at one point in the attack stream,” Young added.
“Almost every conversation now is about ransomware, and rightfully so, not only because of the incidents but because it is what a lot of the most advanced attackers are using,” Young said. Because zero trust involves continually assessing identity, users, devices, and the applications and infrastructure that they attempt to access, “that’s the kind of advance notice that organizations need now, rather than after you’ve been hit,” he added. “There’s always going to be indicators of posture, whether it's for a person, a device, an account, or one of your cloud resources — especially the ones that aren’t easily visible.”
Trend Micro SASE Coming Soon?Additionally, customers can use leverage Trend Micro’s risk scores for zero trust to feed third-party SASE and other platforms via APIs.
"They may already have a vendor in that [SASE] category, or they may choose one in the future, and we will absolutely plug in to that vendor’s product,” Skinner said, adding that Trend Micro’s risk assessment can help third-party SASE platforms make better security decisions about devices and users. “It’s kind of analogous to what some vendors are doing with querying EDR products and things like that, because they don’t have the insight themselves.”
However, in the future customers may be able to use Trend Micro’s own SASE capabilities. “We’re growing those secure access capabilities ourselves, and so a little bit later in the year, we will roll out some capability that customers could use standalone without having to integrate with a third-party vendor,” Skinner said.
Comments