Okta's latest annual "The State of Zero Trust Security" report offers a look into how organizations are embracing the zero-trust security model and the resulting surge in its investments.
The identity and access management (IAM) vendor partnered with Qualtrics to conduct a survey of 860 information security decision-makers worldwide in April 2023 across a range of industry verticals, focusing on the healthcare, public sector, financial services and software verticals.
The report showed almost all (96%) of organizations either already have a zero-trust security initiative in place or plan to start one within the next 18 months and 61% are well into their zero-trust journey in 2023, compared to only about one in four in 2021.
Meanwhile, smaller organizations with 500-999 employees have been somewhat slower in adopting this security measure compared to their larger counterparts with 5,000 to 9,999 employees.
Okta’s report also revealed trends across regions and industries. North America is leading the zero-trust charge with 73% of organizations having a defined strategy and Japan and Australia were least likely to have one at 47%. In terms of industries, the financial services sector narrowly edges out the software industry with 71% adoption compared to 69%.
Okta report shows a rise in zero-trust investmentDespite macroeconomic struggles, zero-trust security budgets have been on an upward trajectory.Eighty percent of respondents reported that their organization’s zero-trust budgets had increased over the past year, Okta’s report found.
Globally, while 60% of organizations reported a modest less than 24% budget increase, another 20% witnessed a surge of over 25% since last year. Only less than 3% indicated a decline.
“This year’s report shows organizations globally are deepening their zero-trust investments despite economic headwinds,” Okta Regional CSO Chris Niggel told SDxCentral in an email.
Identity is mission-critical for a zero-trust strategyNiggel also said that the report showed more organizations started recognizing that identity is the cornerstone of zero trust, with 91% of this year’s respondents saying identity is important, jumping from 71% last year.
“We’re not surprised to see this change of heart, as more and more organizations come to realize that strong identity access management is a fundamental strategy to keep people and assets safe in a hybrid/multi-cloud world,” the report wrote.
However, even as organizations lean into zero trust, the reliance on passwords remains a pressing concern.
The report found over half (55%) of organizations still deploy passwords to verify internal and external users and only 19% adopted more secure and high-assurance methods like biometrics for authentication.
Although the adoption of zero-trust initiatives continues to grow, passwords continue to be the leading authentication factor across industries,” Niggel said. “As we look to the future, however, we’re seeing higher adoption of easy-to-use phishing-resistant factors such as Yubikey and biometrics.”
“With the increasing impact of cyberattacks on organizations, getting away from passwords and security questions should be a strong focus for every company,” he added.
Comments