All briefings
Zero Trust

Zero Trust starts with discovery and prioritisation

By Marcin Pajdzik ·

Zero Trust is a security strategy for protecting business services and data through explicit, least-privilege access decisions informed by identity, device health and context. Access is reassessed as risk and context change. Discovery establishes where applying that strategy will reduce business risk and what organisational and technical changes it requires.

Two questions discovery has to answer

Discovery has to establish where the organisation stands today, and where a gap would cause the most harm.

The first question is answered by a maturity baseline. It follows Epitechnic's nine-area assessment structure, covering identity, devices, networks, applications, workloads and data, together with monitoring, automation and governance. The structure is mapped to the five pillars and three cross-cutting capabilities of the CISA Zero Trust Maturity Model and to the architecture principles in NIST SP 800-207. Using recognised models gives leadership a consistent structure for assessing progress and challenging investment priorities.

A baseline on its own produces a list of gaps. A large estate can have weaknesses in every area, and the list gives no reason to address one before another. A criticality assessment identifies where compromise would cause the greatest business harm, providing a starting point for prioritisation.

Criticality in business terms

A criticality assessment rates each service by the harm its compromise would cause, scored separately for confidentiality, integrity and availability. A service holding personal records may tolerate an hour of downtime, while a production scheduling system may hold nothing confidential and still halt operations when it stops. Scoring the three dimensions separately keeps those differences visible.

The ratings use the organisation's own impact scale, the one its enterprise risk framework already applies to operations and customers, finance, legal and regulatory exposure, reputation and people. Each service is rated against the worst plausible outcome, including the effects on dependent services and business operations, so the rating measures consequence and leaves likelihood to the risk assessment that follows. The accountable business owner validates the impact rating and its assumptions. Each rating is summarised in business language, so an executive can see why a service matters without reading the technical detail.

Applied consistently, the same scale produces ratings that can be compared across the estate. Comparable ratings turn a collection of assessments into a ranking, and give the board a basis for investment it can test against its own risk appetite.

From ranking to roadmap

Criticality sets the anchor for sequencing. The roadmap then weighs it against the exposure of each service, the sensitivity of the data involved, the regulatory drivers that require or constrain change, the dependencies a change would affect, and the engineering effort needed to bring the service under Zero Trust controls.

For the highest-ranked services, discovery combines traffic observed over a representative period with identity and access records, then validates dependencies and access needs with service owners. Access rules designed from that evidence can be limited to what the business needs, and a planned change can be checked against real dependencies before it goes live.

The first pilot should address a meaningful business risk within a manageable scope, with clear success measures and a controlled rollout. It tests the method end to end, produces artefacts that later services can reuse, and gives a measured effort figure that informs estimates for similar deployments.

Discovery also tests how far the organisation's existing identity, network and monitoring investments can go once configured and governed to the target state. Where they can close a gap, the roadmap can sequence that work ahead of any new purchase.

What the board receives

A Zero Trust Discovery and Roadmap delivers a maturity assessment across those nine areas, priority use cases grounded in business risk, the target capability and operating model implications, and a phased roadmap with investment priorities. Criticality runs through all four, so the roadmap explains each priority in terms of the harm it reduces. The roadmap identifies accountable owners, how access exceptions will be governed, and how progress will be measured through reduced exposure and continued service performance.

With those outputs the board can approve the priorities, the first phase of investment and which existing investments to bring up to standard before buying anything new. The lateral movement case study shows the approach applied to the finance segment of a global logistics business. To discuss discovery for your organisation, request a Zero Trust discovery.

References

  • Cybersecurity and Infrastructure Security Agency, Zero Trust Maturity Model, Version 2.0, April 2023.
  • National Institute of Standards and Technology, Special Publication 800-207, Zero Trust Architecture, August 2020.
Start the conversation

Facing this in your organisation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.