
Organizations today face a non-stop onslaught of sophisticated, AI-driven cyberattacks. But traditional security models are poorly suited to stop these advanced threats in the modern world, with its cloud computing and hybrid work. That’s because yesterday’s perimeter-based security models, which rely on tools such as firewalls and VPNs, are fixated on the network. They involve extending access to the network as a whole, they operate under the assumption that users within the network should be trusted by default, and they focus on securing the network as a way to stop threats and data loss.
This approach to security was designed for the on-premises-only world, but with the proliferation of cloud services and remote work, this “castle and moat” security model actually exposes modern organizations to increased risks. How so?
First, it expands the attack surface through endless network extension to off-premises users, devices, clouds, and apps, as well as through firewalls with public IP addresses that can be found and exploited on the web by bad actors. Next, network-centric architecture fails to prevent compromise because it relies on security appliances that lack the scalability needed to inspect encrypted traffic and stop the threats therein. Third, by extending access to the network as a whole, it enables lateral movement, whereby attackers can access resources connected to the network. Finally, perimeter-based architecture fails to stop data loss due, once again, to limitations with encrypted traffic inspection, as well as the fact that legacy tools aren’t designed for modern leakage paths like sharing functionality in SaaS apps.
Understanding zero trust: A modern approach to security
Zero trust architecture shifts away from the above model by eliminating implicit trust and decoupling security and connectivity from the network. Instead of a moat for a castle, zero trust acts as an intelligent switchboard that provides secure, any-to-any connectivity in a one-to-one fashion that forgoes the need to connect users to the network. It uses context to govern access to IT resources, because identities can be stolen, and even legitimate users with valid credentials can pose a threat. Specifically, zero trust architecture scrutinizes contextual factors such as user behavior, user location, and device security posture, to assess risk and determine whether access should be granted. This continuous, adaptive approach ensures intelligent, least-privileged access.
Key principles of zero trust include:
- Never trust, always verify: All access requests, whether internal or external, are verified with rigorous checks before any connection is established.
- Least-privileged access: Users are only granted the minimum level of access necessary to perform their duties (they are never given blanket network access), significantly limiting the scope of potential breaches.
- Continuous monitoring: Continuous analysis of traffic allows for the detection of abnormal activities in real-time, ensuring proactive threat detection and prevention.
- Assume breach: By adopting a mindset that a breach has either occurred or is inevitable, organizations can remain vigilant and better prepared to prevent breaches entirely, as well as find and stop those in process more swiftly
Zero trust is delivered as a service from the cloud and at the edge, providing organizations with a comprehensive platform that consolidates point products, eliminates legacy tools, simplifies complex network-centric infrastructure, and forgoes the need to backhaul traffic to a distant data center. By processing and securing traffic closer to the end user, zero trust minimizes risk and latency, ensuring a safer, more productive workforce. Additionally, this simpler approach delivers greater economic value than legacy architectures that entail countless point product purchases and endless management overhead.
Zero trust architecture successfully eliminates the four ways that perimeter-based architecture increases risk. First, it minimizes the attack surface by eliminating endless network extension, as well as firewalls, VPNs, and their public IP addresses that enable inbound connections from attackers. Instead, all resources and devices are hidden behind a zero trust cloud that uses inside-out connections to prevent any exposure.
Second, zero trust stops initial compromise when it is delivered by a high-performance cloud platform that has the scalability necessary to inspect all traffic (including encrypted traffic at scale) so that it can identify cyberthreats therein and enforce real-time policies that block them.
Next, this modern architecture prevents lateral threat movement across connected IT resources by connecting users directly to the specific applications they need, rather than to the entire network.
Finally, zero trust blocks both accidental and malicious data loss through its ability to inspect and secure encrypted traffic, as well as any other modern data leakage paths, including SaaS applications, cloud platforms, endpoints, and email.
Overcoming barriers to implementation
Despite the clear advantages of zero trust architecture, organizations may still have barriers that impede its implementation. One of the primary barriers is inertia—and not just from practitioners who have built their careers by creating security perimeters and routable networks. In particular, many organizations are reluctant to abandon their existing investments in traditional network and security infrastructure. Companies have spent millions building these systems, and transitioning to a zero trust architecture requires a fundamental shift in thinking, approach, and technology.
To overcome these hurdles, businesses must secure executive-level buy-in, specifically from the CIO. That’s because zero trust represents a transformational change that must be motivated from the top-down; it is not just a technological upgrade. However, this doesn’t mean organizations have to overhaul everything at once. Instead, they can begin by addressing specific, high-impact use cases—like upgrading from VPN to zero trust network access (ZTNA) for securing access to private applications. By focusing on immediate needs and smaller scale projects in this way, organizations can phase in zero trust architecture gradually, without overwhelming practitioners or end users, all while demonstrating its value through early success stories.
Embrace the future of security with zero trust
The traditional, network-centric methods of cybersecurity are no longer adequate for modern organizations facing modern cyber threats. With the increasing complexity of today’s IT environments—especially with cloud apps and hybrid work arrangements— zero trust offers a solution that fundamentally changes how organizations protect their data and stop threats.
Zscaler can help you implement a zero trust architecture that works for your organization. Learn more by signing up for our three-part webinar series: “Zero Trust, from Theory to Practice.”
