With Zero Trust increasingly being turned to by companies what are the key considerations for implementation? asks Rob Smith, CTO, CloudClevr.
Cyber threats are an everyday occurrence now. According to the UK official NCSC (National Cyber Security Centre), 50 per cent of UK businesses reported a cyberattack in the last 12 months. This is much higher for medium-sized and large businesses. One of the most recent was the attack on NHS hospitals in London which had implications far beyond IT, risking peopleโs lives, disrupting treatments and leaking sensitive personal data. When attacks get sophisticated, itโs clear that many traditional security measures wonโt cut it anymore. Organisations need to think about new approaches and methodologies for safeguarding against cybercriminals and thatโs where Zero Trust policies become increasingly relevant.
What is the Zero Trust principle?
According to the NCSC, Zero Trust is a security approach where inherent trust in the network is removed. A traditional IT security policy trusts everyone inside a network. The problem with this approach is once anyone gets access to a network, they can easily move around within the network causing damage. In the era of remote working, Bring Your Own Device (BYOD), and cloud-based services, this traditional policy is no longer sufficient to secure organisations. Zero Trust operates on the principle of automatically trusting nothing and no one. If anyone wants access to resources inside a network, they need to be authenticated each time. โNever trust, always verifyโ is the principle.
Practical recommendations
A recent Okta research found that in just two years, adoption of this modern security framework has more than doubled, and only less than 10% of businesses neither have a Zero Trust initiative nor plan to develop one in the next 18 months. So, how can companies practically implement Zero Trust within their businesses? Some key elements need to be considered:
1) Give least privilege access
A fundamental principle of Zero Trust is to give users the least privilege. This means users have access to only the things they need to perform their jobs and nothing more.
Why is this important? Human error is often cited as the most common cause of risk in an organisation. If a criminal gains access to a privileged userโs account such as an IT admin, they can easily move laterally across the network causing further damage. If access is restricted, this lateral movement becomes impossible and we can contain the threat locally. The fewer people with elevated access, the lower the chances of a mistake causing a security vulnerability.
So, implement role-based access control that limits access to applications and data to the minimum. This is not just limited to your full-time employees, but contractors and third-party vendors to improve your supply chain resilience.
2) Verify continuously
Make sure you always validate the user. Multi Factor Authentication (MFA) is a good place to start to verify your identity. Itโs surprising how many companies still havenโt implemented MFA in their organisation. Microsoft Digital Defense Report observed that 21 per cent of customers who experienced ransomware didnโt have MFA or didnโt mandate MFA for privileged accounts. This one step can go a long way in making it harder for hackers to access your systems. However, validation shouldnโt be just limited to identity. Review other parameters, such as the time of access, location, type of device, IP address etc and flag if any of this is out of place.
Restricting access based on location is another easy way to bolster your security. This means people canโt access your network from locations outside the home country unless they use a VPN. This simple protective measure can mitigate a lot of generic attacks businesses usually fall prey to.
3) Use network segmentation:
In a Zero Trust approach, networks are segmented into small compartments. This is to limit the lateral movement in case of an attack and contain the blast radius. A simple aspect of implementing this in real life is segregating user and guest WiFi.
4) Assume breach
Another Zero Trust principle is to assume that a breach has already occurred in your business. Instead of focussing on how an attacker will get inside your perimeter, you assume theyโre already inside and think about minimising the damage. This is arguably the toughest one to implement because it requires a change in mindset on how you approach security. It requires constant vigilance, significant resource investment, and a proactive stance on security threats.
5) Continuous monitoring and detection:
No network is unbreachable. Along with prevention tactics, Zero Trust asks you to monitor the network traffic continuously for any signs of suspicious activities. Various EDR and XDR tools in the market scan your endpoint devices, cloud infrastructure and network devices. They use AI, machine learning and behavioural analytics to detect anomalies, such as the tone of the emails, to identify potential threats.
Is it possible to be 100 per cent Zero Trust?
Zero Trust sounds great in theory, but can you realistically build a 100 per cent Zero Trust environment? Maybe not. Achieving Zero Trust is a journey. Itโs not a switch you can simply turn on. It involves significant time, cost and effort, and since every organisationโs cyber security posture is different, their paths to achieving Zero Trust will also differ. A one-size-fits-all approach doesnโt work here and achieving a mature Zero Trust strategy can take several years.
If an organisationโs security posture is not that mature, it doesnโt make sense to implement Zero Trust fully right from the beginning. For them, itโs practical to start small, implement certain elements of Zero Trust that are important for the business and then scale gradually. On the other hand, if your security posture is already mature, you may have some elements of Zero Trust principles embedded in your business, whether you realise it or not.
In an ideal world, users would embrace Zero Trust right from the offset. But in reality, it can impact your user experience and slow down productivity if introduced the wrong way. Imagine users needing to authenticate themselves every single time they open Outlook. This increase in authentication points than theyโre used can cause frustration and resistance.
What then is a realistic solution? Instead of rolling out these policies universally, start with those who have elevated privileges and access the most sensitive areas of your network.
For instance, administrators could authenticate daily, while others might only need to authenticate once every seven days. Itโs essential to strike a balance between implementing Zero Trust and maintaining a smooth user experience. Adopt aspects of Zero Trust but make it practical. Youโre still embracing Zero Trust, just a more realistic version of it. Another point to remember is that Zero Trust is just one of a series of layers which together provide an organisation with resilience and improved cyber maturity.
Along with the different approaches to Zero Trust, mindset change and culture shift are equally important to fully adopting this concept.
Challenges of implementation
One main challenge of working towards Zero Trust is, of course, cost. You need skilled IT staff to guide you through this process, establish the right policies and procedures and a dedicated team to continuously monitor your services. Another obstacle is the opposition from the board or leadership team. They question the value of this investment or donโt see a need for it. They think โa breach is never going to happen to usโ. However, this is not a sustainable attitude as the evidence points to increasing levels of cyberattacks across all sectors and across all sizes of business.
Next steps
The key takeaway from implementing Zero Trust is the clear reduction in the total number of incidents and response times. When incidents do occur, they tend to be less severe, and the impact of breaches is significantly reduced. In a world where attacks are increasing and the levels of severity resulting from them is greater than ever companies have to look to move towards a Zero Trust approach.




