Technology Magazine November 2022 | Page 75

CLOUD AND CYBER
Zero Trust has reached “ critical mass ” for identity verification Elsewhere , there are encouraging signs – Marc Rogers , Senior Director of Cybersecurity Strategy , Okta , says identityfirst security has reached “ critical mass ” in the past year . “ The trend is not going away ,” he says . “ Increasingly , identity-centric Zero Trust frameworks will be the best choice for any security-conscious organisation .”
The principle of Zero Trust architecture is straightforward enough , explains Rogers : all network traffic should be considered untrusted until validated . Using this “ don ’ t trust , always verify ” approach helps with the management of remote and hybrid workforces as the threat of ransomware continues to grow .
Okta ’ s recent State of Zero Trust report indicated that all financial services organisations , without exception , planned to have a Zero Trust initiative in development within the next 18 months . This comes after the sector has faced a 35 % increase in ransomware attacks – more so than any other industry , according to the latest report by the Anti-Phishing Working Group ( APWG ).
But heightened awareness does not necessarily translate into action and preparation ; C-suite executives must prioritise Zero Trust and other cybersecurity measures , explains Capgemini ’ s van der Linden . Today , there appears to be a lack of collaboration between cybersecurity teams and boardroom stakeholders , which has a knock-on effect for budget allocation and the speed with which organisations respond to a ransomware attack .
“ Governance is a particular concern – this area demonstrates the lowest level of preparedness across multiple parameters ,”
A study by Cybereason revealed that more than half of organisations had been the victim of a ransomware attack , with 80 % of businesses that chose to pay a ransom demand suffering a second ransomware attack , often at the hands of the same threat actor group .
The report , Ransomware : The True Cost to Business , also revealed that 46 % of organisations who opted to pay a ransom demand reported that some or all of the data was corrupted during the recovery process .
says van der Linden , “ Our research shows that response preparedness is just as low , with 54 % of executives saying that they don ’ t have – or don ’ t know if they have – a team dedicated to preparing for and responding to cyberattacks at their organisations ' smart factories .”
People are a problem , but cyber experts are vital for the fight People are the first , but also the weakest , line of defence , claims van der Linden , so employees must be trained to spot early warning signs of a potential attack so that companies can mount a rapid response . “ Training experts who can oversee the implementation of comprehensive security measures are vital – and investment in this area will not be wasted ,” he says . “ Those that cannot get this off the ground quickly should consider partnering with an organisation equipped with expertise and end-to-end services to manage it .”
This is echoed by Okta ’ s research and Rogers , both of which agree that
technologymagazine . com 75