Evento di Lancio: Smart AI Security. Controllo Totale dei Dati. Prenota il tuo posto

chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
Securing Generative AI for Dummies
Securing Generative AI for Dummies
Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

The UK’s NCSC Cyber Essentials Zero Trust Update: Explained

Feb 07 2023

Late in January this year, the UK’s National Cyber Security Centre announced an update to its Cyber Essentials scheme in order to ensure it “continues to help UK organisations guard against the most common cyber threats”. This year’s update isn’t an overhaul on the same scale as last year’s, but it did include important new guidance about zero trust architectures. You can see more detail here, but in essence, the April 2023 updates confirm that Cyber Essentials certification requirements are completely aligned with a zero trust architecture (as understood and explained by the NCSC here.) 

Why Change?

I was particularly pleased to see this update, and the language that explains the rationale for supporting a zero trust architectural approach is notable:

“…many organisations are embracing flexible working, which means lots of different device types may connect to your systems from many locations….it’s also increasingly common for organisations to share data with their partners and guest users, which requires more granular access control policies….Zero trust architecture is designed to cope with these changing conditions by enabling an improved user experience for remote access and data sharing.”

NIST defines zero trust as: “ the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources.”

Why Now?

Gartner currently estimates that just 10% of large enterprises will have a mature and measurable zero-trust programme in place by 2026—that’s only an increase of 1% compared to today. And Gartner VP John Watts explains why zero trust is important:

“Many organisations established their infrastructure with implicit rather than explicit trust models to ease access and operations for workers and workloads. Attackers abuse this implicit trust in infrastructure to establish malware and then move laterally to achieve their objectives”.

This implicit trust is prevalent, with many organisations designing exceptions within their security policy for “trusted” cloud applications such as Microsoft 365. They often do this when their legacy security architecture causes user experience problems when it relies on physical appliances and long-winded routing maps. I posted about this last year, and the Netskope Threat Lab’s annual report proved my point when it showed that in 2022, 30% of all cloud malware downloads originated from Microsoft OneDrive. We should never implicitly trust applications, users or network connections when designing security policy. 

And yet “zero trust” isn’t a panacea either—in fact Gartner makes it clear that those ever innovative cyber criminals are setting their eyes on targets that are not (or cannot be) covered by zero trust controls. However, as part of a robust security strategy, technology solutions such as zero trust network access (ZTNA) are certainly some of the most useful tools that security professionals can start to implement today. 

Why Netskope?

Netskope holds the NCSC’s advanced “Cyber Essentials Plus” certification, so we know these guidelines and know what is required to comply. On top of that, we happen to be world experts in zero trust—handy.

Netskope helps organisations deliver zero trust across all four transformation stages of networking, security, applications, and data with a unified SASE-ready security service edge (SSE) platform. We do this by enabling context-driven, correctly-privileged access to both private and public applications.

We get excellent feedback from our customers (click the link and search for “zero trust” feedback). Here are a few examples:

  • “Netskope is playing a significant role in our organisation reaching our zero-trust security goals”
  • “Netskope is an important step towards zero trust for our company”
  • “Netskope allows for the enablement of our Zero Trust strategy”

We would love to have a conversation with you about how we can support your efforts to implement zero trust, or achieve Cyber Essentials certification. Take a look at our eBook; How to Apply Zero Trust Principles the Right Way, for more thoughts on this.

author image
Neil Thacker
Neil Thacker is a veteran information security professional and a data protection and privacy expert well-versed in the European Union GDPR.
Neil Thacker is a veteran information security professional and a data protection and privacy expert well-versed in the European Union GDPR.
Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.