Zero Trust and user fatigue

SMART Access & Identity 2024 Access Control & Identity Management, Information Security


Paul Meyer.

When it comes to zero trust network access (ZTNA), Gartner defines it as products and services that create an identity and context-based, logical-access boundary encompassing an enterprise user and an internally hosted application or set of applications. The applications are hidden from discovery, and access is restricted via a trust broker to a collection of named entities, which limits lateral movement within a network.

Gartner1 adds that ZTNA solutions are rapidly replacing remote access VPNs for application access. This Market Guide, which includes a list of representative vendors and their products, will help security and risk management leaders evaluate ZTNA offerings as part of a security service edge (SSE) strategy. Gartner notes an increased focus by end user organisations on zero trust strategies/cloud adoption – and a desire to provide more secure and flexible connectivity for hybrid workforces – heightens interest in the zero trust network access (ZTNA) market.

Organisations identify VPN replacement as their primary motivation for evaluating ZTNA offerings, but find that justification comes from risk reduction, not from any cost savings. Agent-based ZTNA is increasingly deployed as part of a more significant secure access service edge (SASE) architecture or security service edge (SSE) solution to replace always-on VPNs that traditionally provide full network security stacks for remote managed endpoints.

A new study2 from the National Institute of Standards and Technology (NIST) found that a majority of the typical computer users they interviewed experienced security fatigue which often lead users to risky computing behaviour at work and in their personal lives.

What is the perimeter today?

We live in a new world of widespread networking, remote access and rapid information exchange, with new technologies such as mobile devices and cloud, poking even more holes in the perimeter.

Today, cybersecurity is evolving again. Cyberattacks are dynamic, challenging to predict, and have higher stakes. Cybercriminals have the latest technologies at their fingertips. Machines are deployed against the enterprise’s defences, operating at a vast scale, with volume, speed and agility.

The attack surface grows daily, with two-thirds of employees3 said to be using their own devices for work, and some reported using more than one (e.g., cell phone, tablet, personal laptop, wearable technology). The unstoppable trend of bring your own device (BYOD) requires new security measures to manage these myriad endpoints.

So, the castle-and-moat approach to cybersecurity will not do the job. Vulnerabilities permeate all levels of business systems, and your cybersecurity strategies probably need a reboot. Today’s threats cannot be fought with yesterday’s strategies, and a zero trust approach to security is required.

Zero Trust is a network security model based on the idea of never trust, always verify. Users and endpoints are not trusted until they are authenticated; even then they only gain access to specific, limited applications and data. Additionally, they must reauthenticate periodically to maintain their access. Smart threat detection technologies patrol the network, analysing patterns and flagging anomalous or suspicious behaviour.

With holistic Enterprise Information Management (EIM) technologies, critical data is centralised and protected within layers of security, extending from the heart of the enterprise to all endpoints. Protection is complete against all attack vectors, external or internal. The latter ensures protection against mistakes, either deliberate or caused by internal user fatigue (one report by IBM found that 95% of cybersecurity breaches result from human error). In other words, human mistakes are so overwhelming in cybersecurity that 19 out of 20 cyber breaches result from human error.

Identity access management (IAM) authenticates and authorises each user. An IAM system includes automated lifecycle management for internal and external users, comprehensive identity governance, privileged access management and integrated multi-factor authentication (MFA) capabilities. It stops identity sprawl to third parties, centralising and protecting identities.

However, securing identities is just the beginning. One of the most common ways the bad guys circumvent enterprise security protocols is through endpoints. All edges are vulnerable – servers (on-premises and on-cloud), workstations, desktops, laptops, tablets, and mobile devices. This is why a Zero Trust security system must understand every unique endpoint and its security status, yielding complete visibility and control over any endpoint requesting access.

Find out more at iOCO, +27 11 607 8100, solve@ioco.tec, https://ioco.tech/

[1] https://www.securitysa.com/*gartner8

[2] https://www.securitysa.com/*ieee1

[3] https://www.securitysa.com/*opentext1




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Paxton set to launch game-changing new system
Paxton Access Control & Identity Management News & Events
Access control is evolving fast. Installers and end users are looking for systems that are simple to install, easy to manage remotely, and flexible enough to scale. In response, Paxton is exploring how emerging technologies can reshape access control.

Read more...
NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
Protecting citizens’ identities: a shared responsibility
Access Control & Identity Management
A blind spot in identity authentication today is still physical identity documents. Identity cards, passports, and driver’s licences, biometric or not, are broken, forged, or misused, fueling global trafficking networks and undermining public trust in institutions.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.