While the zero-trust security model may offer excellent defense against emerging, unrecognized, and unpredictable threats, a piecemeal implementation approach, significant commitment for ongoing administration, and productivity concerns pose daunting challenges preventing organizations from adopting it fully. So how must an organization address these challenges and harness the significant benefits it offers?
Contributor
Transcript
Sanjog Aul [00:00:00]:
Hello and welcome to CTN. To learn more about the show, please visit ciotalknetwork.com and today’s topic is Will Zero Trust Adoption Remain a Pipe Dream? Now, why do I say that Zero Trust security model actually has a great promise. It would help you use this as a defense against the emerging and the unrecognized and the unpredictable threats. We still, people have tried to use it, but then it seems like that lot of organizations are engaged in some sort of a piecemeal implementation approach or they are having issues with the administration’s commitment towards it or some people say, this is a lot of work because you are touching too many things and that’s why Zero Trust doesn’t seem to be gaining ground. Now, I may be wrong. Some organizations might have reached that utopic state, but many organizations say it has not truly become fully cooked yet. So what should organizations do, whether business, IT security, all of these constituents, how should they work individually and collectively to allow Zero Trust to gain ground, get properly implemented, which will help of course, all parties equally.
Sanjog Aul [00:01:15]:
So to discuss this, I have an esteemed panel here. I’ve got three guests, so starting with Gerald Caron, Chief Information Officer, Assistant Inspector General of Information Technology, U.S. Department of Health and Human Services and Office of Inspector General. Hey Gerald, how are you?
Gerald Caron [00:01:33]:
Good.
Gerald Caron [00:01:34]:
How are you?
Sanjog Aul [00:01:35]:
Good, sir, can’t complain and we also have Dan Wilkins, Chief Information Security Officer with the State of Arizona. Hey Dan, how’s life?
Dan Wilkins [00:01:42]:
Good morning. Doing good.
Sanjog Aul [00:01:44]:
All right and Bharat Soni, Chief Information Security Officer and Group Head, Information Security Group, Guarantee Trust Bank. Hey Bharat, how is everything for you?
Bharat Soni [00:01:56]:
I’m fine, Sanjog. Hello everyone. Everything going good.
Sanjog Aul [00:02:01]:
Beautiful, so, let’s jump in, so Gerald, this first question is for you. Zero Trust is not new. I heard about it almost a decade ago but then we still hear people struggling to implement it. Even though we have invested in it and related to people, process the tools and we have tried to do change management, the whole nine. Yet things are at a less than desired state.
Sanjog Aul [00:02:30]:
So what could be missing here?
Gerald Caron [00:02:34]:
No, that’s a good question and I can speak from the experience of people that I’ve interacted with and groups. It is a culture change. It’s a different way of looking at things. It’s not something that you just give to the identity management team if there’s one, or the network team and say, hey, go do this. It’s an architecture. It’s everything has to work together. So it’s a team effort
Gerald Caron [00:02:59]:
and I’ve seen some organizations, they work in stove pipes, right here’s the network team and they do their thing and their stovepipe and do their security and everything but really this has to work together. So it’s an integration effort. At the end of the day. Yes, people integrate and do things today, but this is a more seamless integration. If you look at the Department of Homeland Security’s pillars, which are data, network, application, end user, identity, and oh my god, I forgot the last one, application, then those, this has to all work through all those pillars. So all those pillars have to be integrated in some form or fashion.
Gerald Caron [00:03:38]:
You can’t just work on the identity pillar in my eyes and think that everything’s going to work. There’s so much more to Zero Trust. You almost got to look at the totality of it and understand where you’re at and then understand where you need to be and what are those gaps that you have. You may be doing some things that you can take advantage of, but you really got to look at it in the totality. So it’s an architecture integration effort. It’s not a take a thing off the shelf kind of thing. It’s and it’s also not just a technology challenge.
Gerald Caron [00:04:09]:
There’s the policy and risk tolerance challenge as well. Understanding those risk tolerances and when thresholds are met, what are those policies that you’re going to put in place, really understanding that and also understanding the data. What you’re protecting at the end of the day is the data. What is that data? Where is that data and what does normal look like because if you don’t know what normal looks like, how are you going to take an action when you don’t, when something abnormal happens? I think those things all add up to some of the struggles that I see where, way people organize, some organizations that I’ve experienced are organized. It’s more than just an IT problem. It’s an organizational thing as well, and it’s a culture change.
Sanjog Aul [00:04:50]:
So, Dan, coming to you. So great response, Gerald. Now you mentioned about looking at it holistically. So Dan, coming to you, is this like an elephant which we can eat one bite at a time and still eat it all by and that way at least it is realistic or it’ll become a boil the ocean if you try to eat it all at the same time. What’s the best way to tackle it the first place?
Dan Wilkins [00:05:12]:
The thing is, people want to boil the ocean. They want to do everything in one shot. They want to just have that big bang, effort and be done with it but the reality here is these things take time and effort. These things are not going to be a simple plug my appliance in and I’m all sudden Zero Trust compliant here. So I know everybody wants the easy button. They want to be able to just put what vendor is going to give me the solution that I can just install in my environment, that I’ve done. I can walk away and wash my hands and I’m all set
Dan Wilkins [00:05:38]:
but really what we have to do is just mentioned here is we have to educate, we have to guide the thought process. We have to look at what the culture in the organization is today and how do we start slowly migrating it and change the ship’s course a little bit here because this is not a technology problem to solve. Yes, we can use technology to help us, we can use technology to our benefit in our favor here, but this is not a tool that we’re implementing here. We have to work on people first. We have to work on the thought process, the mindset, on the organizational goals and we have to get away from this, this buzzword. I heard this in SkyMall magazine. I heard this on our business flight that I was taking between here and there
Dan Wilkins [00:06:20]:
and we have to get down to the know the why. Why are we doing this? Why is Zero Trust important? Why we’ve been doing elements of Zero Trust for years, but nobody has really put the whole container around this and said this is what we’re doing from a holistic approach and we have to start with the basics. We can’t do, you can’t jump to the top here without doing the foundation first. You got to build a foundation to get there.
Sanjog Aul [00:06:43]:
So, Bharat, we have had 10 years, okay and with both Dan and Gerald mentioning that yes, we want to do holistically and yes, we have to do piecemeal for us to get there, but 10 years is a lot of time. I’m not saying it was an easy problem to crack in the first case, first place. So what do you think could be happening? Are we going around in circles to say sometimes we are trying to do holistically, other times we are trying to break it apart and try to tackle, but we’re not reaching to where we want to. Where are we missing the boat?
Bharat Soni [00:07:12]:
Okay, so I will align my thought processes with Diane and Gerald both but however, there are a number of reasons why organization really struggles to adopt a Zero Trust. It’s been available already available into the environment. A big part of the organization typically have the opinion that Zero Trust implementation nowadays is the buzzword of Zero Trust which means introduction of shiny new tools. Totally shiny new tools to be introduced and then it has to be it’s like mammoth or something which we need to strategically think it’s. I believe that there are why organizations struggle to implement Zero Trust is, there is always a piecemeal approach followed in such implementation. We can’t take it as a holistic this thing.
Bharat Soni [00:07:59]:
We also, we means, in organizations, anyone who wants to implement Zero Trust must allow or follow a strategic thought process first. In designing and implementation of a Zero Trust involvement into the environment. The strategy should consider very deeply consider the complex factors that are involved. For example, first thing first is planning. Many of the time Zero Trust implementation that we see today comes as also add ons. It’s not something that it’s coming from the base. It’s an add on to already existing infrastructure.
Bharat Soni [00:08:34]:
We have something in place. We want to implement something new into the architecture and then there are bolted after the fact that now we want to implement. There are certain implementation which are already been done. Now we are bolting it something on the fact that some new amount of always when you introduce something new there’s always a friction into the process. So we have to consider all those things granule. Even some legacy application which are into the system they don’t even have support for model itself is not considered because those legacy applications are even before 10 years old, 20 years old application. They are just upgrading themselves from a security perspective
Bharat Soni [00:09:11]:
but not including the Zero Trust framework into the model. Unless we change the whole things back. It will require a complex complete redesign or maybe very significant workaround to have Zero Trust model work into any organization. So that’s. That’s at a strategic level. Obviously we need to include the people process and the other strategic implementation part of what is in the system already and how we want to implement it. That’s my thought.
Sanjog Aul [00:09:39]:
So Gerald, based on Bharat what he’s just said. He said a bunch of things which could be the reasons why Zero Trust people are not able to implement but can we just keep talking about things which are preventing us or can we do something about it so that in five years. I will not say a year, in five years if I come back and have the same discussion with you guys. You don’t say that these are challenges anymore and life is good and we are singing Kumbaya and Zero Trust is implemented.
Gerald Caron [00:10:10]:
Being with the federal government, of course we have executive orders and we have OMB, memos out of OMB telling us to do it now. So we have that forcing thing that, that of course is making us do it. Now our people still struggling and there’s a lot of education to be done, but it’s starting to, that wave is starting to shift. So people are starting to catch up. What we could have been doing started 10 years ago. We’re just, some people are just starting and understanding the concept and wrapping their head around it.
Gerald Caron [00:10:39]:
So, I think for us five years you’re going to see some successful implementations. Now are they going to be that utopia that with all the Forster principles and that the John Kinder Vad who is the father of Zero Trust, is it going to be that utopia? Maybe not but, it’s steps forward are better than no steps at all in this case and I think what’s also going to change that culture is and I think Dan, being with the state government, if I’m not mistaken, we’re very compliance focused, whereas we have a checkbox of things that we have to go through for our systems, Zero Trust doesn’t lend itself to that necessarily that checkbox of compliance. What we’re trying to be, we’re trying to be with Zero Trust, we’re trying to be effective at our cybersecurity and why do I say that compliance and effectiveness are two different things.
Gerald Caron [00:11:28]:
The compliance can say I must provide authentic, strong authentication or authentication, I do username and password. That’s not strong, that’s not effective. We really need to focus on effectiveness and how we measure that effectiveness going forward and I think once that’s realized and we start focusing on how to get to that stage and that thought process is going to help but I think you’ll see successful within five years. As you said, it is a multi year journey. It’s not a one year thing, it’s not a shiny object. It changed the way, it’s going to change the way users work, but build those things in those requirements.
Gerald Caron [00:12:06]:
So really this is a big communication effort for us as well within our organization to include our users because we want to know how they want to work, what data they rely on, when do they rely on that data. So we can build those requirements and then that will reduce the friction of adoption because we’ve included them, we’ve communicated with them, we give them a heads up because that’s one of the things, is some efforts like this, if IT is here to enable a mission and if that mission can’t get done, guess what that goes up to the upper reaches of your organization and all of a sudden your Zero Trust effort in this example could go to the wayside because, hey, you’re impeding the mission kind of thing. Really bringing in the user community as well, I think is very important. So there’s a big, we have a marketing and education effort with our whole organization. Not just go do it in the IT shop and then put this new thing out and now all your users are going to be like, what is this kind of thing? So we’re trying to include their requirements, so we’re using it and leveraging it as a modernization effort at the same time.
Sanjog Aul [00:13:11]:
So, Dan, how much Zero Trust is good enough for us to say, okay, we made progress. You may not be at that utopic state yet. You’ve not reached the holy grail, but this is good enough so that we can stay on it. Otherwise people will say, this is like an endless thing, and it would actually start sucking in resources and your, the law of diminishing returns will start kicking in.
Dan Wilkins [00:13:42]:
Very true. So here’s the trap that everybody falls into here is you’ve got a forest fire that’s just blazing through. It’s burning down trees and everything, and everybody wants to just parachute into the fire and start putting the fire out. Well, if we don’t know the scope of what we’re trying to accomplish, if we don’t know how big the fire is, what direction the wind’s blowing, if we don’t know any of that, how are you going to attack this problem? You’re not going to be able to effectively fight this fire. You may have a localized being able to deal with something at a very local level, but you’re not seeing the big picture here. So I think what we need to do is really perform a business risk assessment across the organization, need to figure out where are our pain points. What exactly are we trying to solve here? What is the issue that we have in front of us, okay. Now, Zero Trust may not be the answer right now. It might be a future answer.
Dan Wilkins [00:14:29]:
It might be something that we’re building toward. It may not be something we need to implement right this minute, but we need to understand what exactly are we trying to accomplish first. So I like to liken this to, you’re running a race. So you start running a race and you’re like, okay, I’m feeling great. I’m running. This is great and you’re passing people and you’re passing by the refreshment stands and everything and you’re running and you keep going and then all of a sudden you’re like, I’m starting to get tired here.
Dan Wilkins [00:14:52]:
Where am I running to, okay, I haven’t really got there yet, haven’t got to the finish line, we’re expecting it. Where’s this thing at? So then we look at this and say, hey, buddy, I’m running here. Do you know where the finish line is and he’s, what finish line, what are we talking about here and you’re like the finish line to the race. Nobody knows what you’re talking about. So we need to get back to what exactly? What are we trying to solve here? What is the mission we’re trying to accomplish here and we need to identify that by clear goals and objectives. So establish exactly what we’re looking for, what are our parameters and try not to get that scope creep that happens on every project.
Dan Wilkins [00:15:22]:
We have every single project that comes along. This just add this one piece in, just add this one piece in, just add this one piece in and we never get there. We never have a defined scope and we’ll never get there. So that’s what I would say. We need to define what mission we’re trying to accomplish, what are the benefits for that, and how do we support and enable through technology to help hit those goals and objectives. That’s what I would say.
Sanjog Aul [00:15:45]:
So, Bharat, based on what Dan said, how much of that did you get a chance to paint as a picture so that people know where we are heading and when you try to get people to go in that direction, what pitfalls did you encounter?
Bharat Soni [00:16:04]:
What I would say that here, and I agree with the point that this is a journey, we cannot just say that we have achieved something and with the way what we are looking at, the dynamics of technology changing every day, new regulations are coming every day. I can tell you Zero Trust is an ongoing process. We cannot say that after five years also we will be able to complete this process. So there will be something new coming up. There will be something compliance from a compliance level, from a risk profiling from everything that will come up. So for me, Zero Trust will remain a continuous and ongoing journey for everyone, every organization and as rightly mentioned earlier that it’s a cultural change.
Bharat Soni [00:16:42]:
What we say that every place there is a risk which is to be assessed at the initial level itself. So when we talk about the risk that has to be adopted into the DNA or the culture of the organization. So maybe I would say when an employee, whether a new hire at a mid level or wherever in the organization the person is coming. When you look for the adoption of things, it has to be started from the initial process. Obviously there will be pitfalls you cannot convince. There is always saying that there’s no single bullet for everything.
Bharat Soni [00:17:13]:
So there is always what you call people who will be convinced. Management will always look it as a cost sometimes. Why we are doing this, why we are not doing this? So there is a business case. My thought process really is we need to start making it as a DNA change, not just profiling or awareness issue. It’s a DNA change into the organization. Then only we can get ahead onto this journey. If you don’t profile our organization, what are our risks? What is the details in which we are looking for? Maybe for the sake of discussion, Zero Trust cannot be implemented on everything. Again, management will come back and say that it’s a big budget we are talking about.
Bharat Soni [00:17:52]:
So let’s identify our risk around the assets and then we can talk about how much to spend, what will be my ROIs, how I’m going to do this thing, who are involved into this whole process. That’s a very strategic and risk based process and it has to be adopted from top to bottom and bottom to top. It’s a both way approach. You cannot say that only one person, one team or one single person from a management is responsible. Everyone is responsible. How we say that security is incomplete without you. The same thing goes on with this thing as well. That Zero Trust is Zero Trust
Bharat Soni [00:18:29]:
whatever we do, the name itself defines it as a Zero Trust. So it’s ongoing process. The new employee will be coming, existing employee will be assessed and that’s how it has to be done. Obviously we have to look for the strategic approach and business profile. That’s my thought. Thank you.
Dan Wilkins [00:18:45]:
And if I could add to what Bharat was saying, we need to pick one thing and do it really well instead of trying to pick 90 things and do them halfway or mediocre. The problem people run into is that they want to take on so many different things, they want to take on different elements and all just puts new thing in a new stack, a new tool, a new vendor, a new solution and now you’re doing your spread so thin that you can’t even focus on anything. So we need, if we’re truly going down the Zero Trust path, we need to pick one element of it and do it really well. Learn our lessons, figure out how it works and what we need to change and do moving forward. Then as we build our strategy out and take a look at things we see, we understand, okay, this didn’t work so well. We need to make some adjustments or this worked really well. Let’s keep going that path and take it from that standpoint.
Dan Wilkins [00:19:27]:
So do one thing, learn your lessons and then do the next thing well too.
Sanjog Aul [00:19:31]:
Let’s take a quick break listeners. We’ll be right back and Gerald, when we come back like to ask you that. Okay on one hand you said since OMB is telling you to push this and that’s why you have a mandate, but then we also need an ongoing support and for that you need to have a compelling business case. So yes, you’re from government, but there are a lot of people who would be listening to this would come from the private sector who will have to make a business case and I’m assuming you also need to but what is it that for this marathon, I don’t even call it a sprint because it’s a long term play. So how do you create a compelling business case for this marathon type initiative so that you have not just only the upfront but also the ongoing support and sponsorship.
Sanjog Aul [00:20:21]:
So please stay tuned listeners. We’ll be right back.
Sanjog Aul [00:21:22]:
Welcome back. So Gerald, we need sponsorship and support from our management all along because this is a long term journey as we all said it. What would you say would be the tenets of a business case which when made for Zero Trust will give you what the blessing, the money, the support, the influence that you need to make Zero Trust happen?
Gerald Caron [00:21:45]:
So that’s a great question. Definitely, I like to go back to one-o-one. What are we trying to do for our users? They have a mission to do. We want to make sure the confidentiality, integrity and availability is always there. Those are the triage of, for cybersecurity and if you’re doing those things right, your people are getting their mission done because they’re confident the system’s available
Gerald Caron [00:22:08]:
when they need it and the data that they’re relying on, it has the integrity that they can trust. So in doing that of course like I said there’s yet I’m working to get buy in for the whole organization that was, that has been my effort from the C suite to understand here’s the current state and doing investments in these areas will get us toward so that we can maintain the mission. Then people have the right data at the right time and we can rely on it. So one of the things that we did is we did some visual displays in our business case for our management. So so we had this capabilities model and we had all these functional capabilities and we did an inventory of as is for each of those functional capabilities and it was about probably 70 functional capabilities, cybersecurity capabilities and we put them in the pillars of Zero Trust that Department of Homeland Security has defined. We added a couple other pillars to split some things out and we showed them this is the state as we are now a lot of red, a lot of yellow on that red, meaning we have gaps. We got a lot of work to do in this area.
Gerald Caron [00:23:13]:
Others is yellow is we have some tweaking. The green, we had a bit of green. We’re doing good at these so we can adopt these and we can take credit for these but that was a very visually telling. It’s yeah, we have some work to do on the cybersecurity front if we want to do and Zero Trust is that way to do that because you also got to say everybody talks about the malicious actor. It’s not always the malicious actor. It’s just that person trying to get something done and get their mission done
Gerald Caron [00:23:38]:
but if they are able to circumvent your security that you put in place, guess what, bad guys can too. We put together that argument. We’ve also reached out and we’ve already educated and gave a one-o-one to our user base on Zero Trust and what we’re and I mentioned earlier, we’re making it a modernization effort as well because why we’re telling them hey, here’s some benefits that you’re also going to get as a result of us doing this. Like right today I VPN them back and relying on an on-premise network just to put them back out to the cloud and the internet. There’s technologies now that I can leverage for Zero Trust and still have the security telemetry, but I can send them more direct. Also single sign on authentication, doing things around identity, more seamless movement between platforms having the right data at the right time that has that integrity but in the turn, we’re also asking them, how do you want to work, not how do you work, but how do you want to work? So we can build those requirements in. What is the data you need? When do you need that data? How do you access that data? How do you want to access that data because with COVID and everything, people are working differently. They’re getting more and more comfortable and we want to be able to keep accommodating that type of work environment.
Gerald Caron [00:24:48]:
So building those things in makes it a lot easier to adopt because now it’s not so much being just a security effort, we’re actually modernizing the environment and bringing them benefits to possibly make their work better, a little easier and is it going to change? Yes but as long as it’s very transparent of what that change is going to be, the less friction you’re going to have. So it’s a huge marketing effort for us. The importance of it is understood. That graphic visual that we provided, of course, not being a capital investment coming in, a revenue coming in, we have these budget planning cycles, so we’re really done. This investment, what can I take advantage that I have first and foremost, if I didn’t spend another penny, what can I do with my investment today and I can show some wins, but I’m also able to show my gaps through that visual and say, and spread it out
Gerald Caron [00:25:40]:
and now I’m reprioritizing also. Here’s how I got to reprioritize and take some risk. There’s some risk you got to take to move something forward. We’ve put that business case together and get some understanding, some buy in. Our users are actually understanding having that communications early on rather than going and Frankenstein’s laboratory coming up with this IT thing and then trying to push it out at the last minute and then educating them after the fact, that wouldn’t go over too well probably including them and saying, hey, things are going to change, but you’re part of the team. So we’re making it a team effort. So I like to equate it to a football team or any kind of team.
Dan Wilkins [00:26:19]:
I do the work for our fans.
Gerald Caron [00:26:21]:
Our fans are our users and if I am doing good and putting a good product on the field, making my fans happy, they’re liking what they’re seeing, they are able to provide input into that, then it’s going to be a much easier road to hoe, I think.
Sanjog Aul [00:26:38]:
So, Dan, when you’re looking at the, this whole business case development which of course. Gerald, thanks so much. Good response there. We also have to explain the leaders along with building the business case that we will need their support and which means you have to actually wear the hat of a leader, which you anyways do in all areas but in this case it’ll be interesting because you have to lead up, lead sideways and lead down because this is so holistic. So what would you say what new leadership muscles or what new communication approaches which you saw tried and if they worked or they did not work, would love to get your inputs on that. Especially in context of the Zero Trust. What did you try besides the tactics you will do, the leadership that you use or the communication styles you used, which actually ended up working well for you or which ones did not work for that matter?
Dan Wilkins [00:27:33]:
Plenty of things don’t work well but I tell you what does work well, and Gerald touched on this already, is listening to what the business needs, okay. So listening to the users, listening to what is actually taking place in the environment because many times we’re trying to solve a problem that isn’t actually a problem, okay, so we jump in, we’re like, hey, we want to just rush to the fire. We wanted to throw the buckets of water on it and we want to get to work and like, hold on, that was a prescribed burn. We want that to burn. We want to get rid of the brush. We want to get rid of those problems in the environment.
Dan Wilkins [00:28:02]:
So you’re putting out the fire that we just started, okay, so we want to make sure that we’re solving the right problem and we’re not going to know how to do that until we start listening to what the business actually needs and what they want. A perfect example of this is, you let’s just imagine for a second that you own a building of some type, whether it’s a warehouse, office space, whatever. You own a building and as a business owner, you want to protect your investment. So you get some insurance and you get a few things and you’re like, okay, I’m in pretty good shape and then all of a sudden lightning strikes the building and burns the building down. You’re like, what the heck, I didn’t plan on that.
Dan Wilkins [00:28:36]:
I didn’t realize this was an issue. So you do some research and you’re like, oh, I’m in a lightning area. This is prone to happen. This is going to be an issue for us. So you go build your, rebuild your building. You put lighting protection up and you’re like, all right
Dan Wilkins [00:28:47]:
cool,
Dan Wilkins [00:28:48]:
I’m all set. Then a vehicle is driving down the road, jumps the curb, crashes into the building, and then burns the building down. You’re like, what the heck, I didn’t plan for that. I didn’t even know this was an issue. So you rebuild the building, get your insurance check, and you put out the vehicle, bow yards and everything to keep that from crashing into there and now all of a sudden, you see something that somebody doesn’t like, and arsonists burned your building down. You’re like, what? You can’t win here. The building keeps getting burned down.
Dan Wilkins [00:29:11]:
So now you think to yourself, maybe I spray fire protection on the building and keep the building from burning down that way. Every time that you have a solution, there’s another problem that surfaces, okay, we’re not looking at the big picture here. The big picture is the building is getting destroyed, okay. Now it doesn’t matter if it’s fire. It doesn’t matter if a satellite falls out of space and crashed into it. Earthquake, the sinkhole open, it doesn’t matter why the building is destroyed. The problem is the building got destroyed, okay, so we keep trying to solve the individual problems here.
Dan Wilkins [00:29:40]:
We keep trying to look at this from a business perspective of, oh, we need to implement Zero Trust. Why, ask the question why, why do we need to implement Zero Trust? We go back to the business and listen to the business. Now, this is important. We need to listen to what the business problem is, which people always want to bypass and just, I already know the answer. I don’t need your input. I don’t need to listen to you. I don’t need anything
Dan Wilkins [00:30:01]:
and there’s the mistake people fall into. We don’t actually get input. We don’t listen to our community. We don’t pull those groups of people together and what you need to do is have a representative from every area. So you need to have somebody from finance, somebody from HR, somebody from purchasing, somebody from IT. We need to have somebody that represents every part of the business to come together and say, okay, what problem do we have as an organization? What would be a showstopper for us? What would be an issue that we can’t solve and how does Zero Trust help us make sure that’s not a problem for us and that’s what I would say. I would say we need to make sure that we’re understanding why we’re even going down this path to begin with
Dan Wilkins [00:30:39]:
and now we can build that threat matrix. I gave you a few examples of lightning and arson and things like that put a weight factor on those, define those. How likely is this to occur? Is this a problem? Is this significant problem to invest dollars in and so once we have that matrix, the matrix will give us all the answers that we need. We’ll be able to look at that and say all right, we have a good use case for investment here. We can get people on board because we know what we need to protect and why we need to protect it.
Sanjog Aul [00:31:08]:
When Bharat, you look at the the situation that we deal with here. Dan gave an interesting way of looking at things and good analogies by the way Dan, about the fire and why the fire is all that said, I’m sure as part of your communication and leadership buy in, et cetera, Bharat, you might have done it, but then you have to listen and I’m assuming you might have listened to a whole lot of people and then you would have tried to put together a strategy on how you would even define and carry forward this whole Zero Trust implementation. What would you say would be the tenets of that strategy which when are put in place and as part of you even building your strategy, what safeguards did you put in so that you do not direct this effort into a different direction than what it should be? How do you accurately position Zero Trust to become successful versus throwing a dice?
Bharat Soni [00:32:06]:
Okay, so Sanjog, I will go back to my last point about changing to the DNA and doing a risk profile of the organization. I’ll start with that and I have two different versions. Being into financial industry I will say that Zero Trust is something we cannot just look for internal staff access only. It can be also look from a third party user access and all those things. It’s a overall accessibility from every single point of interaction with my infrastructure. So these are the different point of views. So when you say that yes I have also faced the same kind of challenges and let me give you an example and it’s something you know when we started the implementation of two factor authentication before that everyone thinks that username password seems so easy. I have to just remember my 8 character maximum and I have to just remember my 3 password history back.
Bharat Soni [00:33:00]:
I don’t need to change my password maybe in 15 days or 30 days with the change in dynamics and implementation of two factor authentication. For the sake of discussion you have to first convince the top that yes, this is what the reason why you are implementing it because when you push things if the top management is not convinced, that’s a fail implementation approach. So we have to start seriously communicating with Them awareness campaign. Maybe on the organizational intranet. We have to also see how we’re communicating with all the users. Adoption of any strategy starts with simply communicating from every level. Communication is the key. If we have the right communication
Bharat Soni [00:33:42]:
because at the end we are the one who are doing the risk profiling. We are the one who are engaging technology, we are the one who are engaging other business holders but communication, if it’s not happening and we are not doing a right and proper communication, it will always fall down on first step itself. We know that the digital space is changing every day. So the problem is how to convince and create it as a journey. First thing first is you have to first ensure that yes, they understand that Zero Trust is important. For example, what I’m going to, what I started doing in the initial phases, just ensure that they are aware. Fine.
Bharat Soni [00:34:18]:
There is an awareness, but awareness has to be supplemented by certain examples. Now there was, I will not name the organization but within the country, there was a, I will say financial fraud happened in one of the organization in Nigeria where they used the normal spear phishing attack. The user unknowingly compromised the passwords and then there was something been happening over the weekend and then on top of it there was an attempt and it got successful. So when you communicate with your members, you have to also mention that look, this was the reason for this because business will not understand your technicalities. We have to simply play the, what you call this like the financial numbers over there
Bharat Soni [00:35:08]:
and what is the loss. If you implement this, these are my risk. My risk is the probability of my risk and if you implement the controls in place, what are, what is the probability of the risk to be materialized? Then the digital transformation happens. So we cannot just say that the risk is something, it’s a process, it should be what in an agile manner because the risk profiling changes as you change the organizational or the business needs are been changing. Now being into financial industry, when I mentioned that it’s not only for my internal staff, third parties, let me say third parties plus even my customers because somehow if I’m not ensuring that the customer devices are being locked down properly, there is a possibility that from the customer’s perspective something will happen and which will impact onto my infrastructure. So we have to look this approach as a holistic approach from the organization.
Bharat Soni [00:36:01]:
Every single point of interaction, whether internal, external, third parties, customer, even customer inclusive has to be properly adopted into the strategy given awareness. Give a communication channel to the management, hear from them that these are the challenges. Maybe business will come with their own because business will say that no, this cannot be done but how we are going to have a win win situation for both. We cannot just sit and relax. Business has said they’ve accepted the risk, but ultimately the risk will harm the whole infrastructure. The buying has to become from the top, maybe sometimes from the board in mid range organization and to show the ROIs, it’s very critical.
Bharat Soni [00:36:43]:
We have to always have, maybe even the regulations can help when we’re talking about the business case. Dan and Gerald can also help me out. For example, in US the government has mandated Zero Trust for federal governments. Now this federal government Zero Trust implementation can be made for companies that interact with government. So it’s a ripple effect. If the company wants to do a business with the government, they need to implement Zero Trust over there and ultimately their environment will get secured and hence wherever they’re interacting, that environment is also secured. So these kind of business cases from a regulatory perspective, from a business perspective have to be considered and then only the binds has to be taken out and obviously we have to continuously communicate and make management aware about it. That’s my thought.
Sanjog Aul [00:37:30]:
Let’s take a quick break listeners. We’ll be right back and general, when we come back, let’s talk about the actual implementation. There are so many different areas to cover as we see this is like a big elephant when we are trying to implement down to the brass tacks where we find the most challenges and which elements are most daunting to implement. Let’s learn more when we come back. Please stay tuned.
Sanjog Aul [00:38:57]:
Welcome back. Gerald, what in your experience when you started this journey and you started implementing and wherever you are currently, what have you found to be giving you sleepless nights?
Gerald Caron [00:39:13]:
Education. There’s been a lot of education. People are used to doing things a certain way, specifically the IT staff and so I actually introduced them to Zero Trust. So there’s been an education and then I brought in certain vendors to give them an idea of what is possible and things like that and then the light bulbs started going off and this actually helps with a lot of things if we were to do this kind of product, not necessarily that product, but hey, it started getting some traction and some understanding and people started diving in and really understanding it and actually getting excited because some of the technologies that we’re now talking about are definitely going to ease some pains that we’ve been having with some of the legacy things.
Gerald Caron [00:39:58]:
The other thing is, we understood the as is after we started understanding what the target state is, doing the as is, doing the inventory that I talked out, talked about before. I identified. If we did these five foundational projects, these are our stepping stones to the next thing. Planned those five foundational projects while we finished the rest of the roadmap, understanding what our gaps were, what projects we would need to fill those gaps and to reach that target state that we wanted from our as is but we also kicked off these five foundational projects. Now, one of those, as I mentioned before, is data mapping. Just understand that’s not network mapping. This is understanding where our data is, where it’s going, because that’s what we’re trying to protect, make sure the right people have the right access to the data.
Gerald Caron [00:40:44]:
Understanding that we have some legacy applications within our organ in our environment as well. So there’s some prerequisite things that we need to do, the things that we absolutely need to do to modernize towards Zero Trust too. There’s the concept of the way I’ve done this is the way I’ve been doing it and getting over that hump and understanding that from the technological aspect and understanding what the value it brings to your own IT staff and solve those problems that they’ve been historically doing and then getting identifying I think those five foundational projects and getting that understanding of if we do these five things, here’s what that allows us to take the next step to do. One of those is integrating a lot of the tools that we have today and making relationships and understanding that data and that telemetry that we have, because that’s ultimately going to end up feeding all the factors that I have to take into account to develop that confidence or that what I call risk score to make decisions off of do I allow you in or not? Do I allow you in but read only you can’t manipulate, as you would in this, other factors and so building those thresholds. So what data do I have available that I can start relating so starting that integration of that data so we can make decisions and start making our policies and understanding what our risk thresholds that we want to build. So those are examples of a couple of the things that we’re doing and now a lot of planning’s gone on this past year.
Gerald Caron [00:42:13]:
Probably not a lot of things that you’ve, people are seeing absolutely done but all that planning now things are starting to come to fruition and we’re getting to that starting line and starting to, ready to run, to use Dan’s analogy but we have a target state. So we’re understanding we have and we know where the finish line is. Some of these things. It’s going to be a long race.
Gerald Caron [00:42:33]:
It’s longer than a marathon. It’s more like the ironman thing and because there’s more than just running, we’re going to be swimming, we’re going to be biking, we’re going to be climbing. We’re going to be doing a lot of things on this journey but we understanding what that target state was, understanding the reasons why we want to get to that target state and now that education has sunk in and actually my staff’s pretty excited about some of the things that we’re able to embark on now and actually ease a lot of the pains that we were having and getting rid of that whack a mole kind of concept.
Gerald Caron [00:43:09]:
All right, whack that mole. All right,
Gerald Caron [00:43:11]:
what
Gerald Caron [00:43:11]:
another one popped up and or the little boy with a dike put finger in the dam, oh, there’s another leak. Let’s concentrate. What are we ultimately trying to protect at the end of the day. Where are our crown jewels? Make sure that our tight protections are tight around those crown jewels and that understanding is really helping getting things off on the right start and proper planning, proper road mapping so we can have a good idea of where Dan’s finish line is. Sorry, it’s your analogy, Dan.
Dan Wilkins [00:43:40]:
I’ll talk in. We hope we know where it is.
Sanjog Aul [00:43:44]:
Yes, absolutely. So now with that said so Dan, while we would talk about the different areas of elements but then we got so many things that the security team has to do and I’m sure they have a day job. I’m not saying this is not part of their day job, but to some extent it looks like superfluous and it might be spilling their plate. How do you not have this, I will not say nice to have it is a very good strategic initiative but how do you prevent this from cannibalizing into the other important down to the brass tax execution stuff that your team needs to do and while maintaining their spirits that, hey, you can’t just drop the ball on this either.
Dan Wilkins [00:44:25]:
No and this is another pitfall that organizations fall into all the time. This is one of those things that, speaking of that finish line, this in this case we needed to run the race backwards, okay. We need to start at the finish line and start running the other direction and go back toward the goa and when we’re heading that direction, we’ll need to see where do we need milestones and checkpoints along the way, where do we need that refreshment station? Where do we need those things? That way when we run the race the correct direction toward the finish line, we know what those objectives are. So speaking of the staff involvement and how we’re loading them up with things, here’s the pitfall that organizations run into. They keep wanting to throw additional things over the wall and just take on one more thing, take on another thing, take on another project and the thought process doesn’t go into where, at what point is the headcount increase to accommodate this.
Dan Wilkins [00:45:17]:
Okay, so where do we look at this and say this is going to take an extra X amount of time, whatever that time is, 10 hours, 20 hours, 50 hours, whatever and being able to put that milestone in there and say we need a breakpoint in here to say we can’t handle this effort, we can’t handle this additional item here with the staff that we have, we need to bring on additional people and you’re not going to be able to do that until you have those objectives defined. If you know what that finish line looks like and how you’re going to get there when you need to get there, okay, is this a six month race? Is this a five year race? Is this a multi phased effort? How do we look at this? Those milestones along the way are going to help us guide and direct that. So that way we’ll be able to pre plan and say, all right, six months from now I’m going to need one more FTE or two more FTEs or three more or whatever that is and we can’t just offload this work. This work has to be done by somebody.
Dan Wilkins [00:46:09]:
The work doesn’t just disappear because we don’t have somebody to do it. The work is still there and so now it’s no surprise we burnout. This should not be shocking to anybody. If we keep throwing additional things on the stack, at some point the stack’s going to break. We can’t handle it all and we won’t be able to do it. So the organizations need to look at this and say, we have more things coming. We need more people to do those things.
Dan Wilkins [00:46:31]:
We need to adjust accordingly in order to accomplish this and that’s where I think we fall down. I think we, we don’t look at this from a perspective of, I want to get to the yes, I want to get to that answer of yes, I want to be supportive of the business. I want to do everything we can do to help the business but I’m not doing anything to actually meet that objective. By increasing staff or outsourcing something if I need to, or bringing in contract resources or staff augmentation or whatever, that work has to be distributed and if we’re not distributing the work, we’re going to run into a problem where we’re probably already there. You say employee burnout.
Dan Wilkins [00:47:06]:
This is why right here, we’re not giving them the resources to do their job effectively and we’re creating our own problems. So we need to look at this from a perspective of we have the goals, we have the milestones, we know what we need to accomplish and if this is important to the organization, if it’s important to management, then it’s important enough to give us headcount to accomplish it. So that’s what I would say.
Sanjog Aul [00:47:27]:
So, Bharat, when you’re looking at the overall, the implementation, the strategy and things that you’ve tried to do, and while Dan explained about what are some of the ways we can have the security team not get overwhelmed with it. We want to make sure that the end goal is not just the people, the process, but also the tools and trust me, I’ve seen it. I’m sure you guys see more than me the number of tools people are pitching as panacea tools. You fill it, shut it and forget it. Can you just throw some light on what you’ve seen and please don’t name any solution providers. We just want to know what is the reality when it comes to the efficacy effectiveness of the tools, which in contrast to the claims that are being made about those tools.
Bharat Soni [00:48:17]:
Okay, so I will start first with engaging all the stakeholders. That’s the very key communication and engaging all stakeholders is a very key in implementation of the Zero Trust. So the awareness has to be key factor and the communication has to be done very well and when you talk about the information security tool, yes, we have to have many tools which are artificially intelligent, enabled, maybe for example, user behavioral analytics, which will ease the job. We are not overwhelming the team. We are not even telling them that they’ll cut down or cut down the staff strength because we are going for automation.
Bharat Soni [00:48:54]:
So it’s a balance we have to manage between the expectation of the management and the expectation of the team. So something has been expected at the board level and then how to achieve that particular goal is where the operational team has to be engaged properly. We can have small milestones and we can have a big leap towards a longer milestone. So that will keep engaged the team. That okay, first thing first. Maybe this is the target we need to achieve in 15 days. Once we achieve it, the team is going to monitor it
Bharat Soni [00:49:26]:
and yes, they will be happy and this is what I have seen in practicality. They will see themselves as successful and enrolled into the process. The next step can be take a bigger leap. Maybe implementation project will take a bigger giant kind of process and technology to be implemented. Then maybe they will be aggressive. Second thing after that should come that appraise them. Obviously you have to take into consideration all their efforts and then again take a smaller one so that they will not be overlapped.
Bharat Soni [00:49:55]:
The approach can be different based on the organization, based on the environment but we have to do automation. We have to engage everyone. We have to also communicate properly. So without naming the tools, there are tools which have failed when it comes to, for example, if something happens into the environment, all of sudden the environmental problem becomes every organization problem within that environment. For example, something happens into one of the bank, maybe in Africa, maybe in the world. All of a sudden you will see that one vendor or two vendors are pushing for the products against it.
Bharat Soni [00:50:30]:
That time is a heated time for everyone. You will be under, you means the information security team, will be pressure from the management. What we are doing this happened over there. What is our challenges to implement certain things. What are the steps we are taking to ensure that this risk does not materialize into our environment under due process of pressure and looking for a tool. That information team may sometimes look for a tool which is just like coming to them as a first come first services kind of thing. Let me first initiate or implement this tool and then I will look for the features. Now thorough assessment will be carried out because everyone is under pressure that when we will look that if implementation of this tool will take us from 0 to even 50 at least we are reducing 50% risk over here.
Bharat Soni [00:51:21]:
So those kind of things definitely will be impacting the Zero Trust and also it impact when the tool is not fulfilling the desired output or maybe there are certain challenges which are not been achieved by that specific tool. Then comes where the CISOs or the information security team handle it badly or give given a backlash from the management because they said that you are not done your job properly. So those kind of pitfalls has to be considered always. There is no one silver bullet to achieve all these things. Some small journeys, longer leaps, consideration of all stakeholders views and thought processes and considering that one solution cannot suffice for everything and obviously at the end of the day everyone is a human.
Bharat Soni [00:52:11]:
We take decisions based on what is presented to us and what is our experience. Sometimes we cannot expect, okay, we cannot expect that everyone is 100% right. So we have to start accepting the mistakes and move on from there as well. So that’s what, I will say that, I’m not naming any tool over here is rightly mentioned because it will again be a problem for me but there are pitfalls. We cannot say that everything has been as good as being shown and presented into the marketing decks. So that’s different.
Bharat Soni [00:52:40]:
What we always say that software demo is always different than the actual implementation. So that’s how the analogy will work into Zero Trust implementation as well because multiple things come together, it’s not one single approach. That’s my thought.
Sanjog Aul [00:52:54]:
Once again, thank you so much Gerald, Dan and Bharat for sharing your insights about the Zero Trust adoption, starting from building the business case to strategy to implementation and overall governance. Thanks so much again.
Bharat Soni [00:53:08]:
Thank you so much.
Dan Wilkins [00:53:09]:
My pleasure.
Bharat Soni [00:53:09]:
Thank you. Have a nice time. Thank you.
Sanjog Aul [00:53:13]:
And listeners, please like us on social media, subscribe to our podcast. Once again, thank you for listening to CTN. This is your host Sanjog Aul signing off. Till next week, take care and god bless.
Download Podcast
Apple Podcast, Google Podcast, Spotify, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
-
- Defense-in-Depth or Zero Trust or SASE, What Does It All Mean Anyway?
- The People side of Cyber Security – Turning organizations’ weakest link into their greatest strength
- Embedding Security in Technology Capabilities
- Security and Agility – Tips for Getting the Best of Both Worlds
- Transforming Security Programs to Become Digital Business Enablers
- Steps to Outcome-Driven Security
- Why Cybersecurity is important for Business Growth
- Managing IoT Security
- Data Security for the Digital Business
- Improving Cyber Security Awareness and Behavior


