Why Zero Trust must be an essential part of cybersecurity strategy

Issue 5 2023 Access Control & Identity Management

In the early days of computing, security was relatively simple since computers were isolated entities. Physical security was sufficient, with authorised users being granted access to a computer room. However, with the advent of computer networking and the internet, security became more complex. The concept of a physical perimeter protecting the network emerged, one could say this can be likened to a castle surrounded by a moat. Authorised users could cross this perimeter and move freely within the network.

Today, the world is even more connected and complex. Cyberattacks have evolved, becoming increasingly creative, dynamic and mostly unpredictable – albeit great advances in prevention and detection technologies have taken place. Cyber criminals have access to advanced technologies and operate at an unprecedented scale, rendering traditional defences insufficient. To counter these threats, organisations must deploy machine-driven defences to match the capabilities of the attackers.


Paul Meyer.

Digital transformation has brought about significant changes in the way businesses operate; data flows constantly, and employees work remotely using multiple devices. Today's cybersecurity challenges are further exacerbated by the growing attack surface. Employees use their personal devices for work, further endorsing the need for new security measures. Additionally, the rise of cloud computing has made enterprise infrastructure more distributed and harder to protect using traditional perimeter strategies.

Unfortunately, this increased connectivity also means an expanded threat landscape. Major data breaches have become commonplace, affecting various industries and causing significant financial losses. One report notes that on average, 150 000 records were compromised per breach to date in 2023, while 2022 saw an average of 75 000 records compromised per breach, meaning that each breach has had a greater impact on organisations and individuals.

Thinking that dates to the Middle Ages doesn’t work

The classic castle-and-moat approach to security, where internal users are trusted and external threats are presumed, is no longer viable. Threat actors can dwell inside a network for extended periods, remaining undetected. Moreover, human error and insider threats pose additional risks. The need for a new security paradigm has never been more apparent.

The Zero Trust model emerges as the solution to these evolving threats. It entails questioning trust assumptions and implementing strict access controls across all network elements. No user or device is inherently trusted, and verification occurs continually.

This approach ensures that potential threats are detected and mitigated promptly, even within the network, and it provides enhanced security for devices both inside and outside the traditional perimeter. Yesterday's strategies are no match for today's threats, necessitating a complete reboot of cybersecurity practices. As cybersecurity risks continue to grow and attackers become more sophisticated, organisations must adopt a proactive and adaptable Zero Trust security strategy to safeguard their data, systems, and overall digital infrastructure.

However, every silver lining has a cloud attached to it.

Navigating the roadblocks

As the threat landscape evolves, enterprises are increasingly recognising the need for a Zero Trust approach to bolster their cybersecurity defences. However, making the transition to a Zero Trust model is far from a walk in the park for most organisations.

One of the primary hurdles to overcome is dealing with legacy systems and technical debt, which can impede progress and leave critical vulnerabilities exposed.

Legacy applications, networks, and protocols that once served enterprises well are now proving to be a hindrance in the face of modern cybersecurity challenges. These systems were not designed with the agility and robust security measures required in today's digital age. Reworking these aging infrastructures demands significant efforts, resources, and financial investments, exacerbating what is commonly referred to as ‘technical debt’. Essentially, the older the systems, the more burdensome it becomes to implement necessary changes.

An inherent limitation of legacy enterprise applications lies in their lack of a ‘least privilege’ concept. Many of these applications rely on outdated authentication models, such as single sign-on, which falls short of the rigorous standards set by the Zero Trust approach. Integrating them with other critical technologies, like Identity and Access Management (IAM) or endpoint security, can prove to be an arduous task.

Unfortunately, legacies are not the end of the issue but rather the tip of the iceberg. In my second article in this series, I will expand further on the barriers to Zero Trust implementation which are far outweighed by the benefits.

Paul Meyer is a Security Solutions Executive at iOCO Tech. He has over two decades of experience in IT Security technology covering application, identity, perimeter and endpoint security. He commenced his career as a Security Engineer Team Lead and has held senior positions with multiple security vendors and ICT service providers in South Africa.

In May 2022, Paul was appointed to the role of Security Solutions Executive at iOCO, where he is responsible for identifying, learning and bringing security solutions to market. The role is strongly focused on technically supporting the sales process and managing vendor relations.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
Protecting citizens’ identities: a shared responsibility
Access Control & Identity Management
A blind spot in identity authentication today is still physical identity documents. Identity cards, passports, and driver’s licences, biometric or not, are broken, forged, or misused, fueling global trafficking networks and undermining public trust in institutions.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
From surveillance to insight across Africa
neaMetrics TRASSIR - neaMetrics Distribution Access Control & Identity Management Surveillance Products & Solutions
TRASSIR is a global developer of intelligent video management and analytics solutions, delivering AI-driven platforms that enable organisations to monitor, analyse, and respond to events across complex physical environments.

Read more...
Securing your access hardware and software
SMART Security Solutions Technews Publishing RBH Access Technologies Access Control & Identity Management Information Security
Securing access control technology is critical for physical and digital security. Every interaction between readers, controllers, and host systems creates a potential attack point for those with nefarious intent.

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...
Access data for business efficiency
Continuum Identity Editor's Choice Access Control & Identity Management AI & Data Analytics Facilities & Building Management
In all organisations, access systems are paramount to securing people, data, places, goods, and resources. Today, hybrid systems deliver significant added value to users at a much lower cost.

Read more...
Luxury residential access
Access Control & Identity Management Residential Estate (Industry)
Clifftown Shore is an exclusive collection of 51 luxury 1, 2 and 3-bedroom seafront apartments and penthouses set within a protected conservation park area, served by CAME’s XiP system and door entry system.

Read more...
From identity to insight
neaMetrics Access Control & Identity Management
Identity outlives technology. When it is trusted, it becomes a foundation for insight and scale. When it is not, every system built on it inherits the risk. Identity quality matters, at both human and system levels, and getting it right is what allows security to endure.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.