Building a zero trust environment

1 June 2019 Infrastructure, Integrated Solutions

New technologies and trends, including the mobile workforce, BYOD, IoT, digital transformation, and the consumerisation of IT, are shifting identity and access management to the very core of digital organisations – the IT environment is becoming increasingly distributed.

So says Adeshni Rohit, business unit manager for Cisco at Axiz, adding that as the IT environment becomes more distributed, all these technologies, while delivering significant benefits and value, are ultimately widening the attack surface and greatly increasing enterprise risk. “What is crucial is that the way we secure today’s businesses under the digital age has changed. Perimeter security, which acts as layers around our valuable assets, is ineffective. We are trying to protect our data, and need to start building that protection around our IP and other information assets.”

Moreover, she says today’s data centres are becoming fragmented, no longer constrained by the comfortable security perimeter of firewalls and VPNs we so carefully constructed over the last decade. “Protecting today’s cloud-based, mobile enterprise requires a whole new approach. Although it is impossible to control the whole security stack for every cloud application, it is possible to employ tools and new identity standards to fill the gaps left by the disappearance of the traditional perimeter as we once knew it.”

IAM (identity and access management) that was once about defining and managing the roles and access privileges of individual users across the company, and under which circumstances in which users are granted or denied access privileges, has changed, explains Rohit. “It now goes far beyond a tool used to manage user identities and access, is it used to uniquely profile users, track their needs and behaviours, and drive security and efficiency.”

Traditional security architectures were designed with two groups in mind, trusted individuals, who need to be able to access everything inside the business, and untrusted ones, who are kept at arm’s length. There was a time, she says, when the tech department threw money at the latest and greatest defensive tools that formed a barrier between the two types of users, and emphasised securing the network perimeter, usually with firewalls. And this worked for a while, the barrier kept potential threats at bay and attackers out. But it also caused problems, because should the barrier fail, or a bad actor find a chink in its armour and gain a foothold on the company network, they would effectively have carte blanche over anything and everything on the organisations systems.

According to Rohit, another problem was the increased adoption of mobile and cloud technologies, that sees more work being conducted outside the safety of the company network. “This effectively breaks down the barrier between the two types of user, and the network perimeter becomes increasingly difficult to enforce. Employees, contractors, partners and suppliers, all access company data from beyond the traditional perimeter. In today’s cloud and mobile world, more individuals access more and more resources and data from a wide range of devices. And it only takes one attacker to wreak havoc within the company network, which means that businesses can no longer assume trust across any part of the IT environment, which throws away the idea of a trusted internal network and versus an untrusted external network.”

Identity is the common denominator, she adds, and the new security perimeter. “It is the only hope of securely connecting a vast ecosystem of users, devices and locations. And this is where zero trust comes in. Zero Trust is a security framework, developed by Forrester Research analyst Jon Kindervag in 2009. With zero trust, organisations cannot automatically trust anything inside or outside their perimeters. They need to verify anything and everything that is trying to connect to its systems, before it grants any access at all.”

Zero trust security rids security teams of the notion that organisations should have a ‘trusted’ internal network and an ‘untrusted’ external network. Technologies such as IoT, mobile and cloud mean that a network perimeter-centric view of security no longer works. What is needed now, is the ability to securely enable access for all users, including staff, third-party partners, contractors, suppliers and suchlike, irrespective of where they are located, or which device and network they are using.

In this way, a zero trust model makes sense. “In today’s security landscape, it’s not about the network any more, it’s about the people who access your systems, and the access controls for those people. This is where identity comes in, and making identity the foundation of zero trust. ‘Never trust, always verify’, is the key principle here. In this way, on the right people have the right level of access, to the right resources, in the right context, at the right time. And all this access is assessed on an ongoing basis, without impacting on the user at all,” says Rohit.

However, she says choosing the right IAM solution is critical. “Beginning a zero trust journey by employing a mixture of on-premises and cloud applications that are not well integrated, means the IT department will be burdened with the task of managing disparate identities across a number of systems. The user is encumbered with having to remember multiple, and therefore most likely weak passwords, and a lack of visibility and ownership over these fragmented identities leaves IT and security teams with massive gaps for threat actors to slither through.

This is why Axiz builds ecosystems to help its partners with their identity and access management needs, explains Rohit. “We help our customers to choose solutions that can scale to meet the needs of any business, from the smaller SMEs to today’s largest corporates, using thousands of integrations, cloud and on-premise, to securely connect everything, giving organisations the ability to easily manage single sign-on, provision users, and synchronise data across apps and systems.”

For more information, contact Axiz, +27 11 237 7000, [email protected], www.axiz.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Local-first data security is South Africa's new digital fortress
Infrastructure Information Security
With many global conversations taking place about data security and privacy, a distinct and powerful message is emerging from South Africa: the critical importance of a 'local first' approach to data security.

Read more...
Software security is a team sport
Information Security Infrastructure
Building and maintaining secure software is not a one-team effort; it requires the collective strength and collaboration of security, engineering, and operations teams.

Read more...
Cape Town estates gain access to advanced security technology at Securex
Securex South Africa News & Events Integrated Solutions
For the first time, estate and complex security decision-makers in the Western Cape will have direct access to the breadth of solutions and expertise these shows are synonymous with.

Read more...
Making drone security more accessible
Editor's Choice Integrated Solutions Residential Estate (Industry) AI & Data Analytics IoT & Automation
Michael Lever discusses advances in drone technology, focusing on cost reductions and the implementation of automated services, including beyond line of sight capabilities, for residential estates with SMART Security Solutions.

Read more...
View from the trenches
Technews Publishing SMART Security Solutions Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
There are many great options available to estates for effectively managing their security and operations, but those in the trenches are often limited by body corporate/HOA budget restrictions and misunderstandings.

Read more...
SMART Estate Security Conference KZN 2025
Arteco Global Africa OneSpace Technologies SMART Security Solutions Technews Publishing Editor's Choice Integrated Solutions Security Services & Risk Management Residential Estate (Industry)
May 2025 saw the SMART Security Solutions team heading off to Durban for our annual Estate Security Conference, once again hosted at the Mount Edgecombe Country Club.

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Make BIG and COMPLEX small and manageable
neaMetrics Suprema AI & Data Analytics Surveillance Integrated Solutions
Traditional CCTV and access systems often operate separately, creating gaps in visibility and efficiency. TRASSIR and Suprema have partnered to develop an integrated platform that improves security, operations, and situational awareness.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.