Site navigation

Implementing a Zero-Trust Strategy: Where to Begin

Elizabeth Greenberg

,

zero-trust strategy
“For most organizations, a zero-trust strategy typically addresses half or less of an organization’s environment and mitigates one-quarter or less of overall enterprise risk,” said John Watts, VP analyst, KI leader at Gartner.

Sixty-three percent of organisations worldwide have fully or partially implemented a zero-trust strategy, according to Gartner, Inc. For 78% of organisations implementing a zero-trust strategy, this investment represents less than 25% of the overall cybersecurity budget.

A survey of 303 security leaders by Gartner found that, while zero-trust is cited as an industry best practice, leaders are still not quite sure what best practices for achieving zero-trust are.

56% of security leaders are primarily pursuing a zero-trust strategy because it’s purported importance, but this does not equate to an understanding of just how secure zero-trust strategies really are.

“Despite this belief, enterprises are not sure what top practices are for zero-trust implementations,” said Watts. “For most organisations, a zero-trust strategy typically addresses half or less of an organisation’s environment and mitigates one-quarter or less of overall enterprise risk.”

To increase understanding, Gartner has released some top practice recommendations of implementing a zero-trust strategy.

1. Establish Scope Early 

For successful zero-trust implementation, organisations need to understand how much of the environment they cover, which domains are in scope, and how much risk they can mitigate.

The scope of a zero-trust strategy does not typically include all of an organisation’s environment. However, 16% of survey respondents said it will cover 75% or more while only 11% believe it will cover less than 10% of the organisation’s environment.

“Scope is the most critical decision for a zero-trust strategy,” said Watts. “Enterprise risk is much broader than the scope of zero-trust controls, and only so much enterprise risk can be mitigated. However, measuring risk reduction and improving security posture is a key indicator of success for zero-trust controls.”

2. Communicate Success Through Zero-Trust Strategic Operational Metrics

79% of organisations that have fully or partially implemented zero-trust, have strategic metrics to measure progress, and of that 79%, 89% have metrics to measure risk.

Security leaders must also keep their audience in mind when communicating these metrics. Fifty-nine percent of zero-trust initiatives are sponsored by either the CIO or the CEO, president, or board of directors.

“Zero-trust metrics must be tailored for the zero-trust deliverables as opposed to rehashing metrics used for other areas, such as the effectiveness of endpoint detection and response,” said Watts. “Zero-trust efforts deliver on specific outcomes – such as reduction of malware’s lateral movement on a network – often not captured by existing cybersecurity metrics.”


Recommended reading


3. Anticipate Increase in Staffing and Costs, but Not Delays 

62% of organisations anticipate their cost will increase and 41% of organisations expect their staffing requirements will also increase as a result of a zero-trust implementation.

“The budget impacts of organisations who adopt a zero-trust strategy will vary based on the scope of the deployment as well as how robust the zero-trust strategy is early in the planning process,” said Watts. “Zero-trust initiatives inherently affect the budget as organisations take a systemic and iterative approach to mature their policies toward risk-based and adaptive controls, adding overhead to the organisation’s ongoing operational burden.”

While only 35% of organisations said they encountered a failure that disrupted their zero-trust strategy implementation, organisations should have a zero-trust strategic plan outlining operational metrics and measure the effectiveness of zero-trust policies in order to minimise delays.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data