zero trust

DriveLock Delivers Zero Trust to the Endpoint

DriveLock, a leading global provider of IT and data security solutions, specializes in a Zero Trust security approach based on the "never trust, always verify" principle. It is designed to combat harmful actions and access attempts from inside the corporate network as well as from external sources. DriveLock's Zero Trust platform is comprised of several pillars, providing a holistic approach to effective security.




zero trust

Cybersecurity Snapshot: Apply Zero Trust to Critical Infrastructure’s OT/ICS, CSA Advises, as Five Eyes Spotlight Tech Startups’ Security

Should critical infrastructure orgs boost OT/ICS systems’ security with zero trust? Absolutely, the CSA says. Meanwhile, the Five Eyes countries offer cyber advice to tech startups. Plus, a survey finds “shadow AI” weakening data governance. And get the latest on MFA methods, CISO trends and Uncle Sam’s AI strategy.

Dive into six things that are top of mind for the week ending Nov. 1.

1 - Securing OT/ICS in critical infrastructure with zero trust

As their operational technology (OT) computing environments become more digitized, converged with IT systems and cloud-based, critical infrastructure organizations should beef up their cybersecurity by adopting zero trust principles.

That’s the key message of the Cloud Security Alliance’s “Zero Trust Guidance for Critical Infrastructure,” which focuses on applying zero trust methods to OT and industrial control system (ICS) systems.

While OT/ICS environments were historically air gapped, that’s rarely the case anymore. “Modern systems are often interconnected via embedded wireless access, cloud and other internet-connected services, and software-as-a-service (SaaS) applications,” reads the 64-page white paper, which was published this week.

The CSA hopes the document will help cybersecurity teams and OT/ICS operators enhance the way they communicate and collaborate.

 

 

Among the topics covered are:

  • Critical infrastructure’s unique threat vectors
  • The convergence of IT/OT with digital transformation
  • Architecture and technology differences between OT and IT

The guide also outlines this five-step process for implementing zero trust in OT/ICS environments:

  • Define the surface to be protected
  • Map operational flows
  • Build a zero trust architecture
  • Draft a zero trust policy
  • Monitor and maintain the environment

A zero trust strategy boosts the security of critical OT/ICS systems by helping teams “keep pace with rapid technological advancements and the evolving threat landscape,” Jennifer Minella, the paper’s lead author, said in a statement.

To get more details, read:

For more information about OT systems cybersecurity, check out these Tenable resources: 

2 - Five Eyes publish cyber guidance for tech startups

Startup tech companies can be attractive targets for hackers, especially if they have weak cybersecurity and valuable intellectual property (IP).

To help startups prevent cyberattacks, the Five Eyes countries this week published cybersecurity guides tailored for these companies and their investors.

“This guidance is designed to help tech startups protect their innovation, reputation, and growth, while also helping tech investors fortify their portfolio companies against security risks," Mike Casey, U.S. National Counterintelligence and Security Center Director, said in a statement.

These are the top five cybersecurity recommendations from Australia, Canada, New Zealand, the U.S. and the U.K. for tech startups:

  • Be aware of threat vectors, including malicious insiders, insecure IT and supply chain risk.
  • Identify your most critical assets and conduct a risk assessment to pinpoint vulnerabilities.
  • Build security into your products by managing intellectual assets and IP; monitoring who has access to sensitive information; and ensuring this information’s protection.
  • Conduct due diligence when choosing partners and make sure they’re equipped to protect the data you share with them.
  • Before you expand abroad, prepare and become informed about these new markets by, for example, understanding local laws in areas such as IP protection and data protection.

 

 

“Sophisticated nation-state adversaries, like China, are working hard to steal the intellectual property held by some of our countries’ most innovative and exciting startups,” Ken McCallum, Director General of the U.K.’s MI5, said in a statement.

To get more details, check out these Five Eyes’ cybersecurity resources for tech startups:

3 - Survey: Unapproved AI use impacting data governance

Employees’ use of unauthorized AI tools is creating compliance issues in a majority of organizations. Specifically, it makes it harder to control data governance and compliance, according to almost 60% of organizations surveyed by market researcher Vanson Bourne.

“Amid all the investment and adoption enthusiasm, many organisations are struggling for control and visibility over its use,” reads the firm’s “AI Barometer: October 2024” publication. Vanson Bourne polls 100 IT and business executives each month about their AI investment plans.

To what extent do you think the unsanctioned use of AI tools is impacting your organisation's ability to maintain control over data governance and compliance?

(Source: Vanson Bourne’s “AI Barometer: October 2024”)

Close to half of organizations surveyed (44%) believe that at least 10% of their employees are using unapproved AI tools.

On a related front, organizations are also grappling with the issue of software vendors that unilaterally and silently add AI features to their products, especially to their SaaS applications.

While surveyed organizations say they’re reaping advantages from their AI usage, “such benefits are dependent on IT teams having the tools to address the control and visibility challenges they face,” the publication reads.

For more information about the use of unapproved AI tools, an issue also known as “shadow AI,” check out:

VIDEO

Shadow AI Risks in Your Company

 

4 - NCSC explains nuances of multi-factor authentication

Multi-factor authentication (MFA) comes in a variety of flavors, and understanding the differences is critical for choosing the right option for each use case in your organization.

To help cybersecurity teams better understand the different MFA types and their pluses and minuses, the U.K. National Cyber Security Centre (NCSC) has updated its MFA guidance.

“The new guidance explains the benefits that come with strong authentication, while also minimising the friction that some users associate with MFA,” reads an NCSC blog.

 

 

In other words, what type of MFA method to use depends on people’s roles, how they work, the devices they use, the applications or services they’re accessing and so on.

Topics covered include:

  • Recommended types of MFA, such as FIDO2 credentials, app-based and hardware-based code generators and message-based methods
  • The importance of using strong MFA to secure users’ access to sensitive data
  • The role of trusted devices in boosting and simplifying MFA
  • Bad practices that weaken MFA’s effectiveness, such as:
    • Retaining weaker, password-only authentication protocols for legacy services
    • Excluding certain accounts from MFA requirements because their users, usually high-ranking officials, find MFA inconvenient

To get more details, read:

For more information about MFA:

5 - U.S. gov’t outlines AI strategy, ties it to national security 

The White House has laid out its expectations for how the federal government ought to promote the development of AI in order to safeguard U.S. national security.

In the country’s first-ever National Security Memorandum (NSM) on AI, the Biden administration said the federal government must accomplish the following:

  • Ensure the U.S. is the leader in the development of safe, secure and trustworthy AI
  • Leverage advanced AI technologies to boost national security
  • Advance global AI consensus and governance

“The NSM’s fundamental premise is that advances at the frontier of AI will have significant implications for national security and foreign policy in the near future,” reads a White House statement.

 

 

The NSM’s directives to federal agencies include:

  • Help improve the security of chips and support the development of powerful supercomputers to be used by AI systems.
  • Help AI developers protect their work against foreign spies by providing them with cybersecurity and counterintelligence information.
  • Collaborate with international partners to create a governance framework for using AI in a way that is ethical, responsible and respects human rights. 

The White House also published a complementary document titled “Framework To Advance AI Governance and Risk Management in National Security,” which adds implementation details and guidance for the NSM.

6 - State CISOs on the frontlines of AI security

As the cybersecurity risks and benefits of AI multiply, most U.S. state CISOs find themselves at the center of their governments' efforts to craft AI security strategies and policies.

That’s according to the “2024 Deloitte-NASCIO Cybersecurity Study,” which surveyed CISOs from all 50 states and the District of Columbia.

Specifically, 88% of state CISOs reported being involved in the development of a generative AI strategy, while 96% are involved with creating a generative AI security policy.

However, their involvement in AI cybersecurity matters isn’t necessarily making them optimistic about their states’ ability to fend off AI-boosted attacks.

None said they feel “extremely confident” that their state can prevent AI-boosted attacks, while only 10% reported feeling “very confident.” The majority (43%) said they feel “somewhat confident” while the rest said they are either “not very confident” or “not confident at all.”

 

 

Naturally, most state CISOs see AI-enabled cyberthreats as significant, with 71% categorizing them as either “very high threat” (18%) or “somewhat high threat” (53%).

At the same time, state CISOs see the potential for AI to help their cybersecurity efforts, as 41% are already using generative AI for cybersecurity, and another 43% have plans to do so by mid-2025.

Other findings from the "2024 Deloitte-NASCIO Cybersecurity Study" include:

  • 4 in 10 state CISOs feel their budget is insufficient.
  • Almost half of respondents rank cybersecurity staffing as one of the top challenges.
  • In the past two years, 23 states have hired new CISOs, as the median tenure of a state CISO has dropped to 23 months, down from 30 months in 2022.
  • More state CISOs are taking on privacy protection duties — 86% are responsible for privacy protection, up from 60% two years ago.

For more information about CISO trends:




zero trust

DoD evaluates zero trust use cases, cloud providers

The Pentagon is also working with major cloud service providers like Microsoft and Google to evaluate their zero trust implementations.

The post DoD evaluates zero trust use cases, cloud providers first appeared on Federal News Network.




zero trust

Applying zero trust to OT requires ‘common sense approach’

Operational technology suffers from a technical debt that renders infrastructure vulnerable to cyberattacks as it becomes further enmeshed with IT systems.

The post Applying zero trust to OT requires ‘common sense approach’ first appeared on Federal News Network.




zero trust

Applying zero trust in federal IT

Patrick Sullivan, CTO of Security Strategy at Akamai Technologies, joins host John Gilroy on this week's Federal Tech Talk to discuss Zero Trust and how to apply it to federal information technology.

The post Applying zero trust in federal IT first appeared on Federal News Network.




zero trust

How the Army is always testing, training on zero trust

The Army I Corps used the recent Yama Sakura 85 exercise to further prove out how to create a single, secure network to share information with allied partners.

The post How the Army is always testing, training on zero trust first appeared on Federal News Network.




zero trust

From AI to zero trust, how 2023 will be remembered by federal IT experts

Federal News Network asked a panel of current and former federal executives for their opinions about 2023 and what federal IT and acquisition storylines stood out over the last 12 months.

The post From AI to zero trust, how 2023 will be remembered by federal IT experts first appeared on Federal News Network.




zero trust

Portnox survey reveals CISO’s views on job security, zero trust, multi-factor authentication and more

Portnox, provider of cloud-native, zero trust access control solutions, today unveiled the results of its latest survey, ‘CISO Perspectives for 2025’, revealing critical insights into the challenges faced by Chief Information Security Officers (CISOs) at large enterprises.




zero trust

DoD agencies confront zero trust challenges, misunderstandings ahead of 2026 deadline

The Defense Department’s zero trust framework is acting as a catalyst, driving mission owners to industry in search of zero trust solutions

The post DoD agencies confront zero trust challenges, misunderstandings ahead of 2026 deadline first appeared on Federal News Network.




zero trust

CMS looks to make ‘intentional’ investments in push to underlying zero trust pillars

During this exclusive CISO Handbook webinar, moderator Justin Doubleday and guest Robert Wood, chief information security officer at Centers for Medicare and Medicaid Services will explore how his agency is implementing zero trust and other modern security practices. In addition, David Chow, global chief technology strategy officer at Trend Micro, will provide an industry perspective.

The post CMS looks to make ‘intentional’ investments in push to underlying zero trust pillars first appeared on Federal News Network.




zero trust

Building zero trust as IT devices continue to multiply

During this exclusive webinar, moderator Scott Maucione and guest Steve Wallace, chief technology officer at the Defense Information Systems Agency will discuss the IT landscape and asset management in the era of zero trust. In addition, Tom Kennedy, vice president at Axonius will provide an industry perspective.

The post Building zero trust as IT devices continue to multiply first appeared on Federal News Network.




zero trust

Cyber leaders aim to embed zero trust principles in systems

As civilian and defense agencies work through the nuances of incorporating zero trust strategies, the question becomes: How can this process be sped up? During this exclusive webinar, moderator Justin Doubleday will discuss tools and techniques accelerating the move to zero trust with agency and industry leaders.

The post Cyber leaders aim to embed zero trust principles in systems first appeared on Federal News Network.




zero trust

DISA pushes companies to adopt standards to ensure interoperability across zero trust architectures

During this exclusive CISO Handbook webinar, moderator Justin Doubleday and guests Brian Hermann from the Defense Information Systems Agency and Christopher Day from Tenable will explore zero trust progress and strategy at DISA.

The post DISA pushes companies to adopt standards to ensure interoperability across zero trust architectures first appeared on Federal News Network.





zero trust

Leveraging Wazuh for Zero Trust security

Zero Trust security changes how organizations handle security by doing away with implicit trust while continuously analyzing and validating access requests. Contrary to perimeter-based security, users within an environment are not automatically trusted upon gaining access. Zero Trust security encourages continuous monitoring of every device and user, which ensures sustained protection after




zero trust

Onclave Debuts Secure IoT® at RSA 2020 First, True Zero Trust Platform for Enterprises and Device OEMs

Secure IoT® is the industry's first solution to run and protect any "thing" while reducing customer costs.




zero trust

'Zero Trust' and the Remote Worker

The shift to working at home during the COVID-19 pandemic is yet another reason to embrace the "zero trust" strategy, says Dave Lewis of Duo Security, who provides guidance.




zero trust

'Zero Trust' and the Remote Worker

The shift to working at home during the COVID-19 pandemic is yet another reason to embrace the "zero trust" strategy, says Dave Lewis of Duo Security, who provides guidance.




zero trust

'Zero Trust' and the Remote Worker

The shift to working at home during the COVID-19 pandemic is yet another reason to embrace the "zero trust" strategy, says Dave Lewis of Duo Security, who provides guidance.




zero trust

Zero trust networks with VMware NSX : build highly secure network architectures for your data centers [Electronic book] / Sreejith Keeriyattil.

New York : Apress, [2019]




zero trust

Zero Trust Networks with VMware NSX [electronic resource] : Build Highly Secure Network Architectures for Your Data Centers / by Sreejith Keeriyattil

Keeriyattil, Sreejith. author