ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Why Zero Trust Network Access is not your silver bullet

On 19 September 2024, Digital Transformation host Kevin Crane was joined by Jean Carlos, VP Cyber Security, BOXT; Sasha Henry, Senior Managing Consultant, Cyxcel; and Karim Eldefrawy, CTO and Cofounder, Confidencial.

 

Views on news 


Australia has taken a groundbreaking step in cybersecurity legislation with the introduction of a new Cyber Security Bill, mandating that businesses must report ransomware payments to the government. The bill, presented to the Australian Federal Parliament on Thursday, aims to improve the country’s response to cyber threats following a series of high-profile attacks. Mandated reporting of cyber security incidents is already in force in the US and other governments around the world are expected to follow suit – there is also NIS2 and DORA in the EU. Regulating only specific types of cyber attacks poses the risk of cyber criminals coming up with new threat vectors. Hower, given that cyber security teams are already stretched by compliance exercises, pushing out new legislation may be counterproductive. It’s also a question at what point of the forensic investigation the reporting should take place and what details it should include about the attack. Reporting in cyber security is made more challenging by the speed at which incidents happen in this space. 


Why data labelling is key to ZeroTrust

 

What ZeroTrust advocates is resilience and protection when trust erodes. The framework has already been around in defence for a long time and now it’s being adopted by the commercial world. A considerable barrier to adaptation is the difficulties that data classification and governance present, as well as the micro-segmentation of unstructured data. Such a huge shift requires a complete restructuring of the network architecture, the reconfiguration of access controls in segregated OT and IT environments. Because of the size of such a project, a switch to ZeroTrust often happens incrementally. The transformation also requires a large population of engineers and training for employees to teach them how to use the technology. 


Cryptography has a major role to play too. Transport Layer Security (TLS), a security protocol that encrypts network traffic to protect data and privacy, for example, has been a huge success. Applying ZeroTrust to the data can be less intrusive or disruptive than ripping off the whole infrastructure. The point of the TCP/IP stack, a set of communication protocols that govern how data is transmitted between computers on the internet, is to make you independent of the infrastructure at the highest layer. Also, if you secure the data inside files and containers, you will have security regardless of where data ends up. A business must identify where their crown jewels lie and apply different levels of security according to that, as well as how often and by how many users a particular type of data is used. Despite the complexities of ZeroTrust, if you start classifying your data today and lock it up correctly, you will see immediate results in your security posture. With the user frustration that MFA causes, there is a chance that new discussions will start about risk-based authentication. Access of users to the same data may vary too – for some, it can be read-only, while others, like finance, can also be enabled to manipulate the same data. 


Businesses operating in different jurisdictions have to comply with a variety of data protection regulations, which will have an impact on what an employer can do when vetting candidates and monitoring employees. Using AI to automate data classification raises the issue of data governance creating  a loop. Prior to an AI deployment, however, you need to understand the business’s data. THE LM has all the regulatory data and governmental information about rules fed into it, but when users of the model add more data, the wording may start to get skewed from what the baseline is. Therefore, it’s important for businesses to curate who can add information to the model. As a first step, businesses can start classifying data under a couple of labels (i.e., public, internal, etc) rather than doing nothing, which will alert employees to the fact that there are different types of data with different levels of security controls. Without taking any further steps, you can also just monitor the organisation in the background and use the information gained to guide your implementation of controls.  

 

The panel’s advice

  • It’s almost impossible to implement ZeroTrust across the whole business, so it’s key to identify which the critical areas are where micro segmentation, and a more restricted data classification methodology can be applied.
  • It will take at least a decade for ZeroTrust to become the norm.
  • ZeroTrust has been a 5 year journey so far, and it may go on for another 10 or more years.
  • As a first step, bring the culture to your organisation that data should be labelled.
  • Figure out what size of ZeroTrust suits you and what you should complement your current access management with – is it EDR, SIEM or PAM?

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543