Every Solution You Can Imagine – and More
What cybersecurity solution do you need? From Zero Trust to ADR, IAM, risk/privacy, data protection, AppSec and threat, securing digital transformation, to resiliency and remediation, we can build the right program to help solve your challenges.
A Single Partner for Everything You Need
Optiv works with more than 450 world-class security technology partners. By putting you at the center of our unmatched ecosystem of people, products, partners and programs, we accelerate business progress like no other company can.
We Are Optiv
Greatness is every team working toward a common goal. Winning in spite of cyber threats and overcoming challenges in spite of them. It’s building for a future that only you can create or simply coming home in time for dinner.
However you define greatness, Optiv is in your corner. We manage cyber risk so you can secure your full potential.
Why the Evolution of Zero Trust Must Begin with Data Protection
October 14, 2021
The need for “Zero Trust” today isn’t the same as it was years ago when the term was first coined. Back then, businesses only had a handful of remote workers signing in to the corporate network. You couldn’t implicitly trust the authentication of those remote users because they weren’t on the company LAN and the common solution was installing two-factor authentication.
Things have changed. The actual definition of Zero Trust today is much broader than the idea of going from “zero” to “full trust.” It’s more than just not trusting authentication because the user isn’t on your network. You also can’t trust the devices they’re running. You can’t trust the applications they’re using. And you can’t trust the network they’re traversing.
There are many more potential trust risks today, too. There are also many more real threats – the FBI saw a 400% increase in cyberattacks seeking to exploit new opportunities in the first few months of the pandemic. At the same time, there’s also a much higher demand for official business being done outside the organization. In 2021, the percentage of remote employees is expected to double, and nearly three-fourths (74%) of companies plan to permanently shift at least some employees to work from home (WFH) after the pandemic ends.
Despite the implicit “zero,” Zero Trust can’t be an all-or-nothing proposition. If the business can’t authenticate the user, then that user can’t be given access to company resources. If the majority of the workforce is working from home, using their own devices, applications and home networks, literal enforcement of Zero Trust would effectively translate to “zero work gets done.” This is why any useful evolution of Zero Trust principles must include data protection.
Organizations are moving ever-increasing amounts of data out into the cloud and software as-a-service (SaaS) has dramatically boosted the volume and changed the nature of network traffic. Previously, the majority of internet traffic was accessing static information sites, but now more than half of internet traffic related to SaaS and cloud apps contains business-critical data. This shift in network traffic has resulted in a network reversal – diverting traffic away from on-premises security appliances in the data center and directly to the cloud.
Unless you have forced hairpinning of all the network traffic from managed devices through your data center, users will go directly to the cloud-based applications – leaving organizations completely blind to the transaction (without a monitoring proxy).
Lack of visibility is a very real problem. While cloud-based applications serve pressing business needs, security teams can’t manage the risk of something they can’t clearly see. Further complicating the issue, most users access applications on more than one device (personal laptop, tablets, phones, etc.).
The attack surface has broadened because of the rising volume of data that now resides outside of data centers (in the cloud) and the vast number of users working remotely. This not only increases opportunities for cyberattacks, but it also complicates data security and regulatory risks. Understanding data flows, as required under many privacy regulations, requires constant discovery of cloud services and the ability to “geofence” data so it doesn’t cross international borders. A strong data protection program is required to inspect the traffic, determine if it’s regulated data and then enforce restrictions to remain compliant.
So, how do you ensure proper data protection in this kind of world with Zero Trust?
A modern security model should center around data rather than legacy approaches designed around protecting an on-premises site. Putting data at the center of your security model means moving controls out of the data center and instead placing them around data and users. And that’s really the essence of building a secure access service edge (SASE) architecture.
Properly designed, SASE provides a framework to completely rethink your network security and cloud data protection. It converges network and security functions into a single entity. Both network and security shift to the cloud as services, away from the data center, and closest to the point of data access. The “perimeter” – if we can even call it that – then becomes a dynamic, policy-based edge that can be provisioned when and where you need it.
The big change here is that it’s not just protecting assets in the cloud using security as-a-service. It’s really a narrowing down of the platform as well – simplifying the stack. SASE means you’re bringing together security as-a-service and network as-a-service and running them across carrier-grade network systems.
A software-based next-generation secure web gateway (NGSWG) is really the heart of a SASE architecture, the focus around which you can add on different network and security services. Next-gen SWGs bring together data leakage prevention (DLP), web security and a cloud access security broker (CASB) into one platform. Once integrated, NGSWGs can monitor and protect the data flowing to and from all critical business systems.
It’s here where we can start to approach data protection for a Zero Trust world. You have devices, users and networks that you don’t trust. But you need to connect them to your private applications, as well as your SaaS, web and infrastructure as-a-service workloads. A SASE architecture that enables visibility and analytics, as well as automation and orchestration capabilities, allows users to work from anywhere while still getting access to everything they need – without putting the organization at undue risk.
September 16, 2021
This guide provides an intro and dives into Optiv's Zero Trust principles and how to visualize your Zero Trust journey.
September 15, 2021
This guide offers advice on how to prepare, plan, design, implement, operate and optimize your custom SASE plan.
Let us know what you need, and we will have an Optiv professional contact you shortly.