Zero Trust Security: What It Is and Why It Matters Now

Zero Trust Security

Zero Trust Security: What It Is and Why It Matters Now

From the onset of the Digital Age, online businesses have protected their networks by fortifying the perimeter. Firewalls, antivirus software, and passwords kept unauthorized users out. But once a user was inside, the security model assumed they could be trusted. As business network usage has expanded, that approach has proven increasingly inadequate. Cybercriminals preying on remote workers can often obtain legitimate usernames and passwords through phishing, credential theft, and other attacks. Once inside the network, their ability to move from one system to another is often unconstrained.

Zero Trust security addresses this problem by eliminating the assumption that a user who has been granted entry is automatically trustworthy.

The Cold War Origin of “Trust, but Verify”

For readers of a certain age, the term zero trust will conjure memories of the phrase “trust but verify,” popularized during Pres. Ronald Reagan’s Cold War diplomacy. Few people remember that Reagan didn’t coin the term. It came from an old Russian proverb—doveryai, no proveryai—that Mr. Reagan learned during his negotiations with Soviet leader Mikhail Gorbachev. The American scholar and Russian specialist Suzanne Massie, whom Reagan consulted about Russian history and culture, encouraged him to learn Russian proverbs because the Russians liked to communicate through them.

Reagan first used the expression publicly in connection with the Intermediate-Range Nuclear Forces Treaty, negotiations that culminated in the December 1987 agreement eliminating an entire class of U.S. and Soviet nuclear missiles. In September 1987, Reagan explained that the proposed INF treaty would require an extraordinarily stringent verification system. He then introduced the proverb in Russian: “Dovorey no provorey.”

The phrase expressed an apparent contradiction in Reagan, whom many saw as an old Cold Warrior, who did not shy away from calling the Soviet Union an “evil empire.” When challenged as to whether negotiating with Gorbachev meant Mr. Reagan had abandoned his earlier position, the President explicitly answered, “I haven’t changed from the time when I made a speech about an evil empire.”

Reagan understood, as many Americans did, that Soviet leadership had a history of violating or evading international agreements. He acknowledged that absolute verification was impossible, but argued the United States should obtain as much verification as technologically and diplomatically possible. The INF Treaty therefore included unusually intrusive measures, including on-site inspections and monitoring designed to make cheating considerably more difficult to conceal.

President Reagan wanted a treaty, but he was not going to sign one and just assume the Soviets would follow its terms in good faith. Any treaty that actually made the world safer needed a mechanism to verify compliance at every critical juncture. Your business network should settle for nothing less.

What is zero trust security?

Zero Trust is a cybersecurity approach based on a simple principle: never trust automatically; always verify. The National Institute of Standards and Technology (NIST) describes Zero Trust Architecture as a model that does not grant implicit trust to users or devices simply because they are located inside an organization’s network. Instead, authentication and authorization occur before access to an enterprise resource is established.

In practical terms, Zero Trust means that being connected to the company’s Wi-Fi, having a company-issued laptop, or having previously logged into an application does not automatically grant unrestricted access. Every access request is evaluated according to factors such as:

  • Who is requesting access?
  • What device are they using?
  • Is the device properly secured?
  • What application, system or data are they attempting to access?
  • Does the user actually need that access to perform their job?
  • Does the request present unusual or elevated risk?

The objective is to provide the minimum level of access necessary rather than giving users broad access to an entire network.

Why traditional network security is no longer enough

The traditional “castle-and-moat” security model was designed around a relatively simple assumption: trusted employees and systems were inside the perimeter, while threats were outside. Modern businesses no longer have a clearly defined perimeter.

A New Jersey employee might work from home in Bergen County, connect through a coffee-shop Wi-Fi network in Hoboken, access Microsoft 365, or another cloud application, and then connect to a company server in an office in Morris County—all during the same workday.

Cloud computing, remote work, mobile devices, and third-party services have effectively dissolved the traditional network boundary. NIST specifically identifies these developments as reasons organizations need to rethink perimeter-based security.

Zero Trust instead assumes that an attacker could already be present somewhere in the environment. Consequently, compromising one account or device does not automatically give an attacker unrestricted access to everything else.

How Zero Trust helps stop modern cyber threats

One of the greatest advantages of Zero Trust is its ability to limit the damage caused by a successful intrusion. Consider a phishing attack. An employee inadvertently provides a criminal with valid login credentials. Under a traditional security model, those credentials might allow the attacker to enter the corporate environment and begin exploring other systems.

A Zero Trust architecture can require multifactor authentication, verify the device being used, restrict the employee’s permissions and evaluate the request based on its risk. Even if the credentials are legitimate, access to sensitive applications or information can still be denied.

Zero Trust can also reduce lateral movement—an attacker’s ability to move from one compromised computer or account to other systems. NIST identifies unrestricted lateral movement following a perimeter breach as a significant weakness of traditional network security.

Other important Zero Trust protections include:

  • Multifactor authentication — Passwords alone are not sufficient to establish identity.
  • Least-privilege access — Employees receive only the permissions required for their jobs.
  • Device security — Access can depend on whether a computer or mobile device meets defined security requirements.
  • Network segmentation — Sensitive systems can be isolated so that compromising one system does not expose the entire network.
  • Continuous monitoring — User, device and network activity can be monitored for suspicious behavior.
  • Application and data controls — Security policies can be applied directly to applications and sensitive information rather than relying exclusively on network location.

The Cybersecurity and Infrastructure Security Agency, an agency of the US Department of Homeland Security, has composed a Zero Trust Maturity Model organized around five pillars:

  • Governance — Decision-makers establish the policy (e.g., only authorized personnel using compliant devices may access the database).
  • Visibility and analytics — The mechanisms determine who the employee is, what device is being used, whether the device is compliant, from where the request originates, and whether the behavior appears unusual.
  • Automation and orchestration — These mechanisms apply the appropriate response. If everything checks out, access is granted. If the attempted entry appears suspicious, access is restricted automatically and the security team alerted.

The results are shared with the decision-makers who re-examine the policy in light of events. The result is a continuous feedback loop where performance is analyzed and optimized.

The role of an MSP in implementing Zero Trust

For a small or medium-sized New Jersey business, implementing Zero Trust can appear complicated. An organization may not have the personnel or expertise to redesign its identity management, endpoint security, network architecture, and access policies internally. That is where a Managed IT Services Provider, such as KMF Technologies, can play an important role.

An MSP can begin with an assessment of the company’s existing environment. This includes identifying users, devices, applications, cloud services, sensitive data, and existing access privileges. The MSP can then determine where excessive permissions, outdated systems, or weak authentication protocols create unnecessary risk. Implementation may include deploying or strengthening:

  • Multifactor authentication and identity management
  • Endpoint detection and response
  • Mobile-device and endpoint management
  • Conditional access policies
  • Network segmentation and secure remote access
  • Least-privilege permissions
  • Security monitoring and logging
  • Vulnerability and patch management
  • Backup and recovery systems
  • Employee cybersecurity training

Importantly, Zero Trust does not have to mean replacing an entire IT environment overnight. NIST emphasizes that organizations can develop a Zero Trust architecture progressively, incorporating existing technologies and moving toward more granular access controls over time.

Zero Trust is an ongoing process

Zero Trust is not a single security product your business purchases and installs. It is an approach to managing cybersecurity without making network usage too difficult or tedious for your employees. At KMF Tech, our IT pros help businesses develop a practical Zero Trust roadmap, implement the necessary technologies, and continually monitor and refine the environment.

In an era of ransomware, credential theft, phishing, remote work, and cloud computing, you can’t afford to trust a user simply because they’ve gained access to your network. Zero Trust is your hall monitor, acting to verify the user, verify the device, limit access, and oversee activity. The Zero Trust approach can make the difference between a security incident you contain and one that becomes a crisis. Let KMF Tech show you how. Call us today.

Author: Rick Ferreira


Previous Mobile Device Management: Keeping Company Data Safe on the Go