Available on Demand | May 29, 2025 | 2 Hours | 2 CPE

State and local, territorial, and tribal governments are not bound by the federal agency mandate to implement zero trust architectures, but there are numerous reasons they are either considering it or taking action to put it in place.

Zero trust is a particularly important concept for these smaller government bodies because they own and operate critical infrastructure and provide vital day-to-day services to their residents, from issuing driver’s licenses to approving building permits. It also helps these governments comply with various privacy and security regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), which protects sensitive health information from being disclosed without the patient’s consent.

Hosted By:

Claudia Hosky, Publisher, FedInsider

Claudia Hosky
Publisher,
FedInsider
John Breeden II, Moderator & Contributing Editor, FedInsider

John Breeden II
Contributing Editor,
FedInsider

Open Remarks:

CyberThreats 2025: Ken Klestinec, Regional Sales Manager, Akamai Technologies

Ken Klestinec
Regional Sales Manager,
Akamai Technologies

Session One: Beyond Zero Trust — Embracing Least Permissive Trust

The premise of zero trust architectures is based on the maxim “never trust, always verify.” This can be difficult when working with siloed legacy systems, where communication links are tenuous because of proprietary technology or don’t exist because they were never connected to each other. Additionally, ZT is identity-based, but users often have multiple “identities” depending on their physical location, their day-to-day work, groups they may belong to, etc. Incorporating the concept of “least permissive trust” takes identity-based access one step further.

Bernice Bond, Chief Information Security Officer (CISO), North Carolina Department of Information Technology

Bernice Bond
Chief Information Security Officer,
North Carolina Department of IT
Jason Turse, Principal Enterprise Architect, Public Sector, Akamai Technologies

Jason Turse
Principal Enterprise Architect,
Public Sector, Akamai Technologies

Session Two: The Building Blocks of Least Permissive Trust: ICAM & Micro-Segmentation

Micro-segmentation – dividing networks into smaller segments that can be isolated, often at the individual workload level – mitigates threats from users that legitimately have access to one part of a system but should not be able to move laterally to other parts of that system. Identity Credential Access Management (ICAM), compliments micro-segmentation, ensuring that access and permission is specifically in line with the persona attached to them. Both network solutions embody the tenants of Least Permissive Trust, building flexible, responsive controls that can block unexpected or inappropriate movements within a network.

Cesar Gamez, Information Security Administrator, City of Roseville CA

Cesar Gamez
Information Security Administrator,
City of Roseville CA
CyberThreats 2024: Douglas Holland, Senior Solutions Engineer, Akamai

Douglas Holland
Senior Solutions Engineer,
Akamai Technologies

Session Three: Applying Analytics to Least Permissive

Maximizing the value of identity verification and network micro-segmentation requires visibility across not just identity and networks, but devices, applications, workloads, and data. With that visibility comes the opportunity for analytics, to create a unified cybersecurity picture. Automation and orchestration can streamline security operations, and improve governance by applying relevant regulations and reporting requirements.

Micah Maryn, Sr. Solutions Engineer, Government Solutions, Akamai

Micah Maryn
Senior Solutions Engineer,
Government Solutions, Akamai

Closing Remarks:

Rob San Martin, Vice President, Public Sector, Akamai Technologies

Rob San Martin
Vice President, Public Sector,
Akamai Technologies

FI-CS-Akamai-CPS-Logos-Color