As the host city for the largest summit the UK has ever held, COP26, the increased focus on Glasgow put government organisations, local businesses, and the city’s infrastructure at risk. At the time, they are said to have ramped up security measures ahead of the conference over fears that hackers may target their computer systems.
This sense of heightened alert is compounded by a 95% rise in cybercrime in Scotland in the last year, according to the ONS. From the impact of remote and ultimately hybrid working, through to some of the more prolific and disruptive attacks, almost every industry in Scotland has been affected – spanning the public sector through to supply chains, manufacturers, and healthcare.
Two prime examples of this are the high profile and successive attacks on Scotland’s Environment Protection Agency (Sepa) in which more than 4,000 files were stolen and Glasgow-based engineer company Weir, which was hit by a hack of its IT systems costing it millions of pounds.
This constant and underlying threat from hackers is causing a clear shift in the way Scottish organisations view trust within their networks. This in large part is due to their workforces suddenly spreading out geographically due to working from home.
Increasingly, many see their remote access technology as an essential part of their internal cybersecurity review process and find that zero trust or a least privilege view is more suitable in a hybrid working world. The concept of zero trust is becoming the norm.
Scottish organisations have adapted as applications and data continue to move off-premises while still keeping on-premises applications. In fact, they are leaning on more hybrid and multi-cloud environments to provide them with their ongoing digital transformation needs. This trend echoes the findings in a recent Fortinet report that says 76% of respondents use at least two cloud providers.
More control and a steady security approach adopted by all users across geographies and time zones – off or on-networks – or accessing on or off-premises applications, is key. So how do organisations keep users who shouldn’t have access to a network out? Critically, this is where the zero trust strategy comes into play.
No one can be trusted
Zero trust works on the basis that all organisations – big or small, private or public – face constant external and internal threats. Zero trust also views every attempt to access a network or an application as a threat.
No one inside or outside the network should be trusted until their identity has been systematically scrutinised. Fortinet-coined term Zero Trust Access (ZTA) is a significant first step towards implementing a zero trust security architecture. Establishing ZTA involves pervasive application access controls, powerful network access control technologies and strong authentication capabilities.
One aspect of ZTA that focuses on controlling access to applications is Zero Trust Network Access (ZTNA). ZTNA builds on the principles of ZTA to authenticate users and devices before every application session to confirm that they adhere to the organisation’s policy to access that application. ZTNA supports multi-factor authentication to uphold the highest degree of verification.
Adopting the zero trust model for application access or ZTNA makes it possible for organisations to rely less on traditional virtual private network (VPN) to secure assets being accessed remotely. A VPN often provides unrestricted access to the network, which can allow compromised users or malware to move laterally across the network making data vulnerable to exploitation.
Recommended
- Airlines warn of “catastrophic” crisis with new 5G service
- Is automation key for growth in banking and payments sectors?
- Open Rights Group criticises Home Office “scaremongering” on encryption
This is why it is crucial that a shift to a zero trust strategy is necessary. A consistent policy applies this democratically, whether users are on or off the network, which is a benefit of ZTNA. This effectively means an organisation has the same defences, no matter where a user is connecting from.
A ZTA mindset
Adjusting to a ZTA mindset takes some getting used to for an organisation as it will likely feel daunting. There’s a common misconception that rolling out a zero trust architecture requires a complete overhaul of a business’ network. There will certainly be some uphill battles in the initial stage, but successful implementation is about having the right framework in place paired with the right tools to execute.
Every environment would benefit from a consistent zero trust approach. It’s a cultural shift, which surprisingly is often a bigger switch to make than the technological one. It involves a commitment to changing how access is granted and how security is maintained across the organisation.
ZTA is an revolutionary step, not a blanket replacement of existing identity and access management. It’s something that’s accessible to everyone, small businesses through to larger enterprises. And is crucial to helping Scottish organisations secure themselves against an aggressive and changing threat landscape.
Given the interconnectedness of the global networks that are exploited by cybercriminals, no single territory is safe, and so zero trust strategies have a vital role to play within Scottish business right here and right now.





