Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Vodacom to take control of Safaricom in R36-billion deal - Shameel Joosub

      Vodacom to take control of Safaricom in R36-billion deal

      4 December 2025
      Black Friday goes digital in South Africa as online spending surges to record high

      Black Friday goes digital in South Africa as online spending surges to record high

      4 December 2025
      BYD takes direct aim at Toyota with launch of sub-R500 000 Sealion 5 PHEV

      BYD takes direct aim at Toyota with launch of sub-R500 000 Sealion 5 PHEV

      4 December 2025
      'Get it now': Takealot in new instant deliveries pilot

      ‘Get it now’: Takealot in new instant deliveries pilot

      4 December 2025
      What South Africans searched for most in 2025

      What South Africans searched for most in 2025, according to Google

      4 December 2025
    • World
      Amazon and Google launch multi-cloud service for faster connectivity

      Amazon and Google launch multi-cloud service for faster connectivity

      1 December 2025
      Google makes final court plea to stop US breakup

      Google makes final court plea to stop US breakup

      21 November 2025
      Bezos unveils monster rocket: New Glenn 9x4 set to dwarf Saturn V

      Bezos unveils monster rocket: New Glenn 9×4 set to dwarf Saturn V

      21 November 2025
      Tech shares turbocharged by Nvidia's stellar earnings

      Tech shares turbocharged by stellar Nvidia earnings

      20 November 2025
      Config file blamed for Cloudflare meltdown that disrupted the web

      Config file blamed for Cloudflare meltdown that disrupted the web

      19 November 2025
    • In-depth
      Jensen Huang Nvidia

      So, will China really win the AI race?

      14 November 2025
      Valve's Linux console takes aim at Microsoft's gaming empire

      Valve’s Linux console takes aim at Microsoft’s gaming empire

      13 November 2025
      iOCO's extraordinary comeback plan - Rhys Summerton

      iOCO’s extraordinary comeback plan

      28 October 2025
      Why smart glasses keep failing - no, it's not the tech - Mark Zuckerberg

      Why smart glasses keep failing – it’s not the tech

      19 October 2025
      BYD to blanket South Africa with megawatt-scale EV charging network - Stella Li

      BYD to blanket South Africa with megawatt-scale EV charging network

      16 October 2025
    • TCS
      TCS+ | How Cloud on Demand helps partners thrive in the AWS ecosystem - Odwa Ndyaluvane and Xenia Rhode

      TCS+ | How Cloud On Demand helps partners thrive in the AWS ecosystem

      4 December 2025
      TCS | MTN Group CEO Ralph Mupita on competition, AI and the future of mobile

      TCS | Ralph Mupita on competition, AI and the future of mobile

      28 November 2025
      TCS | Dominic Cull on fixing South Africa's ICT policy bottlenecks

      TCS | Dominic Cull on fixing South Africa’s ICT policy bottlenecks

      21 November 2025
      TCS | BMW CEO Peter van Binsbergen on the future of South Africa's automotive industry

      TCS | BMW CEO Peter van Binsbergen on the future of South Africa’s automotive industry

      6 November 2025
      TCS | Why Altron is building an AI factory - Bongani Andy Mabaso

      TCS | Why Altron is building an AI factory in Johannesburg

      28 October 2025
    • Opinion
      Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

      Your data, your hardware: the DIY AI revolution is coming

      20 November 2025
      Zero Carbon Charge founder Joubert Roux

      The energy revolution South Africa can’t afford to miss

      20 November 2025
      It's time for a new approach to government IT spend in South Africa - Richard Firth

      It’s time for a new approach to government IT spend in South Africa

      19 November 2025
      How South Africa's broken Rica system fuels murder and mayhem - Farhad Khan

      How South Africa’s broken Rica system fuels murder and mayhem

      10 November 2025
      South Africa's AI data centre boom risks overloading a fragile grid - Paul Colmer

      South Africa’s AI data centre boom risks overloading a fragile grid

      30 October 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » When will Zero Trust move from hype to reality?

    When will Zero Trust move from hype to reality?

    By Skybox Security29 March 2022
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    While the approach of Zero Trust may become a reality to some organisations over the course of 2022, for most organisations it will mostly exist as an aspiration. Others will claim success simply by applying a few of the many principles of Zero Trust in practice. That said, it will undoubtedly be a slow journey to get there.

    What is Zero Trust and why do we need it?

    The theory behind Zero Trust fundamentally changes how we perceive threats. Conventionally, we perceived bad actors as being on the external side of the network (the untrusted side) and viewed everyone sitting on the inside (the trusted side) to be both known and therefore trusted.

    In today’s cybersecurity climate, this a dated mindset. Unfortunately, it’s still the status quo for many organisations. This thinking goes back in time to the days where clear perimeters existed, and the only way into the network was through tightly controlled channels. And even those “tightly controlled” channels were not always secure or even the only way in.

    See how Skybox Security can help you with Zero Trust

    But the model worked to a degree, and defence-in-depth was born. Based on the continuous growth in the number of vulnerabilities and increased sophistication of both hackers and TTP (tactics, techniques and procedures) that we see today in our complex digital ecosystem, clearly something needs to change. Enter Zero Trust.

    ‘Trustworthy’ users can inadvertently let the bad actors in

    Evidence of successful data breaches and cyberattacks has shown us that bad actors can operate from within the network, on the so-called “trusted” side. This design is something that attackers can leverage to their advantage and can often go undetected until it is too late. Often, the so-called “trusted” users are unaware that an attacker may have used their user identity. The actors may be silently in the background relying on users’ privileges to infiltrate and move across the network to access sensitive data and critical systems undetected.

    Zero Trust is an approach that flips this on its head. It changes the model to one that applies the “least-privilege” principal by default, categorising all users as automatically untrusted from the outset. Therefore, to access any resource, the user must be identified and authenticated before gaining access and privileges for that application, system or resource.

    Government entities increase pressure to adopt Zero Trust principles

    Zero Trust is not going away. In fact, government entities are increasing the pressure. For example, the executive order on improving US cybersecurity, issued by the White House in May 2021, made the federal government’s position clear on the need to advance Zero Trust. Just a few months ago, it also announced the federal strategy to move the US government itself towards a Zero Trust architecture.

    As our adversaries continue to pursue innovative ways to breach our infrastructure, we must continue to fundamentally transform our approach to federal cybersecurity,” said CISA director Jen Easterly. “Zero trust is a key element of this effort to modernise and strengthen our defences. CISA will continue to provide technical support and operational expertise to agencies as we strive to achieve a shared baseline of maturity.” — Office of management and budget releases federal strategy to move the US government towards a Zero Trust architecture, the White House briefing room, 26 January 2022.

    Read our point of view on the Biden executive order

    The same goes across Europe where EU organisations are equally being encouraged to adopt Zero Trust principles with the latest revision of the European NIS directive, NIS2.

    Concern about maintaining business operations stunts Zero Trust framework adoption

    We can’t deny that a methodology designed to establish different levels of trust as additional access and movement is required and is entirely logical. However, implementing a complete Zero Trust model successfully, as it is defined, is largely impractical in the real world and an unrealistic objective for many organisations.

    That’s not to say Zero Trust is unrealistic to achieve because it’s flawed or doesn’t work; applying the theory to practice in the real world is just difficult. In the real world, enterprises face many challenges: fragmented infrastructures, legacy systems, bespoke applications, visibility, cloud environments, existing transformation, migrations and more.

    Businesses are reluctant to make changes that impact important organisational operations. This impact must be considered when changing how an infrastructure behaves and how users (employees, customers, partners) interact with these services.

    When considering operational impact, redefining and redesigning access and privileges is extremely complex. Thus, Zero Trust has often been considered “hype” instead of “reality” due to the difficulty level of implementation.

    Zero Trust will become the new best-practice benchmark

    Enterprises should look to identify areas of their networks and critical assets where Zero Trust is achievable. They can then apply Zero Trust principles to make solid improvements to increase their security posture efficacy overall. Those that make inroads – even incrementally – will be much more successful in preventing a security breach over the next few years.

    Over the next few years, many enterprises will set Zero Trust security objectives in their strategy, with established metrics to evaluate and measure success. The organisations that fail to take this initiative will continue to leave parts of their critical infrastructure open and susceptible to sophisticated attacks, not to mention the steady increase in cost of managing and operating a suboptimal defence strategy over time.

    Zero Trust will become the new best practice benchmark, particularly for organisations undertaking cloud transitions and migrations to cloud services. In this case, defining trust models and data access within cloud environments becomes more practical and achievable.

    Advance your Zero Trust network strategy with the Skybox Security Posture Management platform

    Skybox Security can help you establish and maintain a Zero Trust framework by providing visibility and a continuous understanding of your hybrid networks and the attack surface across all environments. You need to model and analyse your network, cloud and security configurations together. This context helps you make informed decisions about what critical assets to protect with Zero Trust, how to properly design the network environments and what specific policies need to be applied. Once the Zero Trust architecture is established, continuous and adaptive modelling of the hybrid networks is necessary to effectively maintain the Zero Trust posture.

    Skybox can help you advance these five key areas of developing and executing a Zero Trust strategy:

    1.) Determine where to focus your zero trust efforts. With Skybox, you can aggregate and consolidate data sets that reflect the current configurations of your hybrid infrastructure, all your security controls, and endpoints. You can then identify the critical assets, applications, data repositories and infrastructure that will comprise your Zero Trust zone.

    2.) Model your hybrid network. By understanding your network connectivity, combined with your network and security configurations, you will know what you are starting with. Then you can visualise and assess your security efficacy and develop your Zero Trust strategy.

    3.) Architect for Zero Trust. Develop and optimise segmentation strategies, as well as configure and optimise your network and security technologies.

    4.) Establish and validate Zero Trust policies. With Skybox, you can automatically assess policies for exposure risk and compliance. Validate policies using a network model.

    5.) Monitor and maintain. Leverage a network model to continually monitor your hybrid networks. Validate changes before they go live to ensure compliance. Automate change management processes and align with your Zero Trust architecture.

    Visit www.skyboxsecurity.com for more information or check out all the recent Skybox Security content on hub.techcentral.co.za/skybox.

    • This promoted content was paid for by the party concerned


    Skybox Skybox Security
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleCourt orders analogue TV switch-off delayed until June
    Next Article Rise to the Challenge with the new Redmi Note 11 Series from Xiaomi

    Related Posts

    4 tips for exposure management of your business applications - Skybox Security

    4 tips for exposure management of your business applications

    19 February 2025
    Network professionals lose nearly half their week to manual tasks that could be automated - Skybox Security report

    Network professionals lose nearly half their week to manual tasks that could be automated

    3 December 2024

    Skybox: half of firms fear security incidents due to siloed network and security teams

    17 October 2024
    Add A Comment

    Comments are closed.

    Company News
    AI is not a technology problem - iqbusiness

    AI is not a technology problem – iqbusiness

    5 December 2025
    Telcos are sitting on a data gold mine - but few know what do with it - Phillip du Plessis

    Telcos are sitting on a data gold mine – but few know what do with it

    4 December 2025
    Unlock smarter computing with your surface Copilot+ PC

    Unlock smarter computing with your Surface Copilot+ PC

    4 December 2025
    Opinion
    Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

    Your data, your hardware: the DIY AI revolution is coming

    20 November 2025
    Zero Carbon Charge founder Joubert Roux

    The energy revolution South Africa can’t afford to miss

    20 November 2025
    It's time for a new approach to government IT spend in South Africa - Richard Firth

    It’s time for a new approach to government IT spend in South Africa

    19 November 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    AI is not a technology problem - iqbusiness

    AI is not a technology problem – iqbusiness

    5 December 2025
    Vodacom to take control of Safaricom in R36-billion deal - Shameel Joosub

    Vodacom to take control of Safaricom in R36-billion deal

    4 December 2025
    Black Friday goes digital in South Africa as online spending surges to record high

    Black Friday goes digital in South Africa as online spending surges to record high

    4 December 2025
    BYD takes direct aim at Toyota with launch of sub-R500 000 Sealion 5 PHEV

    BYD takes direct aim at Toyota with launch of sub-R500 000 Sealion 5 PHEV

    4 December 2025
    © 2009 - 2025 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}