Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
view of earth from space which shows some areas with lights on as it is night time

14 May 2024

4 minutes read time

The 5 Common Mistakes Businesses Make With Zero Trust Security

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Zero Trust security is rapidly changing the cybersecurity landscape. Zero Trust security protocol shifts controls from traditional perimeter-based security models. Every connection to your business assets is continuously verified before access to resources is granted. So effective is it that 56% of global organisations say adopting Zero Trust is a “Top” or “High” priority.

A zero-trust approach offers significant security advantages, but the transition process presents several potential pitfalls. Running into these can harm rather than help a company’s cybersecurity posture.

In this blog, we explore common pitfalls whilst offering guidance on navigating effective Zero Trust security adoption.

What is Zero Trust security?

A Zero Trust security model assumes that everything and everyone could be a potential threat. This is true even for all users, even those already inside a company network. Whilst it sounds like a drastic measure to take, it adds an effective lay of security and provides organisations with controls that allow it to better manage users.

The key tenets of Zero Trust are:

  • A Policy of Least Privilege: company users are only given access to areas that are essential for them to perform their job role. This is managed using RBAC (Role-Based Access Control) measures, and access can be both granted and withdrawn at any time.
  • Continuous Verification: Authentication isn’t ‘one and done”; it’s an ongoing process. Users and devices are being perpetually assessed against access rules configured by the business. If a user and/or device stops meeting these rules, they will be asked to reauthenticate.
  • Micro-Segmentation: Networks are broken down into smaller areas. This mitigates the potential damage done to the wider network in the event of a security incident, as it allows for easier isolation and resolution of an issue.

The Most Common Zero Trust Implementation Mistakes

Thinking of Zero Trust as Product and Not A Strategy

A lot of software and hardware vendors pitch Zero Trust as a product feature, leading organisations to think of zero trust as a product. This is the wrong way to think of Zero Trust security. Zero Trust is a methodology and a philosophy and it should be used as such,

Zero Trust should form the basis of how and why a company uses products and applications. For example, using multi-factor authentication (MFA) is a key part of a Zero Trust security model; it helps support a company’s security posture.

Prioritising Technical Controls, Not People 

Whilst the implementation of technical controls is crucial to the success of implementing a Zero Trust security model, a company’s culture and staff behaviour is just as key. It is important to communicate with employees and train them to understand what is required of them to help protect the business.

Not Taking Your IT Inventory

It’s hard to protect something if you don’t know that it exists. The best way to avoid this issue is to take an inventory that catalogs devices, users, and applications prior to implementing a Zero Trust model. Once you have done so, you can consider the roadmap to a successful rollout.

Overcomplicating the Rollout

As mentioned above, you should create a roadmap to help guide you through the process of implementing a Zero Trust security model.

A roadmap will stop you from attempting to do everything at once; something that can cause huge problems and cause unnecessary stress. Prioritise business-critical areas before expanding to other areas of your organisation.

Forgetting Third-Party Access

Whilst third parties may not be employees, they may need access to certain company assets. Forgetting them could serve a problem in the form of work stopping and tickets piling up. Whilst third parties are, by their nature, a security risk, you can manage this by effectively defining access controls and monitoring activity.

Zero Trust Is A Marathon, Not A Sprint 

Building a Zero Trust environment takes time and great effort. To keep yourself on the right path, do the following:

  • Set Realistic Targets: Define achievable milestones and take a moment to celebrate small wins along the way.
  • Employ Continuous Monitoring: The threat landscape is evolving constantly. Monitor your Zero Trust system and adjust strategies as required.
  • Invest in Training for Your Employees: include staff as active participants in your Zero Trust implementation. As is always true, security awareness training is vital.

With these pitfalls and the amount of effort required, is Zero Trust security worth adopting?

Yes. Something easy to do is rarely worth doing. Employing a Zero Trust security model will lead to enhanced data protection, an improved user experience, and increased levels of compliance.

For help with implementing Zero Trust security policies or advice on other areas of cyber security, contact us.

Back to blog

Recent blogs from CT24

view of earth from space which shows some areas with lights on as it is night time

The steep rise in ‘ClickFix’ style phishing attacks  

What is ClickFix? ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices. Typically, we find that a user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security…

Read more

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more