{"id":4412,"date":"2021-07-12T15:28:22","date_gmt":"2021-07-12T12:28:22","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=4412"},"modified":"2021-07-12T15:29:08","modified_gmt":"2021-07-12T12:29:08","slug":"the-first-steps-towards-zero-trust-security","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/the-first-steps-towards-zero-trust-security\/","title":{"rendered":"The First Steps Towards Zero Trust Security"},"content":{"rendered":"<p>In recent years, companies have begun storing data in multiple locations, from traditional networks to cloud vendors, and, with the rise of work from home, in virtual infrastructures like <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-endpoint-protector-keeps-data-secure-on-daas-platforms\/\" target=\"_blank\" rel=\"noopener\">Desktop-as-a-Service (DaaS)<\/a> and on remote employee-owned devices. This diversification of data storage locations is not compatible with traditional network security models that imply the protection of data from outsider threats, but fully trusting insiders. This paradigm shift has led to the rise of a new security model: Zero Trust.<\/p>\n<p>Traditional IT network security is based on a so-called castle-and-moat approach which builds up a system\u2019s defenses against outside access but trusts everyone inside the network by default. This becomes a problem when attackers manage to get inside the network: nothing prevents them from stealing data or infecting the entire network.<\/p>\n<p>If properly implemented, the castle-and-moat approach effectively protects data but offers very little room for flexibility. Data must stay within the network to be protected. Once it is taken outside it, for example, when an employee <a href=\"https:\/\/www.endpointprotector.com\/blog\/work-from-home-overview-2020\/\" target=\"_blank\" rel=\"noopener\">works from home<\/a>, it leaves the data on that device vulnerable to theft or loss.<\/p>\n<p>The concept of de-perimeterization or Zero Trust emerged as data breaches became a key concern for information security professionals. In Zero Trust, all network traffic is untrusted. All resources must be verified and secured, access control must be strictly enforced, and all network traffic must be inspected and logged.<\/p>\n<p>Applied as an IT security model, Zero Trust entails strict identity verification for every person and device accessing resources on a private network, regardless of whether they are located within or outside the network perimeter. As an approach to cybersecurity, Zero Trust does not mean the use of a single specific technology but incorporates several different principles.<\/p>\n<p>As the <a href=\"https:\/\/www.endpointprotector.com\/blog\/the-cost-of-a-data-breach-in-2020\/\" target=\"_blank\" rel=\"noopener\">cost of data breaches<\/a> skyrocketed, reaching $3.86 million\/breach in 2020, companies have realized the need to evolve from a traditional network-oriented security model and have begun moving towards Zero Trust security policies. But where can companies start with Zero Trust? Here are the first steps!<\/p>\n<h2>Protecting data at all times<\/h2>\n<p>Data should be protected at all times, whether it\u2019s <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-to-protect-your-data-at-rest\/\" target=\"_blank\" rel=\"noopener\">at rest<\/a>, <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-to-protect-data-in-motion\/\" target=\"_blank\" rel=\"noopener\">in transit<\/a>, or in use. <a href=\"https:\/\/www.endpointprotector.com\/blog\/protecting-data-at-rest-vs-data-in-motion\/\" target=\"_blank\" rel=\"noopener\">Data in transit and data at rest<\/a> have different vulnerabilities that an effective Zero Trust security policy should address. Traditional security models focus on data leaving the network, but often neglect data stored locally because it\u2019s within the security of the network itself.<\/p>\n<p>However, it is precisely here that a castle-and-moat approach to cybersecurity fails to protect data. When the network is breached, there is nothing stopping cybercriminals from stealing vast amounts of unprotected data. There is also nothing stopping insiders from stealing or misusing data. It is therefore essential for companies to look at ways to protect data, regardless of the state it finds itself in.<\/p>\n<p>This step does not only apply to endpoints but should also be applied to data stored on Software-as-a-Service (SaaS), DaaS, and cloud services. Sensitive data exported from these services should remain secured throughout its entire life cycle.<\/p>\n<h2>Advanced access control<\/h2>\n<p>Access control is a big part of Zero Trust security policies. However, prompting employees to log on every time they use a different application can hamper productivity and diminish user satisfaction. Single Sign-On (SSO) technology provides the ability for users to sign in once with their credentials and gain access to all their web applications. This reduces the number of passwords employees need to use on a daily basis and the likelihood of weak passwords.<\/p>\n<p>As an extra layer of security, Multi-Factor Authentication (MFA) can be added on top of SSO. This means that, beyond just entering a username and password, users will require additional factors such as a PIN sent via SMS or authentication via mobile apps when they try to log on. SSO together with MFA ensures a level of security in line with the requirements of Zero Trust security policies.<\/p>\n<p>Many software providers have begun introducing SSO and MFA technologies to their products to support companies\u2019 adoption of Zero Trust security models. Our own Data Loss Prevention (DLP) solution, <a href=\"https:\/\/www.endpointprotector.com\/\" target=\"_blank\" rel=\"noopener\">Endpoint Protector<\/a> has integrated SSO and MFA for Azure Active Directory in its <a href=\"https:\/\/www.endpointprotector.com\/blog\/endpoint-protector-5-3-0-5-is-out-discover-whats-new\/\" target=\"_blank\" rel=\"noopener\">latest update<\/a>, making it easier for administrators to securely authenticate by using just one set of credentials.<\/p>\n<h2>Data visibility and logging<\/h2>\n<p>Zero Trust security implies enhanced data visibility and monitoring of data movements. This is particularly important for sensitive categories of data, such as <a href=\"https:\/\/www.endpointprotector.com\/blog\/how-to-protect-pii-with-data-loss-prevention\/\" target=\"_blank\" rel=\"noopener\">personally identifiable information<\/a> (PII) and <a href=\"https:\/\/www.endpointprotector.com\/blog\/protecting-intellectual-property-with-data-loss-prevention\/\" target=\"_blank\" rel=\"noopener\">intellectual property<\/a> which are the targets of most data breaches.<\/p>\n<p>Granular logging and reporting should record all movements of sensitive data as well as the devices, applications, or employees responsible for them. Logs allow companies to detect suspicious behavior that might be a sign of <a href=\"https:\/\/www.endpointprotector.com\/blog\/what-is-insider-data-exfiltration\/\" target=\"_blank\" rel=\"noopener\">data exfiltration<\/a>, potential vulnerabilities in the way data is handled internally while also contributing to audit and compliance efforts.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In recent years, companies have begun storing data in multiple locations, from traditional networks to cloud vendors, and, with the rise of work from home, in virtual infrastructures like Desktop-as-a-Service (DaaS) and on remote employee-owned devices. This diversification of data storage locations is not compatible with traditional network security models that imply the protection of &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/the-first-steps-towards-zero-trust-security\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The First Steps Towards Zero Trust Security&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":4414,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4412","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=4412"}],"version-history":[{"count":1,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4412\/revisions"}],"predecessor-version":[{"id":4415,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/4412\/revisions\/4415"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/4414"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=4412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=4412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=4412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}