
Zero trust, in the order that works
Zero trust is not a product but a starting point: there is no place in the network that is trusted by default. Every request is judged on who it is, which device it is and what is being asked. That sounds large and can be introduced in steps, provided you start with the right one.
VPN against ZTNA
They solve the same question from a different starting point.
- What a VPN doesThe user enters the network and is then inside. What they can reach from there depends on what else has been closed off, and in practice that is more than was intended.
- What ZTNA doesThe user does not enter the network but is granted access to one application, judged each time. An infected device then cannot walk on to the rest, because the rest is not visible.
- What that means in practiceThe change is noticeable to administrators and usually not to users. It does not replace the firewall and is no reason to let go of device management.
Four steps, in this order
Anyone starting at step three stops the work and reverses it the week after.
Identity in order
One place accounts come from, two-step verification everywhere, and a process that closes an account when somebody leaves. Without this the rest has no basis to judge on.
Knowing the devices
Knowing which device belongs to the company, whether it is patched and whether the drive is encrypted. Granting access based on the device only works once that data is right.
Moving application by application
Start with one application and a small group, not with everything at once. Each step produces a list of who could reach it who should not have, and that is the gain.
Closing the old path
As long as the VPN stays alongside it, nothing changes about the risk. Closing the old route is the step that delivers, and the step most often left undone.
What belongs with this
Zero trust touches identity, devices and the network at once.
Start at the step that counts
Tell us how people currently come in from outside. You get an order of work with the first step that removes most of the risk, and what it costs.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.