Federal agencies are implementing zero trust frameworks to strengthen cybersecurity, but face budgeting challenges and complexities when doing so.
Considering the sophistication of cyber threats these days, with the wide variety of those threats including phishing, ransomware, social engineering, bots and many others, stronger cybersecurity measures are a must. Adopting a zero trust environment can provide that level of security, but it also creates a budget challenge for federal agencies as well as state and local governments that normally deal with static IT budgets, which are sometimes planned years in advance.
Thought leaders from government and industry spoke at a recent FedInsider webinar to discuss the budget challenges of zero trust, and how they’re creating and implementing a zero trust path with the sometimes limited resources they’ve been given.
Featured Experts:
The Value of Zero Trust
“Zero trust itself is ultimately a more modern and more effective way of protecting our assets,” said Jennifer Franks, director of the Center for Enhanced Cybersecurity for the Government Accountability Office.
A zero trust model, for instance, allows IT teams to continually authorize users or devices to ensure the right users have the right access to the right resources at the right time. This is an improvement from traditional, parameter-based security models, providing greater access to multi-tool resources where user authentication to the network is continuous, and greater overall situational awareness and monitoring is in place.
As the threat landscape evolves – to the point where even nation-states are attempting to take down electrical grids and water treatment plants – it is critical to also change the traditional way of thinking in terms of cybersecurity, according to Bob Costello, chief information officer of the Cybersecurity and Infrastructure Security Agency.
“We are not just going to secure the perimeter, and instead really need to not trust any device or any user on the network,” Costello said. When it comes to adopting this way of thinking and implementing zero trust where possible, he added, “I think that is a positive thing and in the long-term it helps us move faster.”
Complexities Around Budgeting for Zero Trust
Budgeting for zero trust is a new idea for many federal agencies, said Brian Dennis, principal technologist for the public sector at Akamai Technologies. “Zero trust, it’s not just a product or service that you can buy off-the-shelf, it’s the cybersecurity framework that requires a comprehensive approach,” he said. It requires rethinking and restructuring network architectures, data access and user authentication. This means budgeting for areas agencies have not necessarily been considering before.
Adopting a zero trust architecture means implementing a wide range of components in that process, like microsegmentation for networks, identity and access management, multifactor authentication, continuous monitoring and more.
“We are looking at all these new products and services we are bringing into an organization. So, we have to integrate all those and also combine multiple technologies,” Dennis said. To ensure all these components work well together, this must now be accounted for in the budgeting process. And considering every agency is different and has various needs, customization and tailoring can often be involved in these budgeting processes, too.
Getting these networks up and running for zero trust also requires more cyber talent and a cultural shift, which must be considered in the budgeting process. And budgeting for zero trust isn’t a one-time thing, either. It’s a long-term investment, requiring initial costs, costs associated with deployment, and a budget that allows for scaling as cyber threats evolve.
Adding Zero Trust to Federal Budgets
Applying budgeted resources properly where they are most needed is another key to successful zero trust implementations, according to Jonathan Feibus, chief information security officer of the Nuclear Regulatory Commission. The budget process often takes multiple years, starting with aligning cost models and priorities from what didn’t get done in in previous years with plans for the future. Sometimes that calls for creativity.
For example, when Feibus was looking at the various business lines of the agency, he noticed that certain elements crossed over to other areas when it came to funding zero trust upgrades. For example, funding to help a Common Access Card (CAC) system move into a zero trust environment could draw from both the IT and physical security budget, since the use of CAC cards touches both areas. Aligning and combining those lines of business as it relates to zero trust could make finding the required funds less challenging.
Other business lines, like corporate support, operating reactors and material support could also potentially be funneled into one system to help implement zero trust. “I need to look at how I am doing my development,” Feibus said. “Is it being paid for appropriately? Do I have the right funding there? Do I have the right idea to make sure all of the capabilities that are needed across the enterprise are being taken care of?” Answering questions like that is something that could potentially help agencies as they work support zero trust initiatives.
Nicole Willis, deputy chief technology officer of the National Archives and Records Administration (NARA) – which has a smaller IT budget than many other agencies – must still modernize even though there is little new money to invest in zero trust.
Like many smaller government agencies, Willis says that NARA has quite a few “large modernization projects that we’ve had to spread across many years because of the way the funding is made available.” The key for smaller agencies may be to use funding earmarked for modernization projects to also ease systems into a zero trust environment. “We are looking at modernizing the network structure and our applications while we build zero trust capability,” she added.
How to Budget for Zero Trust
Considering its many components and complexities, Chris Riordan, chief technology officer at RavenTek, recommends including zero trust pillars and capabilities in everything as agencies modernize. “Make sure you are budgeting for those fundamental baseline capabilities in analytics, visibility, automation and orchestration, governance and observability,” he said. This helps to measure outcomes and ensure effective asset management.
Asset management also helps agencies to allocate funds where there are gaps, rather than investing in capabilities they already have or don’t need. Riordan also recommends ensuring there are funds for hiring the necessary experts and getting rid of cycles that are no longer needed when replacing legacy systems. “Transition the staff and get that technology out of your environment because that will increase your risk as well,” he said.
For instance, Willis’ team at NARA, is considering fully utilizing all the solutions they already have around the zero trust pillars of identity management, endpoint security, visibility and analytics. Then, they’ll look at the gaps, and if any of those existing capabilities can be used to fill them, that is what they will do before acquiring anything new.
“We meet regularly with solution providers to see how we can fully implement and leverage all the solutions across the pillars to make sure we are fully maximizing our investments, and then look to identify additional funding to fill in any gaps that remain,” Willis said.
Dennis added that agencies need to be careful because there are quite a few hidden costs that are often overlooked when it comes to zero trust. Those include costs associated with zero trust systems deployment, consultancy for ongoing operations, completing various assessments and even expenses needed to help with meeting certain policy requirements. There are also overlooked technology and infrastructure costs to budget for, like endpoint security, and ongoing maintenance and monitoring tasks. Agencies must also consider cybersecurity training costs, incident response and recovery needs, and any potential productivity loss associated with zero trust deployments.
“It really comes down to budgeting for scalability,” Dennis said. “You have to make sure to account for the fact that your organization will grow and understand that it will change. Any new zero trust architecture needs to scale accordingly with that.”






