Nicolas Blank, expert in developing the Zero Trust Adoption Framework, discusses the importance of focusing on people and practices over products when adopting a zero trust approach. They explore the challenges of running an Exchange server, using Active Directory, and preparing for and preventing security breaches. The podcast also emphasizes the human side of breaches and the importance of device trust solutions.
Zero Trust is about prioritizing people and processes, not just buying products.
Risk modeling and scenario evaluation are crucial for effective security measures.
Deep dives
Importance of Zero Trust Adoption and Framework
Nicholas Blank discusses the importance of adopting a Zero Trust approach to cybersecurity. He explains that Zero Trust is not just about buying specific products, but rather a mindset and a set of practices that prioritize security. Blank emphasizes that organizations should focus on people and processes first, and then consider the products as a distant third priority. He highlights the need for rigorous hygiene, including measures like multi-factor authentication and regular patching, to prevent the majority of attacks. Blank also mentions the Zero Trust adoption framework, which provides guidance on transitioning to a more secure posture and aligning with compliance requirements.
Risk Modeling and Security Doctrines
Blank discusses the importance of risk modeling and aligning security measures with an organization's specific needs and vulnerabilities. He draws parallels between security doctrines of countries and the defensive strategies that companies should adopt. Blank explains that understanding what needs protection and how different scenarios can impact business is crucial. He emphasizes that security should be viewed holistically, considering both compliance requirements and actual security measures. Blank notes the need for continuous evaluation and improvement, as security is an ongoing endeavor.
Employee Awareness and Education
Blank stresses the significance of employee awareness and education in maintaining a strong security posture. He highlights the importance of training employees to recognize potential threats and adhere to security best practices. Blank discusses the value of tabletop exercises and scenario drills in preparing for breaches and making security a priority throughout the organization. He underlines the need for a common language within businesses to communicate security responsibilities to different stakeholders, including executives and business leaders.
Incremental Hardening and Continuous Improvement
Blank emphasizes the approach of incremental hardening to enhance security. He suggests that organizations should focus on improving existing security measures rather than constantly acquiring new products. Blank encourages businesses to prioritize basic hygiene practices, such as multi-factor authentication, regular patching, and securing sensitive data. He also mentions the importance of implementing zero trust principles, assuming breach, and considering risk models tailored to specific business needs. Blank concludes by highlighting the need for continuous improvement and utilizing available resources, such as Azure and Microsoft Learn, to enhance security practices.
We're all using zero trust - but are we using it well? Richard talks to Nicolas Blank about his work helping to develop the Zero Trust Adoption Framework. Nicolas talks about resisting the buzzword effect and avoiding looking at zero trust as a set of products because it isn't - it's really about the people and processes in your organization that keep things secure. The conversation also digs into the tabletop exercises needed to create priorities for security - not everything in your organization needs the same level of protection or effort. It pays to work through scenarios!