Thank you for Subscribing to Telecom Business Review Weekly Brief

Tackling a Changing Threat Landscape: Zero Trust and Network Edge Security


The world we live in is fuelled by innovation and transformation. We are striving to achieve more and push the boundaries of what is possible. Technology and connectivity are enabling us to do this, from sweeping productivity improvements to enhanced efficiency. There is almost no part of our lives or industry that is untouched by connectivity in some form. However, as we continue to see mobile networks become more widespread, with the growth in connected devices and IoT, this in turn is changing the threat landscape for businesses and people. What once meant focusing on securing the physical office perimeter, has now become more complex, with a wider range of threats and a growing attack surface. As connectivity becomes more integrated, this is an issue that business leaders need to tackle with utmost priority.
IoT, 5G, and Network Edge The challenge is that mobile networks are becoming more open and pervasive, to enable IoT, network edge, and 5G applications. Many of these connected devices and applications are often built using APIs, and as workloads continue to shift toward the cloud, we are seeing a growing attack surface and an increased risk of cyber-attacks. Nowadays most of the deployed API-based applications rely on public or mobile internet as the main data transport. This creates the potential for a multi-fold increase in cyber-attacks on vulnerable IoT end points and API clients, permeating beyond the enterprise perimeter control. This is a challenge that is only going to grow as IoT projects intensify and become more critical. IoT has rapidly become one of the fastest growing categories of devices within modern enterprises, with IDC estimating 55.7 billion connected IoT devices by 2025. From smart cities, smart farms, and smart factories, the envisioned IoT world is filled with a plethora of fascinating opportunities. IoT can mean billions of devices communicating with each other every day and sharing data, to empower new use cases, possibilities, and more efficient and safer ways to work, live, and socialise. This is a trend that will continue to rise with the role of edge cloud and 5G, bringing room for more innovation and potential new applications. Today, IoT devices are already becoming integral to business processes and projects are shifting beyond what was once low-bandwidth massive IoT applications, such as smart meters and asset tracking, toward more advanced use cases with larger data volumes, requiring higher throughput and lower latency. Endpoint management and a growing attack surface In a truly borderless world, IoT means a heavy reliance on remotely deployed and mobile devices – all of this represents a vast virtual expansion of the enterprise network perimeter. Therefore, businesses are becoming more exposed to a broader attack surface that hackers and criminals can exploit. IoT devices have unique characteristics that are more nuanced than the traditional devices that a typical organisation might expect to manage. These types of devices often have limited processing power and storage, and may have proprietary operating systems, real-time operating systems, or may use a pared down version of Windows on Linux. In turn, devices may also be unable to support client-based security software models. Enterprises often have limited options for enforcing security and have zero visibility on the performance and behaviour of the device. This is a challenge that more businesses are quickly becoming aware of. In fact, a survey conducted by Analysys Mason in 2022 found that 72 percent of global enterprises cited security concerns as the biggest challenge regarding the deployment of IoT. Enter Zero Trust and a network edge approach While endpoint enforced security and a cloud-based approach bring some benefits, this alone won’t cut it. Endpoint security means installing an agent on each physical device to identify, encrypt, and authenticate. However, a device-based approach does not protect against vulnerabilities that exist in the data in motion path. Likewise, with the cloud, this would also require deployment of an agent on each device and necessitate that all the enterprise traffic be directed towards a specific cloud environment. The problem with this approach is that all traffic from the connected endpoints traverses the public internet, thus exposing it to vulnerabilities and security threats as it hops from each mobile network operator to the cloud to the organisation’s server. Simply put, the traditional security solutions are not enough. However, by adopting a network approach and underpinning this with a Zero Trust policy, organisations can significantly bolster their security and minimise any threats. The zero-trust framework offers a holistic approach and has a vast range of security benefits, while a network edge approach offers an agentless solution with zero footprint on user devices. This combination makes for a winning approach when it comes to getting to grips with the growth of IoT. Let’s look at some of the core benefits: Benefits of zero trust: ● Authorization for each and every use – limiting user access to show only what is needed ● Zero trust fabric makes endpoints ‘invisible’ to the Internet, while encrypting data in motion ● Endpoints only have access to the specific services which the organization’s policy permits Benefits of network edge security solutions: ● Act as the first line of defense for enterprise’s core network ● Agentless, zero touch deployment ● No impact on device performance, as it does not consume end device resources ● Keeps the traffic end-to-end private ● Lower latency, for better application performance ● Threat prevention for data in motion ● No added exposure to vulnerabilities and malicious threat actors A network edge security approach is easier to manage and more robust, as it doesn’t need to be physically managed through each device. It is also advisable to apply an additional layer of security, employing the concept of zero trust. This enables additional layers of security, by enforcing the principle of Least Privileged Access, meaning that no user can access authorised data. One of the most dangerous cyber breaches is when an attacker breaks through and can compromise the entire system, but a Zero Trust approach prevents lateral network movement helping to safeguard data and limit the damage of any breach stopping it in its tracks. By applying this multi-layer approach to cyber-security efforts, enterprises can grow and transform with the confidence that their applications are secured against cyber-attacks.