×

Latest News

What is a Zero Trust security model and why are more and more companies using it?

Some indications from ESET Italy

By Fabio Buccigrossi, Country Manager of ESET Italia

Even before the pandemic, a survey of early 2020 by Cybersecurity Insiders and Pulse Secure on more than 400 IT managers from companies around the world, varying in size and sector, showed that 72% of them were considering implementing the Zero Trust model in their security strategy. Improving cybersecurity is also urgent at a national level, so much so that the Italian government recently approved a decree-law establishing the National Cybersecurity Agency (ACN) with the aim of protecting the essential functions of the State from cyber threats and developing the capabilities to prevent and counter them adequately.

What does Zero Trust mean specifically?

Zero Trust is a term coined in 2010 by Forrester Research analysts and identifies a security model that follows the principle of "never trust and always verify" every entity, whether internal or external to the corporate perimeter of an organization. Through this approach, which does not allow a priori trust, the security of each of a company's resources and key entities, such as data, networks, devices, workloads and people, is guaranteed.

The substantial difference compared to the traditional IT security model is that, while the latter considers everyone within the corporate network as trustworthy by default, thus compromising the security of the organization's resources if an attacker manages to access it, the Zero Trust model assumes that the latter is already within the network, thus avoiding giving indiscriminate trust to users and devices without prior control.

How to implement the Zero Trust model in the company?

An organization that decides to implement the Zero Trust model should develop the following three key areas:

Visibility: it is important to identify the devices and resources to monitor and protect, thus having visibility over all assets and access points.

Policy: it is necessary to establish effective policies that allow only certain people to access specific resources.

Automation: processes must be automated to ensure the correct application of policies, also allowing the organization to quickly adapt to any changes compared to standard procedures.

By leveraging these three elements, the Zero Trust security model is capable of building defenses around each critical business entity.

Why is there more and more interest in adopting the Zero Trust model?

As the researchers report Forrester, the Zero Trust methodology allows you to control and know all the data you have at any time and, in the event of a security breach, it is able to promptly detect the moment and place where the attackers may have stolen the data. Starting from the assumption that, how highlights According to the 2020 report from IBM and Ponemon Institute, the average cost of a data breach globally is $3.86 million and the average time to identify and contain it is 280 days, the Zero Trust model represents a valid solution.

Other aspects to consider are the growing diffusion of the approach Bring Your Own Device (BYOD) and remote working methods, which require employees to be able to access the internal resources of their organization from anywhere and at any time; the increase in attempts to brute force attack against Remote Desktop Protocol (RDP), recorded during the pandemic, and the growing adoption and use of cloud storage services to host critical business data, resources and services.

Further problematic vectors for the traditional perimeter security model are the supply chain attacks, the outsourcing of services and the employee turnover.

For further information and to find out in detail how ESET implements the Zero Trust approach to Endpoint Security in practice, we recommend the webinar scheduled for 21 October 2021 at 10.30 am. More information on this link.

For more information see www.welivesecurity.com

TOP