zero trust DriveLock Delivers Zero Trust to the Endpoint By www.prleap.com Published On :: Tue, 28 Jan 2020 08:30:00 PST DriveLock, a leading global provider of IT and data security solutions, specializes in a Zero Trust security approach based on the "never trust, always verify" principle. It is designed to combat harmful actions and access attempts from inside the corporate network as well as from external sources. DriveLock's Zero Trust platform is comprised of several pillars, providing a holistic approach to effective security. Full Article
zero trust Cybersecurity Snapshot: Apply Zero Trust to Critical Infrastructure’s OT/ICS, CSA Advises, as Five Eyes Spotlight Tech Startups’ Security By www.tenable.com Published On :: Fri, 01 Nov 2024 09:00:00 -0400 Should critical infrastructure orgs boost OT/ICS systems’ security with zero trust? Absolutely, the CSA says. Meanwhile, the Five Eyes countries offer cyber advice to tech startups. Plus, a survey finds “shadow AI” weakening data governance. And get the latest on MFA methods, CISO trends and Uncle Sam’s AI strategy.Dive into six things that are top of mind for the week ending Nov. 1.1 - Securing OT/ICS in critical infrastructure with zero trustAs their operational technology (OT) computing environments become more digitized, converged with IT systems and cloud-based, critical infrastructure organizations should beef up their cybersecurity by adopting zero trust principles.That’s the key message of the Cloud Security Alliance’s “Zero Trust Guidance for Critical Infrastructure,” which focuses on applying zero trust methods to OT and industrial control system (ICS) systems.While OT/ICS environments were historically air gapped, that’s rarely the case anymore. “Modern systems are often interconnected via embedded wireless access, cloud and other internet-connected services, and software-as-a-service (SaaS) applications,” reads the 64-page white paper, which was published this week.The CSA hopes the document will help cybersecurity teams and OT/ICS operators enhance the way they communicate and collaborate. Among the topics covered are:Critical infrastructure’s unique threat vectorsThe convergence of IT/OT with digital transformationArchitecture and technology differences between OT and ITThe guide also outlines this five-step process for implementing zero trust in OT/ICS environments:Define the surface to be protectedMap operational flowsBuild a zero trust architectureDraft a zero trust policyMonitor and maintain the environmentA zero trust strategy boosts the security of critical OT/ICS systems by helping teams “keep pace with rapid technological advancements and the evolving threat landscape,” Jennifer Minella, the paper’s lead author, said in a statement.To get more details, read:The report’s announcement “New Paper from Cloud Security Alliance Examines Considerations and Application of Zero Trust Principles for Critical Infrastructure”The full report “Zero Trust Guidance for Critical Infrastructure”A complementary slide presentationFor more information about OT systems cybersecurity, check out these Tenable resources: “What is operational technology (OT)?” (guide)“Discover, Measure, and Minimize the Risk Posed by Your Interconnected IT/OT/IoT Environments” (on-demand webinar)“How To Secure All of Your Assets - IT, OT and IoT - With an Exposure Management Platform” (blog)“Blackbox to blueprint: The security leader’s guidebook to managing OT and IT risk” (white paper)“Tenable Cloud Risk Report 2024” (white paper)2 - Five Eyes publish cyber guidance for tech startupsStartup tech companies can be attractive targets for hackers, especially if they have weak cybersecurity and valuable intellectual property (IP).To help startups prevent cyberattacks, the Five Eyes countries this week published cybersecurity guides tailored for these companies and their investors.“This guidance is designed to help tech startups protect their innovation, reputation, and growth, while also helping tech investors fortify their portfolio companies against security risks," Mike Casey, U.S. National Counterintelligence and Security Center Director, said in a statement.These are the top five cybersecurity recommendations from Australia, Canada, New Zealand, the U.S. and the U.K. for tech startups:Be aware of threat vectors, including malicious insiders, insecure IT and supply chain risk.Identify your most critical assets and conduct a risk assessment to pinpoint vulnerabilities.Build security into your products by managing intellectual assets and IP; monitoring who has access to sensitive information; and ensuring this information’s protection.Conduct due diligence when choosing partners and make sure they’re equipped to protect the data you share with them.Before you expand abroad, prepare and become informed about these new markets by, for example, understanding local laws in areas such as IP protection and data protection. “Sophisticated nation-state adversaries, like China, are working hard to steal the intellectual property held by some of our countries’ most innovative and exciting startups,” Ken McCallum, Director General of the U.K.’s MI5, said in a statement.To get more details, check out these Five Eyes’ cybersecurity resources for tech startups:The announcement “Five Eyes Launch Shared Security Advice Campaign for Tech Startups”The main guides: “Secure Innovation: Security Advice for Emerging Technology Companies”“Secure Innovation: Security Advice for Emerging Technology Investors”These complementary documents:“Secure Innovation: Scenarios and Mitigations”“Secure Innovation: Travel Security Guidance”“Secure Innovation: Due Diligence Guidance”“Secure Innovation: Companies Summary”3 - Survey: Unapproved AI use impacting data governanceEmployees’ use of unauthorized AI tools is creating compliance issues in a majority of organizations. Specifically, it makes it harder to control data governance and compliance, according to almost 60% of organizations surveyed by market researcher Vanson Bourne.“Amid all the investment and adoption enthusiasm, many organisations are struggling for control and visibility over its use,” reads the firm’s “AI Barometer: October 2024” publication. Vanson Bourne polls 100 IT and business executives each month about their AI investment plans.To what extent do you think the unsanctioned use of AI tools is impacting your organisation's ability to maintain control over data governance and compliance?(Source: Vanson Bourne’s “AI Barometer: October 2024”)Close to half of organizations surveyed (44%) believe that at least 10% of their employees are using unapproved AI tools.On a related front, organizations are also grappling with the issue of software vendors that unilaterally and silently add AI features to their products, especially to their SaaS applications.While surveyed organizations say they’re reaping advantages from their AI usage, “such benefits are dependent on IT teams having the tools to address the control and visibility challenges they face,” the publication reads.For more information about the use of unapproved AI tools, an issue also known as “shadow AI,” check out:“Do You Think You Have No AI Exposures? Think Again” (Tenable)“Shadow AI poses new generation of threats to enterprise IT” (TechTarget)“10 ways to prevent shadow AI disaster” (CIO)“Never Trust User Inputs -- And AI Isn't an Exception: A Security-First Approach” (Tenable)“Shadow AI in the ‘dark corners’ of work is becoming a big problem for companies” (CNBC)VIDEOShadow AI Risks in Your Company 4 - NCSC explains nuances of multi-factor authenticationMulti-factor authentication (MFA) comes in a variety of flavors, and understanding the differences is critical for choosing the right option for each use case in your organization.To help cybersecurity teams better understand the different MFA types and their pluses and minuses, the U.K. National Cyber Security Centre (NCSC) has updated its MFA guidance.“The new guidance explains the benefits that come with strong authentication, while also minimising the friction that some users associate with MFA,” reads an NCSC blog. In other words, what type of MFA method to use depends on people’s roles, how they work, the devices they use, the applications or services they’re accessing and so on.Topics covered include:Recommended types of MFA, such as FIDO2 credentials, app-based and hardware-based code generators and message-based methodsThe importance of using strong MFA to secure users’ access to sensitive dataThe role of trusted devices in boosting and simplifying MFABad practices that weaken MFA’s effectiveness, such as:Retaining weaker, password-only authentication protocols for legacy servicesExcluding certain accounts from MFA requirements because their users, usually high-ranking officials, find MFA inconvenientTo get more details, read:The NCSC blog “Not all types of MFA are created equal”The NCSC guide “Multi-factor authentication for your corporate online services”For more information about MFA:“Multifactor Authentication Cheat Sheet” (OWASP)“Deploying Multi Factor Authentication – The What, How, and Why” (SANS Institute)“How MFA gets hacked — and strategies to prevent it” (CSO)“How Multifactor Authentication Supports Growth for Businesses Focused on Zero Trust” (BizTech)“What is multi-factor authentication?” (TechTarget)5 - U.S. gov’t outlines AI strategy, ties it to national security The White House has laid out its expectations for how the federal government ought to promote the development of AI in order to safeguard U.S. national security.In the country’s first-ever National Security Memorandum (NSM) on AI, the Biden administration said the federal government must accomplish the following:Ensure the U.S. is the leader in the development of safe, secure and trustworthy AILeverage advanced AI technologies to boost national securityAdvance global AI consensus and governance“The NSM’s fundamental premise is that advances at the frontier of AI will have significant implications for national security and foreign policy in the near future,” reads a White House statement. The NSM’s directives to federal agencies include:Help improve the security of chips and support the development of powerful supercomputers to be used by AI systems.Help AI developers protect their work against foreign spies by providing them with cybersecurity and counterintelligence information.Collaborate with international partners to create a governance framework for using AI in a way that is ethical, responsible and respects human rights. The White House also published a complementary document titled “Framework To Advance AI Governance and Risk Management in National Security,” which adds implementation details and guidance for the NSM.6 - State CISOs on the frontlines of AI securityAs the cybersecurity risks and benefits of AI multiply, most U.S. state CISOs find themselves at the center of their governments' efforts to craft AI security strategies and policies.That’s according to the “2024 Deloitte-NASCIO Cybersecurity Study,” which surveyed CISOs from all 50 states and the District of Columbia.Specifically, 88% of state CISOs reported being involved in the development of a generative AI strategy, while 96% are involved with creating a generative AI security policy.However, their involvement in AI cybersecurity matters isn’t necessarily making them optimistic about their states’ ability to fend off AI-boosted attacks.None said they feel “extremely confident” that their state can prevent AI-boosted attacks, while only 10% reported feeling “very confident.” The majority (43%) said they feel “somewhat confident” while the rest said they are either “not very confident” or “not confident at all.” Naturally, most state CISOs see AI-enabled cyberthreats as significant, with 71% categorizing them as either “very high threat” (18%) or “somewhat high threat” (53%).At the same time, state CISOs see the potential for AI to help their cybersecurity efforts, as 41% are already using generative AI for cybersecurity, and another 43% have plans to do so by mid-2025.Other findings from the "2024 Deloitte-NASCIO Cybersecurity Study" include:4 in 10 state CISOs feel their budget is insufficient.Almost half of respondents rank cybersecurity staffing as one of the top challenges.In the past two years, 23 states have hired new CISOs, as the median tenure of a state CISO has dropped to 23 months, down from 30 months in 2022.More state CISOs are taking on privacy protection duties — 86% are responsible for privacy protection, up from 60% two years ago.For more information about CISO trends:“What’s important to CISOs in 2024” (PwC)“The CISO’s Tightrope: Balancing Security, Business, and Legal Risks in 2024” (The National CIO Review)“State of CISO Leadership: 2024” (SC World)“4 Trends That Will Define the CISO's Role in 2024” (SANS Institute) Full Article
zero trust DoD evaluates zero trust use cases, cloud providers By federalnewsnetwork.com Published On :: Mon, 07 Oct 2024 22:15:42 +0000 The Pentagon is also working with major cloud service providers like Microsoft and Google to evaluate their zero trust implementations. The post DoD evaluates zero trust use cases, cloud providers first appeared on Federal News Network. Full Article All News Cloud Computing Cybersecurity Defense Defense News Technology DoD zero trust strategy Les Call zero trust
zero trust Applying zero trust to OT requires ‘common sense approach’ By federalnewsnetwork.com Published On :: Fri, 18 Oct 2024 15:54:59 +0000 Operational technology suffers from a technical debt that renders infrastructure vulnerable to cyberattacks as it becomes further enmeshed with IT systems. The post Applying zero trust to OT requires ‘common sense approach’ first appeared on Federal News Network. Full Article All News Cloud Computing Federal Insights IT Modernization Technology Booz Allen Hamilton
zero trust Applying zero trust in federal IT By federalnewsnetwork.com Published On :: Mon, 07 Mar 2022 13:19:14 +0000 Patrick Sullivan, CTO of Security Strategy at Akamai Technologies, joins host John Gilroy on this week's Federal Tech Talk to discuss Zero Trust and how to apply it to federal information technology. The post Applying zero trust in federal IT first appeared on Federal News Network. Full Article Artificial Intelligence Automation Big Data Cloud Computing Cybersecurity Federal Tech Talk IT Modernization Radio Interviews Technology Akamai Technologies John Gilroy Patrick Sullivan zero trust
zero trust How the Army is always testing, training on zero trust By federalnewsnetwork.com Published On :: Thu, 13 Jun 2024 12:49:20 +0000 The Army I Corps used the recent Yama Sakura 85 exercise to further prove out how to create a single, secure network to share information with allied partners. The post How the Army is always testing, training on zero trust first appeared on Federal News Network. Full Article All News Army Ask the CIO Ask the CIO Podcasts Cybersecurity Defense Defense Industry Defense News Radio Interviews Technology Army I Corps GDIT John Sahlin Phil Dieppa Rett Burroughs Roberto Nunez Yama Sakura zero trust
zero trust From AI to zero trust, how 2023 will be remembered by federal IT experts By federalnewsnetwork.com Published On :: Mon, 08 Jan 2024 21:36:07 +0000 Federal News Network asked a panel of current and former federal executives for their opinions about 2023 and what federal IT and acquisition storylines stood out over the last 12 months. The post From AI to zero trust, how 2023 will be remembered by federal IT experts first appeared on Federal News Network. Full Article All News Artificial Intelligence Cybersecurity Defense IT Modernization Reporter's Notebook Technology CyberSec Energy Department Franklin Square Group Gundeep Ahluwalia Guy Cavallo Jonathan Alboum Kevin Cummins Labor Department Marines Corps Mike Hettinger Office of Personnel Management Renata Spinks ServiceNow Steven Brand
zero trust Portnox survey reveals CISO’s views on job security, zero trust, multi-factor authentication and more By www.logisticsit.com Published On :: Thu, 13 Nov 1800 17:28:54 -0001 Portnox, provider of cloud-native, zero trust access control solutions, today unveiled the results of its latest survey, ‘CISO Perspectives for 2025’, revealing critical insights into the challenges faced by Chief Information Security Officers (CISOs) at large enterprises. Full Article
zero trust DoD agencies confront zero trust challenges, misunderstandings ahead of 2026 deadline By federalnewsnetwork.com Published On :: Wed, 02 Oct 2024 13:08:24 +0000 The Defense Department’s zero trust framework is acting as a catalyst, driving mission owners to industry in search of zero trust solutions The post DoD agencies confront zero trust challenges, misunderstandings ahead of 2026 deadline first appeared on Federal News Network. Full Article All News Big Data Federal Insights IT Modernization Technology AWS SAPNS2
zero trust CMS looks to make ‘intentional’ investments in push to underlying zero trust pillars By federalnewsnetwork.com Published On :: Thu, 11 Aug 2022 18:55:27 +0000 During this exclusive CISO Handbook webinar, moderator Justin Doubleday and guest Robert Wood, chief information security officer at Centers for Medicare and Medicaid Services will explore how his agency is implementing zero trust and other modern security practices. In addition, David Chow, global chief technology strategy officer at Trend Micro, will provide an industry perspective. The post CMS looks to make ‘intentional’ investments in push to underlying zero trust pillars first appeared on Federal News Network. Full Article Federal Insights Roundtables David Chow Robert Wood Trend Micro
zero trust Building zero trust as IT devices continue to multiply By federalnewsnetwork.com Published On :: Mon, 12 Sep 2022 20:59:02 +0000 During this exclusive webinar, moderator Scott Maucione and guest Steve Wallace, chief technology officer at the Defense Information Systems Agency will discuss the IT landscape and asset management in the era of zero trust. In addition, Tom Kennedy, vice president at Axonius will provide an industry perspective. The post Building zero trust as IT devices continue to multiply first appeared on Federal News Network. Full Article Federal Insights Roundtables Axonius
zero trust Cyber leaders aim to embed zero trust principles in systems By federalnewsnetwork.com Published On :: Tue, 15 Nov 2022 13:53:17 +0000 As civilian and defense agencies work through the nuances of incorporating zero trust strategies, the question becomes: How can this process be sped up? During this exclusive webinar, moderator Justin Doubleday will discuss tools and techniques accelerating the move to zero trust with agency and industry leaders. The post Cyber leaders aim to embed zero trust principles in systems first appeared on Federal News Network. Full Article Federal Insights Roundtables Gary Barlet Illumio Jamie Holcombe Kevin Twibell
zero trust DISA pushes companies to adopt standards to ensure interoperability across zero trust architectures By federalnewsnetwork.com Published On :: Tue, 25 Apr 2023 14:32:35 +0000 During this exclusive CISO Handbook webinar, moderator Justin Doubleday and guests Brian Hermann from the Defense Information Systems Agency and Christopher Day from Tenable will explore zero trust progress and strategy at DISA. The post DISA pushes companies to adopt standards to ensure interoperability across zero trust architectures first appeared on Federal News Network. Full Article Defense Federal Insights Roundtables Technology Brian Hermann Christopher Day CISO Handbook DISA Tenable
zero trust Tips and Tactics from Zero Trust Cyber Exchange By federalnewsnetwork.com Published On :: Fri, 16 Sep 2022 20:05:44 +0000 Our new ebook includes key pointers and lessons learned shared by more than two dozen federal and industry cyber leaders during our Zero Trust Cyber Exchange. Download it now. The post Tips and Tactics from Zero Trust Cyber Exchange first appeared on Federal News Network. Full Article eBooks Federal Insights Zero Trust Exchange
zero trust Leveraging Wazuh for Zero Trust security By thehackernews.com Published On :: Tue, 05 Nov 2024 16:30:00 +0530 Zero Trust security changes how organizations handle security by doing away with implicit trust while continuously analyzing and validating access requests. Contrary to perimeter-based security, users within an environment are not automatically trusted upon gaining access. Zero Trust security encourages continuous monitoring of every device and user, which ensures sustained protection after Full Article
zero trust Onclave Debuts Secure IoT® at RSA 2020 First, True Zero Trust Platform for Enterprises and Device OEMs By www.24-7pressrelease.com Published On :: Wed, 26 Feb 2020 07:00:00 GMT Secure IoT® is the industry's first solution to run and protect any "thing" while reducing customer costs. Full Article
zero trust 'Zero Trust' and the Remote Worker By www.bankinfosecurity.com Published On :: The shift to working at home during the COVID-19 pandemic is yet another reason to embrace the "zero trust" strategy, says Dave Lewis of Duo Security, who provides guidance. Full Article
zero trust 'Zero Trust' and the Remote Worker By www.govinfosecurity.com Published On :: The shift to working at home during the COVID-19 pandemic is yet another reason to embrace the "zero trust" strategy, says Dave Lewis of Duo Security, who provides guidance. Full Article
zero trust 'Zero Trust' and the Remote Worker By www.cuinfosecurity.com Published On :: The shift to working at home during the COVID-19 pandemic is yet another reason to embrace the "zero trust" strategy, says Dave Lewis of Duo Security, who provides guidance. Full Article
zero trust Zero trust networks with VMware NSX : build highly secure network architectures for your data centers [Electronic book] / Sreejith Keeriyattil. By encore.st-andrews.ac.uk Published On :: New York : Apress, [2019] Full Article
zero trust Zero Trust Networks with VMware NSX [electronic resource] : Build Highly Secure Network Architectures for Your Data Centers / by Sreejith Keeriyattil By prospero.murdoch.edu.au Published On :: Keeriyattil, Sreejith. author Full Article