Securing IT with Zero-Trust – Peter Newton, Fortinet
Peter Newton, senior director of product and solutions for Fortinet, explains why zero-trust approaches to securing IT have finally come of age.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Peter Newton who is senior director of product and solutions before Danette and we're going to be talking about all things related to zero trust the networking Peter welcome to show Thank you pleasure to be here Mike. We've been talking about zero trust now for yeah, at least intensely for the last year or so, maybe two. I mean, it's not necessarily a net new idea per se but we appear to be getting more serious about it.
However, it's not something that you kind of just roll out of bed and go buy off the shelves somewhere. It seems like it takes a lot of time skill and effort and kind of first attain it and then maintain it. So what is the challenging getting the zero trust and and where are we in this journey?
I think that's a pretty good assessment of kind of the state of things the what I see a lot. I'm responsible for our zero trust Solutions here at fordnet and I talk with customers about zero trust all the time and I see a lot of confusion zero trust sounds so wonderful from a security standpoint. So a lot of people are talking about zero trust but that has also created confusion is different people are talking about different parts of zero trust.
So first and foremost zero trust at a high level is really a philosophy when a new mindset a new way of thinking about how to architect and secure your network. And then it's a matter of how do you then bring the right architectures and bring those products to your network to actually realize that zero trust. So it is absolutely not something you wake up in the morning and you and you go shopping for your zero trust and buy it and done by noon.
It is much more of a journey. It's a marathon where you start off with an assessment of where you are and then start thinking about where you want to go to next but it is the type of thing that it is a multi-eared journey to and and really quite actually one that you never fully finish it. As I said, it's it's more of a mindset.
So you just always are looking at how you can be more zero trust in your approach how you can bring those principles of zero trust to your network. Ultimately, are we talking about some sort of forklift upgrade of our entire network infrastructure or we just kind of adding software components to our existing infrastructure or is it all the above is just a question of when we do what? Well, you know like a good largely answer.
It's going to depend it kind of depends on what you got and what you can do with it. In some cases, it's more a matter of how do you configure your network? How do you enable certain capabilities that might already exist in other situations?
Perhaps the equipment in place doesn't quite have the capabilities necessary and some replacement might be required, you know right now at Fortinet we've recently rolled out. Well, actually it's been more than a year now. Our ztna capability and for our customers who have been using our firewalls and our client for their VPN access as many have during the pandemic.
For them to shift to azna approach to controlling access to Applications. There's no new hardware required. No new software required.
It's simply a matter of configuration. So it really depends on both the technology and what Question we're talking about it depends on what someone has in their Network as to whether or not zero trust is a disruptive re-architecture of the network or merely just a way of configuring things differently so that you can apply the ideas of zero trust which is at its most simple making sure that only people and devices that should have access to a given asset do have access to a given asset. And that also includes not just people right and we're talking about applications and machines and everything kind of has identity now, and we need to kind of assign those identities and then find some way to manage them as Lisa's how I understand.
Yeah, zero trust, you know, it's a whole philosophy and it's you know, ztna is one use case that looks at the very common situation of how do users access applications. You know, that's 90% of what people do and so bringing zero trust to that's important. But yeah, you're right zero trust also applies to devices trying to access resources.
It applies to you know, the servers, you know talking to each other. So the ideas of zero trust will affect, you know, the entirety of the network that affects users and devices but it also requires the ability to have controls around those assets. So it also affects the network that being the ability to segment and micro segment, you know, so that you're once a user or device has authenticated the idea that they only get access to that particular resource that they should have access to it.
So because well a big concept within zero trust is you want to prevent that lateral movement from attackers where someone gets authenticated or gets access through one mechanism and then they have the ability to run around the network and and do bad things. So a lot of zero trust is, you know, we are enabling people and devices to do what they need to do to do their job. But we're protecting the rest of the network by preventing that that person or advice from going outside of that particular area or particular asset.
Do you think this will also impact the way I teach teams are organized historically we've had you know security teams and their security operations teams, and we've seen them work a little more closely with network operations teams, and now we're starting to see application developers and devops teams. Take more responsibility for security as we go forward. How do you think that these teams will be organized to ensures zero trust?
A lot of what we see with zero trust kind of results in the convergence of networking and security where the security is not a bolt onto a network but really needs to be integrated in as people and devices are connecting to the network as their traversing the network having that security visibility control as integrated into the network. I think will impact how sock and not teams work together. I don't think we're gonna see the end of those two different organizations, but they are going to be working closely together.
We're seeing many times that in zero trust projects you have members of both of those organizations participating in the project because it is affecting both of their areas of responsibility. So I do expect it's going to drive closer collaboration more joint work, but I do see there will remain distinct. Reasons for both organizations both sock and knock to exist on their own.
Will we see machine learning algorithms and AI play a role in this process as well? Sure, but that's just and we've seen artificial intelligence machine learning be applied to a variety of cybersecurity capabilities, you know. Part of the zero trust concept is you want to be doing continuous evaluation of those folks who and devices who have access to your network that's where machine learning and artificial intelligence intelligence can really provide that oversight that analysis at scale for the millions of devices.
That might be on a given Network, you know far more than what a human could actually monitor. So by leveraging those uaba capabilities and and other Behavior monitoring we can actually detect when it looks like a user or device maybe no longer is indeed who they were initially. Maybe there's been an account takeover.
Maybe something is happened. So yes absolutely artificial intelligence machine learning in the same ways that they've enhanced cybersecurity elsewhere those same enhancements will absolutely be useful when applying zero trust philosophies. Then to come full circle we've been talking about zero trust for a while in various forms what's changed that's making it attainable.
Now, what's the thing that people should look at and say Here's the core advances in technology. That's making this easier to implement. One of the challenges of zero trust you mentioned actually at the top was that it is a complex area and it's not just something you wake up and do what we're seeing it as organizations are shifting towards more platform approaches.
It makes it easier to then use select a platform that's prepared for ztna that enables zero trust because you know, for example an importance security fabric, we've invested a lot in enabling those zero trust principles for users and devices so that as organizations are looking at how can I bring these zero trust principles into my network? They actually have a suite of products that are already designed to work together to enable those zero trust principles. So the biggest and challenge we see it when surveys time and time again when it when asked about why companies are not doing zero trust.
One of the top reasons is the complexity of getting all these pieces and parts necessaryly to work together to enable that granular authentication that ongoing verification that control and but with Fortinet security fabric for example as Platform approach those products are already integrated to work together. They're already designed to share information to enable automated activity and give that broad protection and visibility. So having and selecting a platform is really enabling much more zero trust to be applied into today's networks.
So it's I think it's really that Trend towards platform approach to cybersecurity is really enabling the number one challenge of zero trust, which is the complexity of the solution to really be now available to organizations. Do you think as a byproduct of that that we might actually reduce the total cost of security because we won't be spending as much time integrating all these different diverse Point products to try to build something and we'll have something that to your point feels more like an actual platform. From going to a platform approach and having a being able to deploy these zero trust is the reduced burden on the it organization.
And we do we're aware that right. Now one of the issues in the industry is the shortage of it folks who are trained and can support these cyber security networks with the platform approach. It actually enables with the Automation and integration that's already pre-done.
It actually lowers the burden on the it organization and making them more efficient and more effective. So certainly we think that you know, we see, you know smaller it teams that are able to support and provide extensive cyber security protection and these zero trust capabilities whether or not that's going to be an overall savings. I have to think it will simply because you know Manpower is a big part of that that budget for cyber security Is this also going to be more extended than it has been in the past?
I mean we've struggled with on-premise in the cloud and now we see more workloads moving to the edge and yet we don't have more people so it doesn't feel like the equation is going to work out all that well for us if we keep expanding the attack surface unless is there some other way of thinking about this that you know makes it viable. Well, I kind of look at it at the other and the other thing angle in that. One of the reasons that zero trust is becoming so important now and people are really interested in how to deploy it in their network is because they are seeing that attack surface expands so much.
You know, we've just come out of a pandemic where we pushed everybody to remote work. Now. We're in a situation where we're dealing with work from anywhere people working at home some of the time people working in the office some of the time of course travel and coffee shops are always part of the mix and so they're is this increase in the number of attack surfaces couple that with the fact that resources are now being hosted, you know, in internal data centers in Cloud hosted data centers, sometimes, you know, SAS is a certainly come up and so with resources being deployed everywhere with employees working for me everywhere using all types of different devices that is necessarily expanding the attack surface and intelligent response to that.
Is to start treating every connection every user every device as if they are an external connection and that's kind of one of the ideas around zero trust is nothing is trusted just because they're on your internal Network. You don't extend trust to it. So being able to apply.
Global policies no matter where a user is, you know, they're gonna get the same type of access. They're gonna get the same type of inspection. They're gonna get the same type of protection.
I think that's you know, really what's driving a lot of this zero trust, you know, coordinates Universal Z TNA as I mentioned talking about connecting users to Applications. We are enabling a much easier orchestration of that Global policy. Then has historically been the play case.
We've been using have our own zhta at Fortinet here. And our it group is really very pleasantly surprised with how it simplified their life when it comes to configuring all the routes to ensure that users get access to the appropriate applications before they'd have to do a lot of manual routing on the firewalls. But with GTA policies those policies get pushed out and orchestrated across the entire infrastructure that actually makes it simpler for that it organization.
So To get back to where I started. It's the broadening of the attack surface that I think is really driving ztna and it's I think a natural evolution of where we're going and organizations need to shift to a zero trust in order to maintain cybersecurity in this new way of working. Do you think looking back at the way the internet was built and the way we managed networks that we are just simply too trusting and now we're kind of circle and back to fix it particular issue.
I think that's an absolutely spot-on assessment as you know, the initial protocols for the network. We're all just about communication and connectivity security was absolutely an afterthought. But I think that the good news is we've made a lot of progress.
There's a lot that we can we are now delivering that it really bringing the integration of security into networking. All right. Hey Peter.
Thanks for sharing your insights and being on the show. My pleasure my great talking with you. All right back to you guys in the studio.