Zero Trust Security has a Bright & Necessary Future in Government

This year has been an extremely challenging one for federal employees. Instead of commuting to their normal office spaces, they must now clean up their spare rooms and kitchen tables to create home offices and makeshift workspaces. Before COVID-19 forced many agencies to adapt a telework-heavy framework, only 22% of employees telecommuted regularly. That number has now surpassed 90%, and many employees who never thought about teleworking before have been forced into it daily.

Now that agencies have successfully gotten their employees teleworking, the focus is on making the process more streamlined. This will reduce stress, eliminate security vulnerabilities, and allow employees to focus on their core missions, not problems with the telework environment. Government and technology experts believe they should concentrate on four key areas to improve remote working operations.

Featured Experts:

Jeff Lush, CIO, U.S. Air Force Air University
Jeff Lush
Chief Information Officer,
U.S. Air Force Air University
Mahreen Huque, Cybersecurity Technology Consultant, Ernst & Young
Mahreen Huque
Cybersecurity Technology Consultant, Ernst & Young
Susie Adam, Chief Technology Officer, Microsoft Federal
Susie Adams
Chief Technology Officer,
Microsoft Federal
Frank Briguglio, Global Public Sector Strategist, SailPoint
Frank Briguglio
Global Public Sector Strategist,
SailPoint

1. Understand Why Zero Trust is Necessary in Government

A recent report titled The National Counterintelligence Strategy of the United States predicted more attacks as well as more complex attacks from hostile actors. The old methods of trying to protect government using a perimeter security mindset have long since been circumvented by skilled attackers.

“I wish I could say no, but the reality is that cybercriminals are getting smarter,” said Chief Information Officer of the Air University at the United States Air Force Jeff Lush. “And although IT is doing a wonderful job trying to keep up with this overwhelming tide of challenges, when it comes to cyber, it’s difficult.”

Lush said that it is helpful to teach government employees how to maintain self-awareness by telling them not to do things like clicking on links or attachments where the source cannot be verified. But ultimately, someone is going to make a mistake, and unless you have something like a zero trust framework in place, there is a very good chance that attackers will find a way to slip through your defenses.

2. Reduce Exposure & Improve Access Management on the Path to Zero Trust

As evidenced by the SolarWinds breach, insufficient security can act as an open invitation for hostile actors, and government is no exception. However, the situation could have been avoided or mitigated if agencies had reduced their exposure or had better access management and zero trust elements in place. The attack would have still probably happened, but it’s effects would have been minimal.

“The thing that the government is pretty focused on these days as far as cybersecurity is threat detection,” said Cybersecurity Technology Consultant with Ernst and Young Mahreen Huque. That is good, but there needs to be more of a focus on post-breach response. “The recent attack on the software supply chain of the federal government showed the huge amount of exposure an attack can have” if it gets past that initial detection-based protection, she said.

Another element of zero trust that Huque recommends for government is eliminating static access levels, especially for highly credentialed users. Granting unlimited access to critical systems after a simple password or identity check should never be done anymore. SolarWinds and other companies caught in recent supply chain attacks clearly demonstrate the need to limit exposure and maintain a strong zero trust framework, even with established vendors like Microsoft.

3. Don’t Rely on Measures Such as PIV Cards & Other Basic Authentication

While many agencies have grown accustomed to access measures involving things like PIV and CAC cards to ensure authorization, there is growing concern that those methods might no longer be enough. As cyberattacks continue to evolve, the static authentication procedure offered by a PIV card probably won’t be enough to stop a skilled attacker.

“Government can’t rely just on a strong credential like a PIV card or active directory any longer,” said Global Public Sector Strategist for SailPoint Frank Briguglio. “We have to implement suitability policies and interrogations at the device level, and for whatever resource is being accessed and whatever action is being performed.”

By enforcing stronger authentication methods that force the system and users to communicate and constantly verify themselves, it prevents a hostile actor from simply mimicking PIV access and then having free reign within an agency’s system.

4. Zero Trust Provides the Best Methods to Handle Evolving Threats

ace of the overwhelming threats arrayed against government, zero trust is the most viable option for keeping agencies safe. It works even after a breach occurs to mitigate damage and restrict what an attacker can actually do even if they initially gain access.

“You have to think of zero trust as several layers,” said Huque. “We have the users, the application, the data and the network. It’s about authenticating users to data applications and systems in an adaptive way based on risk context and user attributes.”

Briguglio added that the hardest part of implementing zero trust in government is getting “systems and organizations to work together.” It has to be a team effort where management, the IT teams and rank and file employees all understand the need for zero trust and support its implementation to protect their agency. Zero trust might be difficult to implement, but it’s the best path forward to protecting government against the increasingly brutal threat landscape.

Carahsoft-Sailpoint-logos-color