ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Building Zero-Trust: the reality

Sanjeev Shukla at Accenture shares some tips on building a true zero-trust environment

 

Business’ IT environments used to resemble a castle – thick walls, a moat and a drawbridge to ensure that those you trusted could be let in, but anyone up to no good was kept firmly out. And once you were in the castle, you were mostly free to roam around as you pleased.

 

The past several years have seen a change to the ‘castle-like’ defence paradigm. Businesses of all sizes – from the independent small office to the world’s largest companies – have had to adapt the way they worked, creating a rapid shift to the cloud and an increased use of SaaS.

 

Now, IT environments resemble something more like the London Underground, with thousands of entry points and interconnected tunnels.

 

It’s thanks to this that the idea of ‘zero-trust’ has recently created a real buzz across the security industry. However, it’s an overused and often misunderstood term. CISO Role have latched on, some even repackaging old gear as an answer to ‘zero-trust’ security.

 

Most companies that are interested in zero-trust may be stuck in the planning or strategy phase. Why? The reality is that achieving true zero-trust is an incredibly complex journey.

 

The benefits of zero-trust

Zero trust is a term for an evolving set of cybersecurity paradigms that move defences from static, network-based perimeters to focus on users, assets, and resources, rather than network connections and traffic.

 

The model assumes no implicit trust is granted to a device or a user based solely on their physical or network location (i.e., local area networks versus the internet) or based on device ownership (enterprise or personally owned).

 

Each access request to a particular resource is assessed with the context of a user’s entitlements, their device and connection. Based on such a dynamic assessment, a user is trusted to access specific resources for a limited period. There is no implicit trust based on static attributes.

 

The model assumes that threat landscape is constantly changing, and attack surface remains vulnerable so nothing can be permanently trusted. It is a mindset shift for IT and Security professionals, who are used the castle-like defences. Understanding this is important for security leaders looking to achieve zero-trust.

 

Challenges of implementing true zero-trust

Many security providers have presumably jumped on the bandwagon, rushing to release products that promise to create a zero-trust environment. It’s not hard to see why, as the benefits of zero trust environments are obvious.

 

However, implementing a zero-trust environment may prove to be an extremely complex and not as easy as plugging in a tool.

 

The reality is that trust needs to be refactored across both at network and application level. Adding to the complexity is that existing enterprise software is also often built on pre-written trust paradigms that may not be be easily recoded. Front-runners in the space have custom-coded everything from the ground up vs. using commercially off-the shelf (COTS) applications, but this isn’t necessarily a possibility for the vast majority without the time, resources, or skills at their disposal.

 

Many organisations are now possibly getting to an inflection point where they’re realising that if they do need to refactor their systems then they must do it before it’s too late to turn back – but they might need help understanding when and how, and whether it’s worth it for them.

 

Tips for creating a true zero-trust environment

Unfortunately, as far as we are aware, there is no one simple plug-in solution for implementing zero-trust across an organisation, and it shouldn’t be viewed in that way. It requires a mind-set shift and agility. While there may not be one simple solution, there are some basic, fundamental principles that need to be in place to create a truly agile, zero-trust environment:

 

  • Know where all your endpoints are: Do you truly know where all of your endpoints are – especially as hybrid and remote working has likely multiplied them? It’s more important than ever to ensure your organisation has a modern endpoint detection and response (EDR) in place. An EDR continuously monitors the endpoints in order to detect and respond to threats.

 

  • Context is key: For every access request a dynamic risk assessment is required. How risky is the request? What is being accessed? Where is the device? Who is the end user? Any suspicious activity out of the norm? Does this person need access to this information? These are the questions that need to constantly be asked and should be used as the basis for creating a zero-trust policy.

 

  • Set the rules and scale up: Once you’ve established the rules, automate and scale-up. Have this risk assessment to cover both those within and outside of the organisation.

 

  • Take it to the cloud: Simplify access by consolidating and modernizing network and security services to a common cloud-delivered architecture.

 

  • Set up micro segmentation: As discussed already, access control can be completely based on user identity – but it can also be based on network segmentation. This is known as micro segmentation which can create granular and specific secure subsets within a network where the user or device can connect and access only files it needs. From a security standpoint, if a compromise occurs it should be isolated to that particular subset.

 

  • Implement continuous monitoring: Even when the rules and policies are put in place, continuous monitoring of the network is vital. AI, machine learning and data analysis are just some examples of tools that can help with this.

 

The need for zero-trust approach has arisen due to the complex cyber security landscape organisations now find themselves in. This landscape itself keeps evolving and adapting by the day, so simple plug-in one-stop solutions will not work.

 

Organisations need to design an approach that works for their business; an approach robust enough to withstand bad actors, yet agile enough to evolve as required.  

 


 

Sanjeev Shukla is security lead for financial services at Accenture in the UK. Article copyright © 2022 Accenture. All rights reserved. Accenture, and its logo are trademarks of Accenture.

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543