Listen to this episode

What is a "Zero-Trust" Framework, and is it Right for Your Business?

0:0048:51

Recorded May 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of Encrypted Ambition, Craig is joined by Blake and Erin to discuss zero trust frameworks and whether businesses should adopt them. Craig defines zero trust as refusing to trust vendors or proprietary code by default, instead relying on technologies that are continuously vetted and tested, citing open source end-to-end encrypted messaging as an example.

The group discusses the NIST SP 800-207 publication on zero trust architecture and, at the time of recording, regulatory interest in zero trust such as the Biden executive order. Craig explains that remote work, bring your own device, and cloud assets have made the assumption of implicit trust inside a corporate network outdated. He argues that data and email are usually the easiest starting points, followed by applications, hardware, and network layers, and stresses that a proper assessment must come first so new tools do not break existing workflows. The conversation covers limiting breach impact through segmentation, encryption, and passwordless technology, XDR and automated context collection, vendor risks illustrated by the SolarWinds and Target incidents, separating IT and cybersecurity roles, and Craig's view that Apple and Microsoft should lead adoption.

Worth remembering

Key takeaways

  1. Blake cites a definition requiring every user, inside or outside the network, to be authenticated, authorized, and continuously validated before accessing applications or data.
    “requiring all users, whether they're inside or outside of the organization's network to be authenticated authorized and continuously validated for security, configurations, and posture before being granted or access”
  2. Craig argues that depending on one company's closed, proprietary code is not zero trust, because that code is not continuously vetted.
    “Whereas if you're trusting a single company that has proprietary code. And they don't share and they're not open with their code and configuration. Well, that's not, that's not zero trust because they're, it's not continuously vetted.”
  3. Craig highlights that older security models implicitly trusted everything inside the network, which allowed threat actors and malicious insiders to move laterally.
    “Zero trust was created based on the realization that traditional security models operate on the outdated assumption that everything inside an organization's network should be implicitly trusted”
  4. Craig says the data and email components are usually the easiest place for a business to begin moving into a zero trust model.
    “The data and email components are usually the easiest to move into some type of zero trust model”
  5. Craig stresses that a proper evaluation, discovery, and assessment process must come first, since tools adopted hastily may not fit a company's workflows.
    “But a proper evaluation discovery and assessment process has to be followed because if you just go sign up for something, it may not work and be compatible with your workflows and how you operate.”
  6. Craig says embracing technology that does not rely on passwords provides better protections against phishing and business email compromise.
    “if you embrace the technology that doesn't rely on passwords, for example, well, now you're raising the bar in regards to providing better protections against phishing and business email compromise”
  7. Craig argues the same IT provider should not handle both IT setup and cybersecurity without clear separation, because that creates a conflict of interest.
    “you've got one it guy and his name's Bob, Bob should not be doing it setup and configuration and it security or cybersecurity.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

With the rash of cyberscams and a huge portion of the workforce going remote, there has been a lot of talk about implementing a "Zero-Trust Framework." But what is it exactly? Are there any drawbacks, and is it something that will work for your company?

Find out as the Petronella Technology Group team discusses all this and more!

Hosts : Craig, Blake, and Erin

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.