/* ---- Google Analytics Code Below */
Showing posts with label Zero Trust. Show all posts
Showing posts with label Zero Trust. Show all posts

Thursday, October 20, 2022

Cisco on Zero Trust

Good piece on the topic.  Full article at the link.

There’s no better time for zero trust

By Neville Letzerich

Security resilience requires strong, user-friendly defenses

The concept of zero trust is not a new one, and some may even argue that the term is overused. In reality, however, its criticality is growing with each passing day. Why? Because many of today’s attacks begin with the user. According to Verizon’s Data Breach Investigations Report, 82% of breaches involve the human element — whether it’s stolen credentials, phishing, misuse or error.

Additionally, today’s businesses are hyper-connected, meaning that — in addition to your employees — customers, partners and suppliers are all part of your ecosystem. Couple that with hybrid work, IoT, the move to the cloud, and more emboldened attackers, and organizational risk increases exponentially.

Adopting a zero trust model can dramatically reduce this risk by eliminating implicit trust. It has become so crucial, in fact, that several governments including the U.S., UK and Australia have released mandates and guidance for how organizations should deploy zero trust to improve national security.

However, because zero trust is more of a concept than a technology, and so many vendors use the term, organizations struggle with the best way to implement it. At Cisco, we believe you should take a holistic approach to zero trust, starting with what you have and adding on as you identify gaps in your defenses. And while layers of protection are necessary for powerful security, so is ease of use.

Strengthen security resilience with zero trust

Zero trust plays a major role in building security resilience, or the ability to withstand unpredictable threats or changes and emerge stronger. Through zero trust, the identity and security posture of users, devices and applications are continuously checked and verified to prevent network intrusions — and to also limit impact if an unauthorized entity does gain access.

Organizations with high zero trust maturity are twice as likely to achieve business resilience.

– Cisco’s Guide to Zero Trust Maturity

Eliminating trust, however, doesn’t really conjure up images of user-friendly technology. No matter how necessary they are for the business, employees are unlikely to embrace security measures that make their jobs more cumbersome and time-consuming. Instead, they want fast, consistent access to any application no matter where they are or which device they are using.

That’s why Cisco is taking a different approach to zero trust — one that removes friction for the user. For example, with Cisco Secure Access by Duo, organizations can provide those connecting to their network with several quick, easy authentication options. This way, they can put in place multi-factor authentication (MFA) that frustrates attackers, not users.

Enable seamless, secure access

Cisco Secure Access by Duo is a key pillar of zero trust security, providing industry-leading features for secure access, authentication and device monitoring. Duo is customizable, straightforward to use, and simple to set up. It enables the use of modern authentication methods including biometrics, passwordless and single sign-on (SSO) to help organizations advance zero trust without sacrificing user experience. Duo also provides the flexibility organizations need to enable secure remote access with or without a VPN connection. ...' 

Friday, August 12, 2022

Report: Orgs with zero-trust segmentation avoid 5 major cyberattacks annually

Report on Zero Trust Segmentation.

Report: Orgs with zero-trust segmentation avoid 5 major cyberattacks annually  in Venturebeat

 A new report by Illumio found that organizations leveraging zero-trust segmentation avert five major cyberattacks annually, saving more than $20 million in downtime costs.

In the past two years, digital transformation has drastically expanded the attack surface. Where IT was once a walled-in, on-premises technology environment, a modern IT architecture now consists of on-prem, public and multiclouds. This surge in connectivity and growing hybrid complexity has led to a dramatic uptick in the number of vulnerable endpoints (i.e., laptops) and a widening attack surface. In fact, in the past two years alone, 76% of organizations have been the victim of a ransomware attack and 66% have experienced at least one software supply chain attack.

Most surprisingly, the report found that 47% of security leaders do not believe they will be breached — despite increasingly sophisticated and frequent attacks and rising zero-trust adoption rates (even though “assume breach” is a core principle of zero trust).

Zero-trust segmentation saves $20 million in app downtime, averts 5 cyber disasters, and accelerates 14 digital transformation projects annually.

What’s more, the report uncovered that 81% of organizations agree that zero-trust segmentation plays a critical role in accelerating broader zero-trust efforts. According to ESG, organizations classified as advanced segmentation users were 2.1X more likely to have avoided a critical outage during an attack over the last 24 months. These organizations are also bolstering competitive advantages with 14 more cloud and digital transformation projects planned over the next 12 months.  .... ' 

Tuesday, November 30, 2021

Cisco on Zero Trust Security

Future of Zero Trust

Security

An Open Security Ecosystem with Shared Signals is the Future of Zero Trust

By Nancy Cam-Winget  Cisco

Zero Trust: as the name implies, is the strategy by which organizations trust nothing implicitly and verify everything continuously. This industry north star is driving different architectures, frameworks, and solutions to reduce an organization’s risk and improve their security posture.   Beyond the need to enforce strong authentication and authorization to establish trust of an endpoint, how can we verify continuously? Often, the zero-trust approach today uses strong authentication and tools that evaluate the security of the user and device at the point of access, but what happens when the security posture of the user and device change after its initial access request is granted?

With many vendors offering impressive security capabilities in cybersecurity, there is a wealth of information that can be shared. Unfortunately, this information is fragmented and lacks standardization and thus interoperability. Getting all these best-in-class vendors to talk to each other is an expensive and time-consuming task, leaving organizations with disparate signal silos and a serious lack of visibility and control across their environment.

This is the problem the OpenID Foundation’s Shared Signals and Events working group is poised to address. For the unfamiliar, the OpenID Foundation is a non-profit organization that promotes open, interoperable standards with OpenID at its core, most notably the standardization of a simple identity layer on top of Oauth 2.0: OpenID Connect. The Shared Signals and Events working group lives within the OpenID Foundation and is comprised of industry leaders and innovators working to promote more open communication between systems. Shared Signals and Events standards like CAEP and RISC have the goal of enabling federated systems with well-defined mechanisms for sharing security events, state changes and other signals. This communication in turn simplifies interoperability and allows organizations to get closer to the Zero Trust ideal of continuously evaluating and enforcing security.

In its first ratified standard, the Shared Signals and Events working group created an open standard through which multiple services can communicate by publishing or subscribing relevant event streams. The standard drastically simplifies communication between applications with security context.  For example, a cloud application might subscribe to events from an endpoint detection and response solution to quickly remove access from infected systems. Alternatively, an IAM solution might publish a change of user context used by a SIEM tool to start an investigation.  An example shown below demonstrates how a device or an application performs an HTTPS service request in step 1 can trigger an update to a change in state to a policy server in step 2.  Further, a policy service can determine whether that change in state needs to be broadcasted to other subscribers (step 3).  A subscriber to that event can process the information and determine if a remediation response (step 4) is needed.  ... '

Saturday, September 25, 2021

Zscaler and Siemens Join for Zero Trust

Interesting example of Zero trust security, for operational and IOT systems

Zscaler and Siemens join to bring zero-trust security to operational technology systems

 Analysis by Zeus Kerravala

Zscaler Inc. and Siemens AG announced an interesting partnership this week wherein the two vendors are bringing zero-trust security to operational technology systems.

OT systems are most commonly found in industrial networks but are seeing increased adoption in other industries. Historically, OT systems ran on their own proprietary networks that were often isolated from the company’s data networks. Industry leaders have been predicting that information technology and OT systems would eventually come together, but that has been slow to materialize in industrial settings.

Some OT systems have been integrated with IT networks, such as building facilities like alarm systems, LED lighting and heating and air conditioning systems as part of smart building initiatives, but that has been more the exception than the norm in industrial settings.

The COVID-19 pandemic forced many organizations down the IT-OT path as workers required access to the OT systems from home and the most cost-effective way to do that was to enable VPN access through the data network. That enables workers to remotely manage and control systems and diagnose problems.

Although VPNs were successful in connecting workers to industrial systems quickly, they are not ideal because they create a back door into the industrial “internet of things” environments. That greatly expands the organization’s attack surface and exposes the business to large-scale network attacks.

Some organizations have turned to firewall-based network segmentation, and that can work, but it is very complicated to set up and is even more difficult to keep updated in dynamic environments. That’s because every time a device moves, the segmentation policies must be updated. Coarse-grained segmentation is widely used, but businesses have struggled with fine-grained segmentation, which is needed in IoT environments to minimize the impact of a breach.  ... ' 

Dial the Trust Down to Zero

The way to make security work

Dialing the Trust Level Down to Zero

By R. Colin Johnson, Commissioned by CACM Staff, September 23, 2021

Twenty-first century cybersecurity has been steadily moving away from the "perimeter" mentality—authenticating users with passwords, then giving them free access to a computer system's resources at their security level. Stolen passwords, especially those with high levels of access, have resulted in catastrophic releases of vast swaths of personal information (like credit card numbers), government secrets (witness WikiLeaks' releases of classified information), and related crimes (including ransomware).

Now the trust bestowed on authenticated users is being rescinded. The perimeter defense architecture is being superseded by the Zero Trust Architecture (ZTA), which authenticates each user action before it is executed. The U.S. government mandated ZTA and other measures in the May 12, 2021 Executive Order on Improving the Nation's Cybersecurity, which reads, in part: "The Federal Government must adopt security best practices; advance toward Zero Trust Architecture; accelerate movement to secure cloud services, including Software as a Service (SaaS)…and invest in both technology and personnel to match these modernization goals."

The Executive Order also charged the National Institute of Standards and Technology (NIST) with detailing these best practices in a Zero Trust Architecture report.

Said Steve Turner, an analyst at Forrester Research, "Public policy has finally acknowledged that the current model of cybersecurity is broken and outdated, mandating that the model of Zero Trust Architecture become the default method for implementing cybersecurity. With the relentless destructive attacks on computer systems, such as ransomware, there's been a collective realization that Zero Trust should be the de facto standard to secure organizations."

At the same time, the computer hardware itself must be adapted to the ZTA, starting with end-to-end encryption of all data before, after, and ideally even while it is inside the processor. Ubiquitous encryption is just the start. Today, any component—from wireless routers to individual server chips—can offer unauthorized access to intruders. Firmware—from unauthorized swapping of solid state disks (SSDs) in the datacenter, to thumb-drives plugged into user-access devices—are especially vulnerable. Even hardware components without firmware can become dispensers of malware via, for instance, hidden hardware Trojan horses that are impossible to detect by visually inspecting chips. As a result, hardware Roots-of-Trust with certifiable validation followed by chain of custody verification also are being incorporated into the ZTA—starting from the hardware for an initial computer installation, and continuing unabated through firmware and hardware updates, until its eventual retirement.  ... ' 


Monday, June 28, 2021

Extending Zero Trust Security

Security in Industrial Networks

Extending Zero Trust Security to Industrial Networks

Ruben Lobo, Cisco

Recent cyber attacks on industrial organizations and critical infrastructures have made it clear: operational and IT networks are inseparably linked. With digitization, data needs to seamlessly flow between enterprise IT and industrial OT networks for the business to function. This tighter integration between IT, OT, and Cloud domains has increased the attack surface of both – the industrial and the enterprise networks.

The traditional security perimeter that industrial organizations have built over the years by installing industrial demilitarized zone (IDMZ) is no longer sufficient. While this is still the mandatory first step to protect operations, embracing the digital industry revolution requires additional security measures, assuming that no user, application, or connected device are trustworthy anymore.

The Zero Trust Security model that many are now implementing to secure the enterprise workforce, workloads, and the workplace must be extended to industrial operations. It continuously verifies resources to establish trust and compliance in every access request. It identifies not just users, but endpoints, and applications to grant them the absolute minimum access they need.

I recently presented a webinar explaining the specific Zero Trust requirements for IoT/OT networks:  ... '

Wednesday, May 05, 2021

IBM Helps Customers Adopt a Zero Trust Approach to Security

New security architectures, alliance moves by IBM.  

IBM Helps Customers Adopt a Zero Trust Approach to Security

CAMBRIDGE, Mass., May 5, 2021 /PRNewswire/ -- IBM (NYSE: IBM) Security today introduced a new Software as a Service (SaaS) version of IBM Cloud Pak for Security, designed to simplify how organizations deploy a zero trust architecture across the enterprise. The company also announced an alliance partnership with leading cloud and network security provider, Zscaler, and new blueprints for common zero trust use cases. For security professionals, zero trust is a framework for modernizing their  ... ' 

Tuesday, March 02, 2021

Spending in a Solarwinds and COVID Context

Interesting to see the specific implications of security and supply chain contexts. 

Breaking Analysis: How the SolarWinds Hack & COVID are Changing CISO Spending Patterns By David Vellante  FEBRUARY 13 2021  in WikiBon

Top security pros say that the SolarWinds hack and the pandemic have accelerated a change in their cyber security spending patterns. Not only must CISOs secure an increasingly distributed workforce, but they now must also be wary of software code coming from reputable vendors, including the very patches designed to protect them against cyber attacks. Organizations are increasingly prioritizing zero trust approaches including simplified identity access management, better endpoint protection and cloud security. While leading solutions in these sectors are gaining momentum, traditional legacy offerings are being managed down from a spending perspective. 

In this Breaking Analysis, we’ll summarize CISO sentiments from a recent ETR VENN session and provide our quarterly update of the cybersecurity sector. In an upcoming episode we’ll be inviting Erik Bradley of ETR to provide deeper analysis on these trends. Here we’ll give you a first look and our initial take on what’s happening in the information security sector as we kick off 2021. 

The SolarWinds Attack was “Like Nothing We’ve Ever Seen”

It’s been covered in the press but in case you don’t know the details, SolarWinds is a company that provides software to monitor many aspects of on-prem infrastructure, including network performance, log files, configuration data, storage, servers, etc. Like all software companies, SolarWinds sends out regular updates and patches. Hackers were able to infiltrate the update and “trojanize” the software. Meaning when customers installed the updates, the malware just went along for the ride.   ... ' 

Tuesday, February 09, 2021

On Zero Trust

 Elements of Zero Trust

Closing the Cloud Permissions Gap to Achieve Zero Trust: An AWS Risk Assessment  by Sarah on January 26, 2021   Author: Raj Mallempati, COO of CloudKnox

Whether it is to adapt to remote work, improve innovation, or build agile teams, organizations continue to prioritize digital transformation for myriad reasons. And, while there are many business benefits to digital transformation strategies—from boosted productivity to tools that unlock new functions—there are also significant cloud infrastructure security risks that enterprises must mitigate to benefit from their investments fully.

An organization must also carefully balance this emphasis on digital transformation with Zero Trust. A major pillar of the Zero Trust model is the ability to limit excessive user entitlements. Yet, in the cloud, this is very difficult to accomplish when cloud service providers are adding new services and permissions, developing at such a fast pace and attempting to understand the complexity of thousands of permissions daily.

A major cloud security risk, as an example, is associated with the human and non-human identities operating within organizations’ hybrid and multi-cloud environments. In fact, through extensive research and analysis evaluating organizations using Amazon Web Service (AWS), CloudKnox Security Research Labs has discovered a significant delta between permissions granted and permissions used in these environments. This delta is called the Cloud Permissions Gap, and it is a contributing factor to the rise of both accidental and malicious insider threats impacting enterprises of all sizes. Here, attackers are able to exploit an identity with elevated permissions and access across the organization’s critical cloud infrastructure while the organization is unable to implement and manage Zero Trust policies.

Since the Cloud Permissions Gap is challenging to navigate and poses an immediate threat, CloudKnox takes a deeper look into the AWS risk assessment for cloud permissions management to outline where the risks are and offer best practices to mitigate them.

What is the Cloud Permission Gap, and why is it dangerous?

The Cloud Permissions Gap exists across any organization that has adopted public cloud or hybrid cloud infrastructures, making the organization incredibly vulnerable to both accidental and malicious threats. How does this happen, and why is it universally prevalent? Although identities should only have the permissions they need for their specific job functions, a CloudKnox assessment of more than 150 global enterprises uncovered that more than 95% of all identities accessing their organizations’ AWS infrastructure are using less than 2% of their permissions granted. Even worse, 40% of all AWS roles were reported as inactive or over permissioned.   ... "