Zero Trust is a relatively new and evolving approach to network design, but also part of a wider security mindset, one which is often misunderstood.

The term ‘Zero Trust‘ was first coined by research analyst and thought leader John Kindervag, is derived from his motto, “never trust, always verify.” His innovative & ground-breaking point of view is based on the assumption that risk is an inherent factor both inside and outside a network.

What is Zero Trust?

Zero Trust is a security framework requiring all users, whether they are inside or outside an organisation’s network, to be authenticated, authorised, and continuously validated based on their security configuration and posture before being granted or retaining access to an organisation’s network and data.

The Zero Trust framework assumes that there is no traditional network edge and that networks can be local, in the cloud, or a combination of both with resources and employees in any location. The framework uniquely addresses the challenges of modern businesses, including remote workers, hybrid cloud environments, and ransomware threats.

How Zero Trust Works

The implementation of the Zero Trust framework involves the effective combination of highly experienced cyber security professionals and advanced technologies and procedures such as multi-factor authentication and next-generation endpoint security. These are used in synergy to verify a user’s identity, consider their access rights, and maintain network security.

The process of achieving Zero Trust can be broken down into ten simple principles, recommended by the NCSC, which are:

  1. Knowing your organisation’s network architecture, including users, devices, and services.
  2. Creating a strong user identity.
  3. Creating a strong device identity.
  4. Including authentication in all aspects of network access.
  5. Knowing the health of your devices and services.
  6. Focusing on monitoring your devices and services.
  7. Setting policies according to the value of services or data.
  8. Controlling access to your services and data.
  9. Choosing services with zero trust in mind.
  10. Working with other organisations that implement zero trust.
How is Zero Trust different from traditional network security?

Traditional network security follows the ‘trust but verify’ method. This approach automatically trusts users and endpoints within the organisation’s network, putting the organisation at risk from malicious internal threat actors and external threat actors who have gained access to legitimate credentials. The “trust but verify” method can enable unauthorised and compromised accounts to have far-reaching access once they enter a network.

Traditional network security became largely obsolete during the migration to cloud services, a process which accelerated when distributed work environments grew in popularity as a result of the COVID-19 pandemic.

In comparison to ‘trust but verify’, the Zero Trust framework requires organisations to continuously monitor and validate that a user and their device have the appropriate privileges and attributes. It also requires enforcement of policies that incorporate the risk of the user and device, along with compliance procedures and other requirements that need to be considered before access, interaction, or transfers are permitted. In order for zero trust to be put in place, an organisation must know all of their user accounts and establish controls about what these accounts can access.

Zero Trust policies also rely on real-time visibility into hundreds of user and application identity attributes. This is to ensure that all access requests are continuously vetted prior to allowing access to an organisation’s network.

Why is Zero Trust important?

More than 80% of all attacks involve the use or misuse of credentials in a network. Zero Trust is important as it recognises that all user accounts are a risk to the security of a network, as hackers increasingly disguise themselves as legitimate users.

But in addition to delivering significant improvements to an organisation’s cyber security, zero trust also reduces the costs and complexity while providing greater peace of mind for IT leaders and business owners.

If you’re interested in implementing zero trust in your organisation and have any questions about current cybersecurity trends and practices, get in touch using the contact form below.

TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.