Zero trust advice: Start small, but get started

Share post:

Moving to a zero trust environment is so important that CEOs may have to appoint a manager to complete their projects, says a senior IT executive.

“To get zero trust across the finish line, some companies may appoint a zero trust officer,” John Engates, Cloudflare’s field CTO told an IT World Canada MapleSec Satellite webinar on Tuesday.

“Showing leadership, demonstrating how important it is to the organization, putting someone in charge of getting to a zero trust stance is really critical. No matter how you demonstrate that to your stakeholders, it’s really critical someone stand up and say, ‘We’ve got do better at this, we have to do it comprehensively across the entire organization. And we have to do it soon because the threats aren’t getting easier to deal with.'”

Zero trust — a security strategy that assumes no one on the IT network should be trusted — is a philosophy, Engates emphasized, not a product. This is why it can take a while to implement, depending on an organization’s cybersecurity maturity.

Related content: What is Zero Trust Network Access?

Implementing that strategy can begin with ensuring cybersecurity basics are covered — starting with ensuring the organization’s DNS server filters known malware, and moving to identity management, access control, phishing-proof multifactor authentication and more.

Cloudflare has created a zero-trust roadmap with 28 steps in four phases. Not every organization needs to implement that much detail. But the point is, for some large firms, nailing down a zero-trust approach can take a while.

Related content: Four steps to zero trust 

But, Engates said, it can be done in bite-sized chunks. “You can take what you need from a zero-trust architecture. Maybe you’re trying to secure your remote users or contractors. Start there (then) start with the applications that need the most security and work your way out.”

It doesn’t cost a lot for a small organization, he said, while larger ones can start small and expand over time.

Whatever way your firm decides, he said, “get started and get moving.”

The post Zero trust advice: Start small, but get started first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways