{"id":16084,"date":"2023-01-30T13:58:49","date_gmt":"2023-01-30T18:58:49","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=16084"},"modified":"2024-08-26T14:23:50","modified_gmt":"2024-08-26T18:23:50","slug":"the-rise-of-zero-trust-threats-are-no-longer-perimeter-only-concerns","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/the-rise-of-zero-trust-threats-are-no-longer-perimeter-only-concerns\/","title":{"rendered":"The Rise of Zero Trust: Threats Are No Longer Perimeter-Only Concerns"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-the-zero-trust-strategy-approaches-security-from-the-mindset-that-no-one-not-even-your-internal-network-users-can-or-should-be-trusted-automatically-here-s-why-zero-trust-security-is-picking-up-traction-with-organizations-and-governments-globally\">The zero-trust strategy approaches security from the mindset that no one \u2014 not even your internal network users \u2014 can or should be trusted automatically. Here\u2019s why zero trust security is picking up traction with organizations and governments globally\u2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u2026 It\u2019s not paranoia when someone really <em>is<\/em> out to get you. And if you\u2019re an organization or business, you can virtually guarantee that someone, somewhere has you in their crosshairs. <a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\">Verizon reports<\/a> 82% of data breaches involve the \u201chuman element\u201d \u2014 including everything from phishing and social attacks to general errors and misuse \u2014 so, it\u2019s clear why all organizations need to change how they approach cyber security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why the <a href=\"https:\/\/www.defense.gov\/News\/Releases\/Release\/Article\/3225919\/department-of-defense-releases-zero-trust-strategy-and-roadmap\/\">U.S. Department of Defense published information<\/a> regarding plans to shift its network to a \u201czero trust architecture\u201d by 2027. In its Zero Trust Strategy and Roadmap document, the federal defense agency shared its goals about what it aims to achieve and what its vision is for the future: implementing stronger defenses against cyber attacks via a dynamic and adaptive approach (zero trust).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This move toward zero trust security has been picking up traction with businesses and other organizations globally over the past several years. It contrasts the traditional notion that cyber security efforts should focus on external threats and hardening your perimeter defenses to protect against threats outside your network. Imagine the cyber security incidents (and resulting data breaches) that could have been avoided if the targeted organizations had implemented zero trust:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what is zero trust and why is it something that can benefit organizations and businesses across all sectors (not just the DoD)?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-zero-trust-security-the-strategy-of-trusting-nothing-verifying-everything\"><a>What Is Zero Trust Security? The Strategy of Trusting Nothing &amp; Verifying Everything<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Zero trust<\/strong> is an organization\u2019s answer to the childhood warning \u201cstranger danger!\u201d It\u2019s both a framework and strategy that operates with the understanding that no one \u2014 not you, your devices, your apps, or even your CEO \u2014 can (or should) be trusted automatically. And it\u2019s nothing personal \u2014 it\u2019s not because your IT admin doesn\u2019t like you. This real-time security strategy approaches cyber security from the perspective that <strong><em>everyone<\/em> inside and outside your network is a potential threat<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zero trust touches everything relating to your IT ecosystem and everything that goes on in the background. It promotes the idea that there are no traditional network boundaries; your assets and resources can be anywhere \u2014 on prem, in the cloud, or a mix of both. This makes it a versatile approach to hardening your cyber defenses. Therefore, everyone with access to your organization\u2019s network or IT resources must have their identities continuously vetted throughout their connections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of where your assets are that you want to secure, there are three guiding principles at the heart of zero trust security:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-never-trust-always-verify\">1. Never Trust, Always Verify<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">What we mean by this is that users need to authenticate in a verifiable name. Simply taking them at their word just won\u2019t cut it. This entails using setting default-deny policies, setting least access privileges, and using public key infrastructure (PKI) based tools (such as <a href=\"https:\/\/www.thesslstore.com\/blog\/client-authentication-certificate-101-how-to-simplify-access-using-pki-authentication\/\">client authentication certificates<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whenever someone logs in or tries to access something in a zero trust environment, they\u2019ll need to continually authenticate (prove their identity) throughout the session. Why? Because session IDs can be hijacked and someone unintended can take over a connection. By implementing comprehensive identity and access management, you\u2019re reducing the potential harm an account compromise could cause.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-assume-a-hostile-environment-or-that-a-breach-has-occurred\">2. Assume a Hostile Environment or That a Breach Has Occurred<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">With zero trust, you assume the worst (someone bad is already in your network) but hope for the best. You\u2019ll want to assume that every network connection and access request is from an attacker. This involves monitoring all users, devices, connections, requests, and configuration changes continuously to ensure that no one is accessing something they shouldn\u2019t.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-verify-explicitly\">3. Verify Explicitly<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verify that users are accessing things securely. Have security mechanisms in place to ensure they\u2019re doing that. This includes enforcing policies dynamically via the policy engine and policy administrator (PE determines whether access is approved or denied and the PA executes that decision). And, as always, monitor and log all access requests and traffic.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"932\" height=\"449\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/overview-zero-trust.png\" alt=\"An overview illustration of the zero trust security approach\" class=\"wp-image-16086\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/overview-zero-trust.png 932w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/overview-zero-trust-300x145.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/overview-zero-trust-768x370.png 768w\" sizes=\"auto, (max-width: 932px) 100vw, 932px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: This graphic represents a basic overview of the foundational concepts behind zero trust: trust nothing and no one, have security mechanisms in place for identity and device verification, and assume all traffic (both inside and outside the network) is an attack.<\/em><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-there-s-no-one-size-fits-all-approach-to-zero-trust\">There\u2019s No One-Size-Fits-All Approach to Zero Trust<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There are different approaches to zero trust put out by different organizations and different standards as well. Probably the most commonly known zero trust framework is the National Institute of Standards and Technology\u2019s (NIST) special publication: <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-207\/final\">NIST SP 800-207 \u2014 Zero Trust Architecture<\/a>. This document laid the groundwork for other frameworks from agencies such as the <a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/Library\/(U)ZT_RA_v2.0(U)_Sep22.pdf\">U.S. Department of Defense<\/a> and the <a href=\"https:\/\/media.defense.gov\/2021\/Feb\/25\/2002588479\/-1\/-1\/0\/CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF\">National Security Agency<\/a> (NSA).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These other frameworks have a lot to offer information of information and applications. (The DoD guidelines, in particular, offer more breadth and depth than the NSA\u2019s.) And we\u2019ll touch on key concepts from these resources throughout the article.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-zero-trust-matters-looking-beyond-the-surface-to-secure-your-digital-assets\">Why Zero Trust Matters: Looking Beyond the Surface to Secure Your Digital Assets<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We live in a time when you can no longer take things at face value. You can\u2019t simply assume that someone is who they claim to be simply because they type in a username and password; all it takes is a small third-party data breach for someone\u2019s password to become known to the dark web. And if that person uses that same password to secure multiple accounts, then attackers can use it to brute force their way into their accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why it\u2019s crucial that we look much deeper and look at other verifiable and contextual information. This approach helps us determine whether someone requesting access to sensitive resources is authentic and has the authorization to access those assets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Discussing this topic of zero trust always makes me think of scenes from the <em>Mission: Impossible<\/em> movie franchise. In several movies, Tom Cruise\u2019s character, Ethan Hunt, wears masks and contact lenses to impersonate key characters. Sure, on the surface, he looks like each of the people he\u2019s pretending to be. He can even use a voice modulator of some kind to sound like each person he\u2019s impersonating. But just because he looks and sounds like that person doesn\u2019t mean Ethan Hunt (Cruise) really is them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, let\u2019s leave Hollywood behind for a second and imagine if someone who looks and sounds like your boss or CEO walks into your building. You\u2019d likely assume that it\u2019s him or her. That would be pretty hard to fake, right? Heck, if I saw someone walk in who looked and spoke like our CEO, Bill Grueninger, I\u2019d likely assume it\u2019s really him, too. But if I walked up and started tugging on his face to see if it\u2019s a latex mask or is the real deal, I\u2019d likely find myself landing a really uncomfortable meeting with HR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a digital environment where users authenticate remotely, though, you need to have a way to verify their identities are legitimate. It makes you wonder what major cyber security incidents and data breaches may well have been avoided if the targeted organizations adopted zero trust policies and processes\u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-zero-trust-vs-traditional-trust-based-environments\"><a>Zero Trust vs Traditional Trust-Based Environments<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A zero-trust environment differs from a traditional security approach in that zero trust means you have continuously prove your trustworthiness, whereas a traditional environment means that once you\u2019re inside the network, you\u2019re automatically assumed to be safe.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"873\" height=\"852\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-vs-trust-based-network-shadow.png\" alt=\"A graphic with two parts: the first illustrates the concept of a traditional network with an implicit trust zone. The second shows a zero trust network with a no trust zone.\" class=\"wp-image-16087\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-vs-trust-based-network-shadow.png 873w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-vs-trust-based-network-shadow-300x293.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-vs-trust-based-network-shadow-768x750.png 768w\" sizes=\"auto, (max-width: 873px) 100vw, 873px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A set of illustrations that show the difference between a traditional trust-based network and a zero trust network.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, the traditional model no longer works in a world of credential phishing and session hijacking. You need more robust security and authentication measures in place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-seven-pillars-of-zero-trust\"><a>The Seven Pillars of Zero Trust<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you search online, you\u2019ll notice that different organizations approach zero trust in different ways. For the sake of this article, we\u2019ll talk about the seven pillars of zero trust in terms of how the U.S. Department of Defense framework defines them. The seven zero trust pillars we outline below are overarching categories of focus for implementing zero trust. Each pillar involves monitoring and logging but also entails other specific protections.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"774\" height=\"842\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-pillars.png\" alt=\"A graphic using a columned building to illustrate zero trust architecture with each column representing a different pillar of zero trust\" class=\"wp-image-16088\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-pillars.png 774w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-pillars-276x300.png 276w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-pillars-768x835.png 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><figcaption class=\"wp-element-caption\"><em>Image source: A diagram we created based on the U.S. Department of Defense\u2019s seven zero trust pillars with the addition of CA and PKI-based digital identity.<\/em><\/figcaption><\/figure>\n\n\n\n<ol style=\"list-style-type:1\" class=\"wp-block-list\">\n<li><strong>Users<\/strong> \u2014 Controlling access to protected resources by continuously authenticating users using digital identity components (such as client authentication certificates) and verifying users\u2019 access authorizations.<\/li>\n\n\n\n<li><strong>Devices<\/strong> \u2014 Use device digital identity (think TPMs, <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-device-certificate-device-certificates-explained\/\">device certificates<\/a>, etc.) to authenticate access in real time. Devices also must be patched to mitigate vulnerabilities. &nbsp;<\/li>\n\n\n\n<li><strong>Network\/Environment <\/strong>\u2014 Segmentation, isolation, and policy restrictions are three critical components to control access and manage how data moves on your network. This approach helps to restrict access and prevent lateral movement within the network.<\/li>\n\n\n\n<li><strong>Applications and Workloads<\/strong> \u2014 Whether you\u2019re using resources that are on-prem, cloud, or a hybrid approach, the idea here is to secure the application layer.<\/li>\n\n\n\n<li><strong>Data<\/strong> \u2014Secure your data by developing a comprehensive data management strategy and integrating data security measures such as at-rest and in-transit data encryption. This will help protect your data both while it\u2019s on your servers or moving between two endpoints.<\/li>\n\n\n\n<li><strong>Visibility and Analytics<\/strong> \u2014 Having full visibility of your IT environment is crucial to keeping it secure. You can\u2019t protect assets you don\u2019t know exist, and you can\u2019t stop attackers when you don\u2019t realize something is wrong. You can gain actionable insights to improve your cyber security by analyzing your network\u2019s traffic and user behaviors in real time to identify threats. Just be sure to consider that some traffic may contain sensitive data, so decide the best approach (such as informing users and obtaining their consent ahead of time).<\/li>\n\n\n\n<li><strong>Automation and Orchestration<\/strong> \u2014 Automation is a scalable approach that takes monotonous tasks off your team\u2019s plates, freeing them up to focus on tasks that require critical thought processes. These tools also enable you to quickly sort through all the noise your security tools generate to find valuable data.&nbsp;<\/li>\n<\/ol>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-access-controls-access-management-are-critical-to-your-organization-s-cyber-defenses\"><a>Access Controls &amp; Access Management Are Critical to Your Organization\u2019s Cyber Defenses<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Zero trust as a cyber security approach has gained strong support over the last several years. This is partly because of the use of identity-based authentication and user authorization that\u2019s required. In a nutshell, here\u2019s a quick overview of how access controls and management play together to boost your organization\u2019s cyber security:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/the-role-of-access-control-in-information-security\/\">Access controls<\/a> are the rules, settings, and tools you use to control access to sensitive data and resources.<\/li>\n\n\n\n<li>Access management is the process of setting up and managing who has authorization to access specific resources and systems.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, neither of these things is foolproof and requires another security layer in the form of authentication. User and device authentication are all about ensuring that only entities (i.e., those whose digital identities have been verified and their authorizations confirmed) can access your secure digital assets.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-continuous-authentication-is-integral-to-zero-trust\"><a>Continuous Authentication Is Integral to Zero Trust<\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A key element of the zero trust approach is a concept known as <em>continuous authentication<\/em>. The idea behind continuous authentication is that all network users, including your employees, must not only prove their identities when they first log in but also continuously prove their identities throughout their sessions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Why is this necessary? Because session IDs can be set to last for extended periods \u2014 anywhere from a few hours to even a few weeks. This means that if a cybercriminal steals an authenticated user\u2019s access tokens (session IDs and cookies), they can pretend to be them and access whatever protected resources their account has the authorization to access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While some platforms have mechanisms to prevent authentication from happening, this may not always be the case. And it\u2019s true that you can set timeout limits to take effect after certain periods, but if you don\u2019t bother setting up these security limits, then it\u2019s inevitable that at least one bad guy might slip through the cracks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-continuous-authentication-requires-verifiable-digital-identity\"><a>Continuous Authentication Requires Verifiable Digital Identity<\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For zero trust security to work, you need to have a way to prove that you\u2019re really you and aren\u2019t an imposter who\u2019s trying to fraudulently access sensitive data, systems, and other resources. The way to achieve this level of reliable and verifiable digital identity is through the use of public key infrastructure (PKI) and digital certificates. (We\u2019ve talked a lot about these concepts before, but we\u2019ll talk more about them again a little later in the article.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Digital certificates are small data files that pack massive punches. They contain verified identifying information about you and\/or your organization that a trusted authority (certificate authority) attests is authentic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can think of <a href=\"https:\/\/www.thesslstore.com\/blog\/when-to-use-a-digital-signature-certificate\/\">digital certificates<\/a> in much the same way as an official passport: that little government-issued booklet contains verified information about you that proves your identity to people you\u2019ve never met. This way, you can show your passport to airport security and other authorities (i.e., people who don\u2019t know you) to prove you\u2019re really you. (Sorry, there were <em>a lot<\/em> of \u201cyous\u201d in that paragraph.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What do digital certificates and continuous authentication have to do with one another? Everything, really.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>In a zero-trust environment, there are no implicitly or explicitly trusted users, devices, or zones within your network or IT environment. <\/strong>The digital identities of <em>everything<\/em> and <em>everyone<\/em> must be authenticated continuously using verifiable methods \u2014 period. And digital certificates are a means of doing precisely that.<\/li>\n\n\n\n<li><strong>Digital certificates enable trusted third parties to attest to your digital identity\u2019s authenticity.<\/strong> It\u2019s kind of the digital equivalent of how the U.S. Department of State attests to an American\u2019s identity each time it issues a passport.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-public-key-infrastructure-and-zero-trust-the-perfect-combination\"><a>Public Key Infrastructure and Zero Trust = The Perfect Combination<\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In a zero-trust environment, each employee, device, or other network user must have a way to mutually authenticate in a way that\u2019s verifiable. How? By using a security mechanism that the security of the internet itself is built upon: public key infrastructure (PKI).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Public key infrastructure is the combination of rules, processes and technologies that enable two parties to communicate securely. Without PKI, if you were trying to connect to your bank\u2019s website, it would be risky: you wouldn\u2019t have a way to securely send your data because you wouldn\u2019t know for sure who was on the other end of the connection. Even if the connection is encrypted, if you\u2019re connecting to a cybercriminal, they\u2019d have the decryption key to unscramble your data and read it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remember the DoD Zero Trust initiative that we mentioned earlier? Its DoD Zero Trust Architecture document shares one of the most beautiful lines we could hope to read in a government resource as an explanation: <em>\u201cThe use of mutual authentication of users with PKI-based client authentication or mutual authentication certificates to web applications has long been the effective standard.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Darned right, it is. And that\u2019s because PKI isn\u2019t the new kid on the block; it\u2019s been around the block many times since its inception in the mid-1980s. PKI has served as the trusted foundation of internet security since that time because it\u2019s what enables secure remote communications and data transmissions that, otherwise, would be impossible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-zero-trust-is-necessary-to-improve-cyber-defenses\"><a>Why Zero Trust Is Necessary to Improve Cyber Defenses<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to remote user authentication and access, looking beneath the surface is a necessity. You can\u2019t simply see that someone logs in using a basic username-password combination and assume it\u2019s the legitimate account owner; you need an additional layer of verification that continually proves it\u2019s the authentic user. Adopting a zero-trust approach can help in several ways:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-prevents-compromised-credentials-and-access-tokens-from-being-exploited\"><a>Prevents Compromised Credentials and Access Tokens From Being Exploited<\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implementing zero trust is a way to prevent cybercriminals from taking advantage of vulnerable access tokens (session cookies, IDs, or weak credentials) to gain access to sensitive resources while pretending to be legitimate network users. Yup, that\u2019s right \u2014 if even one of your employees who has privileged access uses a weak password for their account, it could be game over for your business. All it takes is one bad enough \u201coops\u201d to cause you to face immense penalties, lawsuits, or even have to close your doors forever.&nbsp;&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-protects-your-brand-and-nurtures-customers-trust\"><a>Protects Your Brand and Nurtures Customers\u2019 Trust<\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Incorporating zero trust into your cybersecurity strategy is also a great way to help protect your organization\u2019s reputation, brand, and bottom line. <a href=\"https:\/\/www.okta.com\/the-state-of-digital-trust\/\">Okta\u2019s 2021 State of Digital Trust report<\/a> shows that 75% of American consumers say they likely won\u2019t do business with brands they don\u2019t trust (i.e., after a data breach or misuse of data). Almost half, a whopping 47%, say they\u2019d take things a step further and would permanently stop using a company\u2019s services for the same reasons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine what would happen if an unauthorized user gained access to your most sensitive data. This could be your intellectual property (IP), customers\u2019 financial data, or even employees\u2019 records. Regardless of which type of data they get their slimy paws on, exposing sensitive data would spell disaster for your organization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-helps-mitigate-other-issues\"><a>Helps Mitigate Other Issues<\/a><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to the no-brainer reason of <em>you don\u2019t want your information accessed by unauthorized individuals<\/em>, there are also other concerns that adopting zero trust could help you avoid<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Non-compliance issues with regard to industry standards,<\/li>\n\n\n\n<li>Data breaches that can lead to hefty fines, penalties, and lawsuits,<\/li>\n\n\n\n<li>Your reputation taking a big hit, and<\/li>\n\n\n\n<li>Customers not trusting you or your services.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-it-looks-like-when-you-don-t-adopt-zero-trust-and-things-go-wrong\"><a>What It Looks Like When You Don\u2019t Adopt Zero Trust and Things Go Wrong<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve seen this type of scenario happen time and again in various data breaches. Here\u2019s a quick example of what could happen without a continuous authentication mechanism in place:<\/p>\n\n\n\n<ol style=\"list-style-type:1\" class=\"wp-block-list\">\n<li>An attacker phishes one of your company\u2019s key employees, tricking or manipulating them into coughing up their privileged access credentials or session ID. This may not be hard considering that <a href=\"https:\/\/www.ibm.com\/reports\/threat-intelligence\/\">IBM\u2019s X-Force Threat Intelligence<\/a> reports phishing as the attack vector in two in five incidents their team responded to.<\/li>\n\n\n\n<li>The attacker uses their login info or session ID to access secure resources using that employee\u2019s account. Once in, they\u2019re able to move laterally across the company\u2019s network \u2014 accessing applications, databases, and other resources that the employee\u2019s compromised account has access to \u2014 pillaging as they go.<\/li>\n\n\n\n<li>Once they find interesting and valuable data, the attacker exfiltrates whatever data they can to an external server they control before installing malware onto your systems. It\u2019s a devastating one-two punch you never saw coming that can bring your company to its knees.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"823\" height=\"626\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/what-can-happen-without-zero-trust.png\" alt=\"This illustration provides an example of what can happen without adopting a zero trust approach. An employee's session ID or login credentials could be stolen and used by an attacker to fraudulently access the employee's session to steal your organization's data or install malware\" class=\"wp-image-16089\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/what-can-happen-without-zero-trust.png 823w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/what-can-happen-without-zero-trust-300x228.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/what-can-happen-without-zero-trust-768x584.png 768w\" sizes=\"auto, (max-width: 823px) 100vw, 823px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A diagram that illustrates the basic concept of how an attacker can exploit compromised credentials in a non-zero trust environment.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Because your organization didn\u2019t require continuous authentication (i.e., didn\u2019t implement zero trust) or have restricted policies in place that are enforced, your IT security admin or cyber security team doesn\u2019t realize that anything is amiss until it\u2019s too late. Now, you\u2019re not only dealing with a data breach, you\u2019re also scrambling to deal with the ransomware situation as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But wouldn\u2019t a firewall be able to tip off your cyber defenders that something\u2019s wrong? Sure, event logs will show a significant increase in traffic. But since the traffic appears to be legitimate (because the attacker is using the employee\u2019s legitimate credentials, may be using a proxy IP address to disguise their true location, and you\u2019re not analyzing device identity attributes or behaviors), they may not initially realize that it\u2019s actually an external attacker and not your legitimate employee accessing your systems until the damage has already been done.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Oh boy. We hope you have business continuity, disaster response and <a href=\"https:\/\/www.thesslstore.com\/blog\/in-case-of-emergency-a-disaster-recovery-plan-checklist-for-data-security\/\">disaster recovery<\/a> plans in place, and that those plans are not only current but that your employees know what their roles and responsibilities are! <a href=\"https:\/\/www.thesslstore.com\/blog\/the-rise-of-cyber-resilience\/\">Cyber resilience<\/a> is crucial; but without the right security mechanisms, strategies and plans in place, you may not like the outcome.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-insider-threats-in-action-a-real-world-look-at-the-elliott-greenleaf-breach-2021\">Insider Threats in Action: A Real-World Look at the Elliott Greenleaf Breach (2021)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers are becoming increasingly sophisticated and potential attack surfaces are expanding. As such, our defense of these systems must become more robust and dynamic. To go beyond discussing zero trust from a largely conceptual standpoint, let\u2019s dive deeper and explore the damage caused to a real-world organization by <a href=\"https:\/\/www.thesslstore.com\/blog\/the-danger-within-insider-threat-examples\/\">bad actors within its trusted internal network<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-happened\">What Happened<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In January 2021, the Pennsylvania law firm <a href=\"https:\/\/today.westlaw.com\/Document\/I1c80a1d070ac11ebb555947e94fe83f6\/View\/FullText.html?transitionType=SearchItem&amp;contextData=(sc.Default)\">Elliott Greenleaf was the victim of an insider attack<\/a> and sustained catastrophic financial losses, according to WestLaw.com. According to multiple reports, four attorneys and a paralegal secretly downloaded a slew of invaluable sensitive data, including confidential files, trade secrets, and client lists. Their actions as insider threats resulted in irreparable damages to their former employer, which has since <a href=\"https:\/\/www.law.com\/thelegalintelligencer\/2021\/02\/16\/elliott-greenleaf-sues-ex-partners-who-left-to-launch-armstrong-teasdales-delaware-office\/\">filed a lawsuit against the four attorneys and the paralegal<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/csrc.nist.gov\/glossary\/term\/insider_threat\">National Institute of Standards and Technology (NIST)<\/a> defines insider threats as:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe threat that an insider will use her\/his authorized access, wittingly or unwittingly, to do harm to the security of organizational operations and assets, individuals, other organizations, and the Nation. This threat can include damage through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of organizational resources or capabilities.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">As it turns out, these legal professionals, who were trusted to operate internal systems (seemingly with little to no oversight), were wolves in sheep\u2019s clothing. They were <a href=\"https:\/\/delawarebusinessnow.com\/2021\/01\/law-notes-rlf-young-conaway-potter-anderson-promotions-armstrong-tisdale-to-open-office\/\">joining a rival law firm in Delaware (Armstrong Teasdale)<\/a> and, it appears, wanted to take Elliott Greenleaf\u2019s info with them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, this isn\u2019t an uncommon scenario; <a href=\"https:\/\/www.code42.com\/resources\/reports\/2022-data-exposure\">Code42\u2019s research<\/a> shows that there\u2019s a one in three chance an organization will lose intellectual property when one of its employees quits. <em><\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-it-happened\">How It Happened<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s quickly break down what occurred that enabled these insiders to wreak havoc based on information shared by Digital Guardian and WestLaw:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The attorneys had immense access to files and data. <\/strong>The attackers had access to read, steal, and destroy highly sensitive information. For example, they reportedly shredded 288 lbs of physical documents. (That\u2019s approximately 28,800 pieces of paper if you\u2019re using standard copy paper). In some cases, they enlisted the help of the paralegal to get certain data for them.<\/li>\n\n\n\n<li><strong>They accessed systems that appear to lack monitoring and\/or alerts.<\/strong> To steal data, they were able to use one or more personal USB devices and had cloud-based file-sharing apps installed on their company devices.<\/li>\n\n\n\n<li><strong>They were able to send and delete emails containing sensitive information without detection.<\/strong> As such, they could send additional sensitive information to personal email accounts \u2014 and subsequently \u201cdouble-delete\u201d the messages in an attempt to cover their trails. Granted, the company says it\u2019s able to access the delete emails via their data backup systems, but by that time, the damage had already been done.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-big-takeaway-from-the-elliott-greenleaf-law-firm-situation\">The Big Takeaway From the Elliott Greenleaf Law Firm Situation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, the Elliott Greenleaf law firmed learned a valuable lesson the hard way: This catastrophe likely could have been prevented (or identifier earlier) if Elliott Greenleaf had adopted a zero trust approach. With zero trust:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the employees\u2019 access should have been continuously verified across all systems,<\/li>\n\n\n\n<li>their reach (i.e., their permissions and breadth of access) should have been restricted to only what they needed to do their jobs (think policy of least privilege), and<\/li>\n\n\n\n<li>their access to resources and use of USB devices should have been disabled \u2014 or, at the very least, monitored, logged, and analyzed.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s our hope that you that you keep this story in mind and recognize that the threat from within your organization can be as, if not more, dangerous than outside attackers. Although the damage caused by this insider breach is irreversible, future attacks of this nature can be prevented through by adopting a zero trust posture.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-adopt-a-zero-trust-strategy\"><a>How to Adopt a Zero Trust Strategy<\/a><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now, we\u2019re not going to get into the nitty-gritty of how to actually implement zero trust. There\u2019s far too much information that would need to be covered that it would, basically, entail creating a whole other article. However, NIST (SP 800-207) and the DoD (DoD Zero Trust Reference Architecture) provide some guidance for federal agencies on how to build zero trust architectures (from the ground up or migrate their systems to zero trust over time). Some of this information may be useful to your organization as well.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-adopting-a-zero-trust-strategy-is-one-of-the-best-ways-to-secure-your-organization\">Adopting a Zero Trust Strategy Is One of the Best Ways to Secure Your Organization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Zero trust isn\u2019t totally new, and it certainly isn\u2019t going anywhere anytime soon. It\u2019s gaining traction over time. Okta reports that 55% of surveyed organizations globally indicate that they have a zero trust initiative in place. A whopping 85% of global 2000 (G2000) companies said they\u2019d allocated \u201cmoderate\u201d or \u201csignificant\u201d year-over-year increases in budgets to fund these initiatives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, there is still room for improvement. <a href=\"https:\/\/www.illumio.com\/resource-center\/research-report\/forrester-trusting-zero-trust\">Research from Forrester and Illumio<\/a> shows that only 6% of organizations indicate that they have fully deployed zero trust within their IT environments. But, hey, it\u2019s a start, right?&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the key attributes of zero trust is limiting who has access to what. This involves setting and enforcing policies, using verifiable digital identity, following the least privilege principle, monitoring all access attempts and behaviors, etc. By limiting a user\u2019s reach to only the resources and systems they need to do their jobs, you reduce your attack surface. So, rather than having cybercriminals have access to everything, they can only access the systems and data that the user is authorized to access. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a zero-trust environment, a bad guy will first have to go through a series of verification checks to ensure they\u2019re the authentic user. If they fail that, then they won\u2019t get access to anything. If they succeed, then at least their reach will be restricted to the privileges you\u2019ve assigned the compromised user\u2019s profile. And since you\u2019re keeping an eye on everything and are logging everything for analysis, it\u2019ll help you better mitigate these issues in the future.<\/p>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>The zero-trust strategy approaches security from the mindset that no one \u2014 not even your internal network users \u2014 can or should be trusted automatically. Here\u2019s why zero trust security&#8230;<\/p>\n","protected":false},"author":17,"featured_media":16092,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16],"tags":[13218,13217],"class_list":["post-16084","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","tag-zero-trust","tag-zero-trust-security","post-with-tags"],"views":7683,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2023\/01\/zero-trust-feature-small.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/16084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=16084"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/16084\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/16092"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=16084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=16084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=16084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}