Site navigation

A Long Road to Zero Trust as Engineers Bypass Security Measures

Elizabeth Greenberg

,

zero trust security
Zero trust strategies are in jeopardy as engineers and organisations often take the path of least resistance when it comes to security controls. 

IT and security leaders are bypassing basic security measures as hopes for a zero trust strategy fails.

A survey of 1,000 IT, security, and engineering leaders from Tailscale investigated where organisations stand in their security posture and zero trust adoption, finding that many organisations are falling flat.

Eighty-three per cent of respondents said that they bypassed security measures just to accomplish tasks, whether it was sharing credentials (23%), using unapproved software (28%), or using their own personal device (32%).

It’s also human factors that often cause vital security upgrades to be delayed. About two in five (42%) of those surveyed said that upgrades were delayed due to the risk of disruptions to workflows or integrations.

A further 39% pointed to leadership or organisations priorities, while a third said the upgrades had an unclear business case or return on investment value. About three in ten also noted that upgrades often lacked clear direction or suitable solutions.

It appears that many are unsatisfied with their company’s security flow, with 99% wanting to redesign their organisation’s network setup from scratch.

About half (49%) complained that their organisation’s infrastructure could not be scaled, with two thirds saying that their workflows were actively blocked or misunderstood by IT and security policies.


Recommended reading


Further, humans seem to be at every step of an organisation’s process, opening them to future risk. About seven in ten (68%) of organisations rely on manual processes for network access, ranging from static firewalls and IP-based permissions. About 90% also reported issues with their current VPN.

Further, the majority of those surveyed (68%) also had access to systems of jobs they had left, leaving even more room for risk.

While zero trust was an aspiration for most organisations, less than a third (29%) primarily use an identity-based access model.

The report offers startling revelations into the long journey ahead to achieving zero trust, hampered by human risk.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data