{"id":22718,"date":"2021-10-19T15:28:18","date_gmt":"2021-10-19T15:28:18","guid":{"rendered":"https:\/\/zpesystems.com\/?p=22718"},"modified":"2021-10-19T16:24:31","modified_gmt":"2021-10-19T16:24:31","slug":"how-to-implement-zero-trust-technologies","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/","title":{"rendered":"How to Implement Zero Trust: Technologies to Shield You From Million-Dollar Losses"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;3.22&#8243; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row _builder_version=&#8221;3.25&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.25&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-1024x683.jpg\" width=\"693\" height=\"462\" alt=\"Staff on laptop with zero trust security in place.\" class=\"wp-image-22730 size-large\" \/><\/p>\n<p>How to implement zero trust security is a growing focus of organizations across the globe. With cyber attacks frequently hitting some of the largest companies and threatening <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-06-04\/hackers-breached-colonial-pipeline-using-compromised-password\" target=\"_blank\" rel=\"noopener\">entire economies<\/a>, it\u2019s no wonder why comprehensive network security is a top priority among public- and private-sector entities.<\/p>\n<p>In this post, we\u2019ll show you what you need to implement zero trust security, from big-picture items to individual technologies.<\/p>\n<p>But first, here\u2019s a recap of zero trust security and why your business won\u2019t be safe without it.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>Why you need Zero Trust Security<\/h1>\n<p>Imagine bringing in a new hire to your department. Soon after, you notice suspicious computer slowdowns and applications that don\u2019t respond as usual. You dive into your program files and discover an unknown .exe file, and you dive deeper to discover attackers actively exploiting your resources. You quickly pull your team together to lock down your network, sanitize every computer and connection, and send out a company-wide instruction to have every employee reset their password.<\/p>\n<p>It turns out, your newest employee unknowingly clicked a bad link and opened the door for a trojan horse attack. But because of your quick response, no significant damage was done and you can rest easy again.<\/p>\n<p>Months later, you come in for your normal workday only to find all your systems locked and unresponsive. Dave, a senior engineer, retired on the day of the attack and never reset his password. The hackers stole his credentials and have gone unnoticed for months. Now your company and its customers are compromised, and the consumer markets you serve are in a frenzy due to a shortage of goods. You can\u2019t help but feel somewhat responsible for the entire ordeal.<\/p>\n<p>This example mimics recent real-world cyberattacks and highlights the importance of moving away from traditional security approaches.<\/p>\n<p>Traditional architecture uses the castle-and-moat security approach. Once a user gains access (crosses the moat), they become trusted to use your organization\u2019s resources (the castle). Aside from the occasional password reset or other authentication protocol, this approach leaves plenty of opportunities for outsider and insider attacks. Zero trust security, however, places a moat around every node and user. This means that no matter how often a system or user needs to access a resource, they always have to verify their identity and intent.<\/p>\n<p>In other words: never trust, always verify. In our example above, implementing simple two-factor authentication could have alerted Dave to his stolen credentials, which would have prevented the attack.<\/p>\n<p>The need for zero trust is due to the explosion of distributed networking. Communications used to be straightforward and centralized: a trusted user using a trusted device would connect from a trusted office location to the data center. Apps and data were securely transmitted between parties, and sealing out attackers could be as simple as deploying a new point solution or product. But user expectations changed all this; now, they need to connect from anywhere using a variety of devices, which means the modern network includes SaaS, cloud, and third-party platforms. This hybrid infrastructure means there are now more nodes and lines of communication than ever \u2014 and each is vulnerable to attack.<\/p>\n<p>If the recent attacks on SolarWinds, Microsoft Exchange, and Colonial Pipeline aren\u2019t convincing enough, consider the latest <a href=\"https:\/\/www.nbcnews.com\/tech\/security\/ransomware-attack-software-manager-hits-200-companies-rcna1338\" target=\"_blank\" rel=\"noopener\">hack involving Kaseya<\/a>, an American company that specializes in IT and network management software. By exploiting the virtual systems\/server administrator (VSA), attackers were able to compromise up to 1,500 of Kaseya\u2019s customers, shutting down educational services, law firms, and an outpatient surgical center in South Carolina.<\/p>\n<p>Pervasive attacks like these have prompted political action, with the President signing a cybersecurity executive order this past May. <a href=\"https:\/\/zpesystems.com\/zero-trust-architecture\/\" target=\"_blank\" rel=\"noopener\">Read our breakdown of the legislation<\/a> and how it aims to improve cybersecurity across public and private sectors.<\/p>\n<p>Now that you know why you need better security, how do you implement zero trust?<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How to implement Zero Trust: The big picture<\/h1>\n<p>Zero trust is merely a concept, however implementing Zero Trust Network Access (ZTNA) means putting this concept to work. Implementing ZTNA involves two parts:<\/p>\n<ul>\n<li>The processes, which we covered in a <a href=\"https:\/\/zpesystems.com\/how-to-overcome-5-challenges-of-zero-trust-security\/\" target=\"_blank\" rel=\"noopener\">previous post<\/a>, and<\/li>\n<li>The technologies, which we\u2019ll talk about in this post<\/li>\n<\/ul>\n<p>At a high level, this diagram shows the components you need when considering how to implement zero trust.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Three-Main-Components-of-Zero-Trust-1024x587.jpg\" width=\"1024\" height=\"587\" alt=\"A high level diagram of the three main components of zero trust security, including the enterprise resource, policy enforcement point, and policy decision point.\" class=\"wp-image-22722 alignnone size-large\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Three-Main-Components-of-Zero-Trust-980x561.jpg 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Three-Main-Components-of-Zero-Trust-480x275.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/p>\n<p>There are three major components to look at in the big picture of zero trust security:<\/p>\n<ol>\n<li>Enterprise resource \u2014 This includes all the IT stuff you need to protect and that your business relies on, like hardware, software, and network equipment. In simple terms, this is like the gold that you keep carefully guarded in the center of your castle.<\/li>\n<li>Policy enforcement point \u2014 This is the datapath element that enables, monitors, and terminates connections between users \/ devices \/ applications and enterprise resources. Simply put, this is like the guard that accompanies those wishing to access your gold.<\/li>\n<li>Policy decision point \u2014\u00a0This is the layer that decides who \/ what is safe and grants \/ revokes access accordingly. In other words, this is the gatekeeper who determines who is allowed into your castle.<\/li>\n<\/ol>\n<p>To better understand these, here\u2019s a closer look at each:<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Enterprise resource<\/h3>\n<p>This component is pretty straightforward, and consists of elements you need to operate and manage IT environments. These elements can include hardware like computers and data storage devices; software such as web servers, content management systems, and operating systems; and network equipment like servers, routers, firewalls, and out-of-band devices.<\/p>\n<p>&nbsp;<\/p>\n<h3>Policy enforcement point<\/h3>\n<p>This component consists of the datapath elements that enable, monitor, and terminate connections between subjects (users \/ devices \/ applications) and your enterprise resources. Though this is represented as one component, it is comprised of two parts that are both typically used in deployments. These parts are:<\/p>\n<ul>\n<li>A client-side agent, usually deployed on a laptop or server.<\/li>\n<li>A resource-side gateway, which controls access in cases where a client-side agent is not used. Examples where gateways are used include regulated healthcare equipment, ATM machines, and operational technology equipment.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>Policy decision point<\/h3>\n<p>This component is the management and orchestration layer. This layer essentially checks identities to verify who is safe, and assigns policies to determine who gets access and to what. This is also represented as one component but is comprised of two parts:<\/p>\n<ul>\n<li>Policy engine \u2014 This is the engine that decides whether a machine or web traffic is safe. To accomplish this, the engine uses a variety of data sources when making its determination, such as PKIs and identity management providers, CDM systems, and activity logs.<\/li>\n<li>Policy administrator \u2014 This administrator uses the policy engine\u2019s determination to grant or revoke access to a machine or web traffic.<\/li>\n<\/ul>\n<p>There are many tools available to help you monitor and visualize traffic, so you can create policies and configure your policy decision point to meet your zero trust outcomes.<\/p>\n<p>In order to create your zero trust configuration, you need to deploy several essential technologies.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How to implement Zero Trust: Essential technologies<\/h1>\n<p>Zero trust is a complete re-imagining of network security and can be a daunting task. But when you add its fundamental technologies to your toolkit, you can effectively build the three components described above and achieve Zero Trust Network Access (ZTNA). Here are the essential technologies you need to accomplish this.<\/p>\n<p>&nbsp;<\/p>\n<h3>Identity and access management<\/h3>\n<p>Such a big part of zero trust security relies on verifying that a device or user really is who they say they are. For this, you need an identity management solution from a trusted provider and public key infrastructure (PKI). This allows you to essentially create and issue a digital fingerprint for every user, and includes information such as their username, role, and other unique data. Multi-factor authentication is a critical component of identity verification, which requires users to present two or more pieces of identification\/verification before granting access.<\/p>\n<p>Additionally, access management is an important piece that determines a user\u2019s authorization level, or in other words, which resources they can access. Identity and access management both feed information into your zero trust model\u2019s policy engine.<\/p>\n<p>&nbsp;<\/p>\n<h3>Policy management<\/h3>\n<p>Another essential technology to have is a policy management solution. This is integrated into your security stack and serves as a single policy creation point. This allows you to define access and authentication policies for your entire organization.<\/p>\n<p>You can specify data access rules for users, devices, and roles, which is vital to achieving micro-segmentation, limiting lateral movement, and enforcing least-privilege access. All of these feed into your policy engine and are used by your policy enforcement point to validate whether a session is allowed to continue.<\/p>\n<p>&nbsp;<\/p>\n<h3>Zero trust equipment and applications<\/h3>\n<p>Tying everything together requires equipment and applications that are able to enforce your policies. These are physical or virtual solutions that sit in front of servers and serve as your enforcement points. For example, this could be your next-gen firewall (NGFW) that initiates the multi-factor authentication protocol, verifies a user\u2019s identity, and uses your defined policies to restrict the user\u2019s access to a specific segment of your network.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>Where can you get these essential Zero Trust technologies?<\/h1>\n<p>When considering how to implement zero trust, keep in mind that there are many vendors who can provide you with the essential technologies.<\/p>\n<ul>\n<li>Obtaining an identity and access management solution is the easiest task when implementing zero trust. Many organizations offer an identity store, such as Azure Active Directory or Google Cloud Identity. You can also use companies dedicated to identity management, such as Duo, Okta, or Ping Identity. Keep in mind that if you need to control third-party access, such as for customers or equipment management contractors, you\u2019ll need a solution that can access multiple identity stores simultaneously.<\/li>\n<li>Obtaining a policy management solution requires careful consideration and should be part of your overall security stack. Look for a solution that allows you to create policies and set up datapath enforcement points. An adequate framework enables you to create authentication and post-authentication access rules, with an enforcement point that segments your network and continuously authenticates sessions. This security stack can be an on-prem NGFW, or delivered via the cloud using a Secure Access Service Edge (SASE) model, both of which are available from trusted providers like Palo Alto Networks.<\/li>\n<li>Regardless of whether you use an on-prem or SASE model, you need an edge infrastructure platform to sit in front of servers and host the enforcement point. For on-prem, this platform must be able to host an NGFW to secure network segments and VLANs. For SASE, this platform must be able to create VPN tunnels to your SASE platform, which can be used for inline inspection and policy enforcement. Either approach requires powerful computing capabilities and a flexible operating system to accommodate workloads for detecting, analyzing, and automatically responding to threats, which few vendors offer.<\/li>\n<\/ul>\n<p>Here are examples of what proper zero trust implementations look like, with ZPE Systems\u2019 Nodegrid as the edge infrastructure platform:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/ZTNA-at-the-data-center-1024x587.jpg\" width=\"1024\" height=\"587\" alt=\"Implementation diagram showing how to implement ZTNA at the data center using Nodegrid.\" class=\"wp-image-22724 alignnone size-large\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/ZTNA-at-the-data-center-980x561.jpg 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/ZTNA-at-the-data-center-480x275.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/p>\n<p>In this diagram, you can see where ZTNA and Nodegrid fit into the scheme at the data center. The user connects via Internet, and the Nodegrid SR device serves as the Policy Enforcement Point hosting a VM. This VM communicates with the Policy Engine to authenticate the user, and then grants access to the data center application.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Zero-trust-with-SASE-1024x587.jpg\" width=\"1024\" height=\"587\" alt=\"Implementation diagram showing how to implement ZTNA at a branch, edge, or other distributed location.\" class=\"wp-image-22725 alignnone size-large\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Zero-trust-with-SASE-980x561.jpg 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Zero-trust-with-SASE-480x275.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/p>\n<p>In this diagram, the user tries to connect to an application at a branch, edge, or other distributed location. The user connects via Internet, where SASE and ZTNA provide secure connectivity. The Nodegrid SR device connects via VPN to the Policy Engine for authentication, and then grants access to the branch application.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How to implement Zero Trust: A recap<\/h1>\n<p>To protect your organization, implementing zero trust requires you to build out the main components. With the policy decision point and policy enforcement point in place, you can secure your enterprise resources from outsider and insider attacks. Ensuring these components work like a well-oiled machine means you need the proper identity and access management tools, a complete policy management solution built into your security stack, and equipment and applications that can enforce your zero trust security policies.<\/p>\n<p>Because user expectations have caused infrastructure to become incredibly distributed and complex, the attack surface has increased dramatically. The traditional castle-and-moat approach to security is no longer adequate, and recent newsworthy cyberattacks showcase the network vulnerabilities that even the largest companies still struggle to address. The President\u2019s latest cybersecurity executive order is a step in the right direction to bolster infrastructure protection for public and private sector entities, and you can use this blog as a starting point to begin your zero trust journey.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.10.8&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>Don&#8217;t get caught without these 5 security must-haves<\/h1>\n<p>Watch our webinar, Cyberattacks: 5 Security Must-Haves for Hybrid Infrastructure Gateways, and learn how to lay a solid foundation that makes implementing zero trust easier. Our experts will talk you through how to:<\/p>\n<ul>\n<li>Keep edge networks and users fully protected<\/li>\n<li>Make smart buying decisions<\/li>\n<li>Get complete security and control for years of serviceability<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.brighttalk.com\/webcast\/18901\/495460?utm_source=ZPESystems&amp;utm_medium=brighttalk&amp;utm_campaign=495460\" target=\"_blank\" rel=\"noopener\">Watch now<\/a> to protect your business from growing cybercrime.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.7.4&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3><\/h3>\n<\/p>\n<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to implement zero trust security is a growing focus of organizations across the globe. With cyber attacks frequently hitting some of the largest companies and threatening entire economies, it\u2019s no wonder why comprehensive network security is a top priority among public- and private-sector entities. In this post, we\u2019ll show you what you need to [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":22730,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<p><span style=\"font-weight: 400;\">It\u2019s Friday morning, and you\u2019re bringing a new site online with <\/span><a href=\"https:\/\/searchitoperations.techtarget.com\/definition\/zero-touch-provisioning-ZTP\"><span style=\"font-weight: 400;\">zero touch provisioning<\/span><\/a><span style=\"font-weight: 400;\">. Your remote branch devices arrived the night before, and all you want the store manager to do is plug them in. A few minutes later, your job is finished and you\u2019ve still got your entire day left. What are you going to do with all your free time?<\/span><\/p><p><span style=\"font-weight: 400;\">This is the picture that\u2019s commonly painted of zero touch provisioning. And why not? When <\/span><a href=\"https:\/\/zpesystems.com\/ztp-vs-manual-configurations\/\"><span style=\"font-weight: 400;\">compared to manual provisioning<\/span><\/a><span style=\"font-weight: 400;\">, zero touch brings drastic improvements and efficiency to deploying networks. Its biggest benefits include:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Helping you deploy sites fast, because it\u2019s a plug \u2018n play solution<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reducing manual work and errors, because it\u2019s automatic<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Supporting on-demand scaling without bogging down your resources<\/span><\/li><\/ul><p><img class=\"alignnone size-medium wp-image-21448\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/08\/Business-person-using-laptop-300x169.jpeg\" alt=\"Business person using laptop connected to network users and services.\" width=\"300\" height=\"169\" \/><\/p><p><span style=\"font-weight: 400;\">With zero touch, you don\u2019t have to be on site for days or weeks manually configuring individual devices. You also shrink the risk of human error that can unwind all your deployment progress and force you to start over. And when it comes to scaling, it eliminates so many of the shipping costs and technician expenses, and instead lets you spin up new sites in a single day.<\/span><\/p><h1><b>So what\u2019s the problem with zero touch provisioning?<\/b><\/h1><p><span style=\"font-weight: 400;\">The trouble with zero touch provisioning is that it usually comes with hidden obstacles that vendors don\u2019t tell you about. Zero touch promises to make deployments quick and easy, but these obstacles can eat up your time savings and make you vulnerable to attacks.<\/span><\/p><p><span style=\"font-weight: 400;\">Here are 3 big drawbacks you need to know about zero touch provisioning.<\/span><\/p><h1><b>Drawback: Zero touch provisioning is limited to one vendor<\/b><\/h1><p><span style=\"font-weight: 400;\">Imagine you\u2019re on location setting up a plethora of devices from different vendors. You plug in your zero touch solution, but you still have to manually configure three other vendor devices that make up your stack. This is the first major drawback to zero touch provisioning.<\/span><\/p><p><span style=\"font-weight: 400;\">For the most part, zero touch is limited to one vendor\u2019s solutions and doesn\u2019t extend to devices or solutions from other providers. This is usually to encourage purchasing multiple solutions from or standardizing on one vendor.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Why is this a drawback?<\/span><\/i><span style=\"font-weight: 400;\"> This is just another approach to vendor lock-in. It limits your freedom when trying to leverage zero touch provisioning, which can be a major drawback especially in custom, multi-vendor environments. When you\u2019re choosing a zero touch solution, consider how much of your stack it can actually automate and how much time you\u2019ll still have to spend on manual provisioning.<\/span><\/p><h1><b>Drawback: Zero touch provisioning isn\u2019t secure<\/b><\/h1><p><span style=\"font-weight: 400;\">What happens if you set up your site with zero touch provisioning, only to discover that your network is already under attack? You wonder how it could have happened, but then you remember all of the preconfiguring required to make zero touch possible. This is another major drawback.<\/span><\/p><p><span style=\"font-weight: 400;\">Most solutions do live up to the promise of being \u2018zero touch,\u2019 but only after you\u2019ve performed extensive preconfiguring of your devices. This is a major security concern because you\u2019re loading up your stack with sensitive information about your network. <\/span><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/one-ransomware-victim-every-10\/?__cf_chl_jschl_tk__=e91acc451b339cf2fc3853ce37c8985b78f577c3-1626446900-0-AS17AWrjmhEiTXaSs_9DupzUV_9tBz1dtbIkrkDYNBCrFQc-bEkKJOtj70dXXPQdHK9YUda8NVPFoFB8LCG1vwm7mj-rXUU0ZRO8IWL3s7kGxOQr2GWGHO5fc7HbO8fmMCXYy5jKlTC5xHWQahzfFTOMxoPTmPWzj-lhZtBDfIUSY8T664ifhv0IUKz-PkFw6SlyUZD3O8g1KDJn1CI1qZnbo2xNjmeXqK--4HrwlExRCAaJwH0UN3SrftXSjJzwPHjdPLpR7hO2qPnJ_FPSZRyGsYze3BEVAapw2_O05L7MCi1KXXdiypJcDjaKXA-MVKI-NUwEgBI31hgiqoXSGFpZWUGWQEKYKvHLUHISVZ4EHGJXGEVJr4gvVvQBFcPrLNvsRpfy_hn414JWS9UBA0sYiHmQJa2K26ljRNmKRATUpBhA3MqYqOfhrRqI5ysfFQ\"><span style=\"font-weight: 400;\">Recent reports<\/span><\/a><span style=\"font-weight: 400;\"> show that ransomware claimed a victim every 10 seconds in 2020.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Why is this a drawback? <\/span><\/i><span style=\"font-weight: 400;\">With your network attack surface more distributed now, especially during the pandemic, it\u2019s critical to minimize your exposure to threats. But having to preconfigure your devices for zero touch provisioning makes it easier for you to become a victim. Even if you can keep careful watch over your devices to ensure no physical attacks occur, hackers can easily exploit your systems through something like an open port that one of your employees forgot to close. In a nutshell, preconfiguring puts you at unnecessary risk.<\/span><\/p><h1><b>Drawback: Zero touch provisioning limits orchestration<\/b><\/h1><p><span style=\"font-weight: 400;\">The ultimate goal of using zero touch provisioning is to add convenience to deployments and management. You want to save time and effort all around by eliminating manual work. But another major drawback to zero touch is that it puts a limit on how much and how many of your processes you can orchestrate.<\/span><\/p><p><span style=\"font-weight: 400;\">Automation is when you can automate simple tasks, while orchestration is when you can automate entire processes and workloads. Most zero touch solutions allow you to implement a little bit of both automation and orchestration, but limit or simply lack support for orchestrating across devices and environments.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Why is this a drawback? <\/span><\/i><span style=\"font-weight: 400;\">The more manual work you have to perform, the less value you get out of zero touch provisioning. And most solutions require you to manually bootstrap VMs, activate service licenses, run Docker apps, and even update device firmware as new patches are released. Though zero touch might save you time and effort on initial setup, consider how these savings might evaporate in the long run.<\/span><\/p><h1><b>Can you avoid these drawbacks?<\/b><\/h1><p><span style=\"font-weight: 400;\">Imagine you\u2019re setting up a new network. Your environment is tailored specifically to your needs, which includes a custom-built monitoring application, Palo Alto NGFW, data thinning workloads, and a host of other solutions meant to optimize operations. And the best part is, you don\u2019t have to worry about vendor lock-in, security gaps, or limited orchestration. All you need to do is plug in your devices, and the entire environment will build itself in just a matter of hours. Everything just works so you don\u2019t have to.<\/span><\/p><p><span style=\"font-weight: 400;\">That is what true zero touch provisioning feels like, and it\u2019s something we\u2019re passionate about at ZPE Systems. That\u2019s why we\u2019ve spent years building zero touch convenience features into our Nodegrid solutions. You don\u2019t have to put up with these major drawbacks any longer.<\/span><\/p><p><span style=\"font-weight: 400;\">Nodegrid\u2019s zero touch provisioning extends across vendor solutions, even to devices that don\u2019t support automation. This means that you can automate and push configurations to whatever you connect to Nodegrid \u2014\u00a0including legacy switches, routers, and other equipment.<\/span><\/p><p><span style=\"font-weight: 400;\">Nodegrid\u2019s zero touch provisioning also eliminates the need to preconfigure devices. ZPE Cloud serves as your repository for configuration files and allows you to remotely push these files to 100% factory-default devices. Physical attacks no longer pose a threat, while built-in security features and alerts automatically block and pinpoint attacks.<\/span><\/p><p><span style=\"font-weight: 400;\">Because Nodegrid OS is Linux-based, it gives you the freedom to orchestrate across devices and environments, with a rich API library and your choice of tools like Ansible, Chef, Puppet, and REST. You can save time and effort on deployments and ongoing management. This means that you can implement a zero touch provisioning solution that automatically spins up VMs, deploys Docker containers, activates service licenses and configures service chaining, updates firmware, and carries out any number of workloads you need.<\/span><\/p><h1><b>Get free resources to help you deploy zero touch provisioning<\/b><\/h1><p><span style=\"font-weight: 400;\">When you\u2019re choosing a zero touch solution, carefully consider how these drawbacks will impact your deployment and management efforts. To help you, download <\/span><a href=\"https:\/\/zpesystems.com\/the-definitive-guide-to-zero-touch-provisioning\/\"><span style=\"font-weight: 400;\">The Definitive Guide to Zero Touch Provisioning<\/span><\/a><span style=\"font-weight: 400;\">, and when you\u2019re ready to implement your solution, use our <\/span><a href=\"https:\/\/zpesystems.com\/ztp-checklist\/\"><span style=\"font-weight: 400;\">4-Step Checklist for Setting Up Zero Touch Provisioning<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p><p><span style=\"font-weight: 400;\">For regular updates to help you streamline enterprise networking, sign up for our newsletter using the form below.<\/span><\/p>","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[98,103,96,35,97,90,134],"tags":[],"class_list":["post-22718","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-logging","category-improve-network-security","category-sd-wan","category-sase","category-user-management","category-vendor-neutral-platform","category-zero-trust-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Implement Zero Trust Technologies | ZPE Systems<\/title>\n<meta name=\"description\" content=\"Cybercrime is growing, and you need to implement zero trust. Read on to discover the essential technologies to shield you from attack.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Implement Zero Trust: Technologies to Shield You From Million-Dollar Losses\" \/>\n<meta property=\"og:description\" content=\"Cybercrime is growing, and you need to implement zero trust. Read on to discover the essential technologies to shield you from attack.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-19T15:28:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-10-19T16:24:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"1600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Baker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Baker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/\",\"url\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/\",\"name\":\"How to Implement Zero Trust Technologies | ZPE Systems\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg\",\"datePublished\":\"2021-10-19T15:28:18+00:00\",\"dateModified\":\"2021-10-19T16:24:31+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\"},\"description\":\"Cybercrime is growing, and you need to implement zero trust. Read on to discover the essential technologies to shield you from attack.\",\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg\",\"width\":1620,\"height\":1080,\"caption\":\"Protection network security computer data and safe financial stability Businessman pressing and key keyword protect to protect digital business finance bank and high private technology on computer\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Improve Network Security\",\"item\":\"https:\/\/zpesystems.com\/category\/improve-network-security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Data Logging\",\"item\":\"https:\/\/zpesystems.com\/category\/improve-network-security\/data-logging\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"How to Implement Zero Trust: Technologies to Shield You From Million-Dollar Losses\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\",\"name\":\"Jordan Baker\",\"url\":\"https:\/\/zpesystems.com\/author\/jordan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How to Implement Zero Trust Technologies | ZPE Systems","description":"Cybercrime is growing, and you need to implement zero trust. Read on to discover the essential technologies to shield you from attack.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/","og_locale":"en_US","og_type":"article","og_title":"How to Implement Zero Trust: Technologies to Shield You From Million-Dollar Losses","og_description":"Cybercrime is growing, and you need to implement zero trust. Read on to discover the essential technologies to shield you from attack.","og_url":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/","og_site_name":"ZPE Systems","article_published_time":"2021-10-19T15:28:18+00:00","article_modified_time":"2021-10-19T16:24:31+00:00","og_image":[{"width":2400,"height":1600,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg","type":"image\/jpeg"}],"author":"Jordan Baker","twitter_card":"summary_large_image","twitter_image":"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg","twitter_misc":{"Written by":"Jordan Baker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/","url":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/","name":"How to Implement Zero Trust Technologies | ZPE Systems","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg","datePublished":"2021-10-19T15:28:18+00:00","dateModified":"2021-10-19T16:24:31+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567"},"description":"Cybercrime is growing, and you need to implement zero trust. Read on to discover the essential technologies to shield you from attack.","breadcrumb":{"@id":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg","width":1620,"height":1080,"caption":"Protection network security computer data and safe financial stability Businessman pressing and key keyword protect to protect digital business finance bank and high private technology on computer"},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/how-to-implement-zero-trust-technologies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"Improve Network Security","item":"https:\/\/zpesystems.com\/category\/improve-network-security\/"},{"@type":"ListItem","position":3,"name":"Data Logging","item":"https:\/\/zpesystems.com\/category\/improve-network-security\/data-logging\/"},{"@type":"ListItem","position":4,"name":"How to Implement Zero Trust: Technologies to Shield You From Million-Dollar Losses"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567","name":"Jordan Baker","url":"https:\/\/zpesystems.com\/author\/jordan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg",1620,1080,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg",1620,1080,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg",1620,1080,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-150x150.jpg",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-300x200.jpg",300,200,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-1024x683.jpg",1024,683,true],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-2048x1365.jpg",2048,1365,true],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-1080x675.jpg",1080,675,true],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-1080x720.jpg",1080,720,true],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security.jpg",1620,1080,false],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-1280x853.jpg",1080,720,true],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-980x653.jpg",827,551,true],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2021\/10\/Network-Security-480x320.jpg",405,270,true]},"rttpg_author":{"display_name":"Jordan Baker","author_link":"https:\/\/zpesystems.com\/author\/jordan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/data-logging\/\" rel=\"category tag\">Data Logging<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/\" rel=\"category tag\">Improve Network Security<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/sd-wan\/\" rel=\"category tag\">SD-WAN<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/sase\/\" rel=\"category tag\">Secure Access Service Edge (SASE)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/user-management\/\" rel=\"category tag\">User Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/simplify-branch-infrastructure\/vendor-neutral-platform\/\" rel=\"category tag\">Vendor Neutral Platform<\/a> <a href=\"https:\/\/zpesystems.com\/category\/zero-trust-security\/\" rel=\"category tag\">Zero Trust Security<\/a>","rttpg_excerpt":"How to implement zero trust security is a growing focus of organizations across the globe. With cyber attacks frequently hitting some of the largest companies and threatening entire economies, it\u2019s no wonder why comprehensive network security is a top priority among public- and private-sector entities. In this post, we\u2019ll show you what you need to&hellip;","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/22718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=22718"}],"version-history":[{"count":8,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/22718\/revisions"}],"predecessor-version":[{"id":22733,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/22718\/revisions\/22733"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/22730"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=22718"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=22718"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=22718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}