Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Does Zero Trust Mean Defence In Depth Is Dead?
Articles

Does Zero Trust Mean Defence In Depth Is Dead?

Phil RobinsonBy Phil RobinsonJune 15, 2022Updated:October 1, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Flash Zero Day vulnerabilities
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Is Defence in Depth still relevant now that the concept of Zero Trust has taken hold? That was the question a colleague asked me recently on a webinar and it got me thinking if one has replaced the other and whether these strategies are mutually exclusive. It’s a complex question because there are pluses and minuses to both approaches.

Defence in Depth (DiD) has been around for decades and there are those that argue the strategy has failed. They point to the bloated cyber security stack of up to 70 solutions now found in the average enterprise and the seemingly unchecked onslaught of attacks over those years. Add to that the evaporation of the network perimeter in a hybrid workforce and the increase in consumption of cloud services, and it’s easy to see why some question the relevance of this framework.

DiD works by using a layered approach to security which effectively buys response time. The theory is that even if a threat actor gets past the initial defence, another security control will likely identify, slow or mitigate the attack, effectively plugging the gap. It can accommodate the needs of the organisation as more layers can be applied to areas deemed high risk but it makes two big assumptions. Firstly, that you have ownership and control over the network and secondly that an attack will originate externally which means that all users within the network are trusted.

Pandemonium

These two issues became all too apparent during the pandemic when we saw mass migration to the cloud to facilitate remote working. Now the users were outside the network, attempting to get in, but so too were the threat actors. Those legitimate users were afforded little protection so could easily be exploited and their credentials used to bypass security mechanisms. As a result, the attack surface had expanded overnight, and it was open season on network defences.

Beleaguered businesses looked at their security arsenals with fresh eyes. Suddenly the point solutions which they had overlapped to improve defences, seemed inadequate because they couldn’t integrate with one another or provide the visibility needed within the cloud. There was a growing realisation of how resource intensive monitoring these systems can be, often resulting in alert fatigue and high staff turnover, causing many teams to seek to either scale back their cyber stack or to limit the number of vendors they use.

Suddenly Zero Trust, a term which was actually conceived back in 2010 (but actually with earlier initiatives such as “deperimeterisation” championed by organisations such as the Jericho Forum) became the hero of the hour. It’s ideal for the modern hybrid environment as it can encapsulate entities, network or data objects and effectively protect remote users and the protection of cloud-based assets. The mantra of the zero trust approach is “never trust, always verify” so that in a Zero Trust Architecture (ZTA) every access request is regarded as potentially hostile and so needs to be authenticated, authorised and continually validated.

Zero tolerance

One of the criticisms of the approach, however, is that it can cause too much friction, exacerbating users. It’s ideal for pureplay cloud businesses that use SaaS but becomes more difficult to implement for those with legacy systems. This can be remedied through approaches such as Just In Time (JIT) protocols that provide the user with temporary access usually via ephemeral certificates which are issued instantaneously and act as self-destructing security tokens. But there’s no getting away from the fact that for most organisations, moving to a zero trust approach will require significant planning.

Recognising this, the National Institute of Standards and Technology (NIST) has just published its  Planning for a Zero Trust Architecture: A Guide for Federal Administrators, whitepaper which aims to provide Federal enterprise admins, system operators, and IT security officers with a blueprint for migrating to a zero-trust architecture using the NIST Risk Management Framework (RMF). Based on NIST SP 800-207 ZTA Roadmap, it’s just as applicable to other organisations, however, and emphasises the need for a phased approach which begins with identifying which tools are compatible with its ZTA and the need to involve cybersecurity planners, management, administrators, and operations.

Mutually exclusive

The consensus is that the adoption of ZTA can be gradual and this means that many organisations will continue to rely upon DiD. Which brings us back to our original question: Can both strategies co-exist? It could be argued that Zero Trust is in fact part of DiD, in that it governs access while DiD protects the data, through encryption and segregation, for example.

DiD has also seen vendors build-out security solutions with features that can help implement Zero Trust. The Zero Trust approach embodies the concept of least privilege, with access typically limited by role, but what happens if a user, when granted access, then begins to deviate from their usual working pattern or to attempt to exfiltrate data? It’s here where a behaviour analysis solution, can help, spotting and flagging the anomalous activity enabling access to be terminated, effectively resolving the insider threat problem.

I would also argue that policies, procedures, security awareness training and robust physical security measures would all form part of an effective DiD strategy to govern and drive resilient user behaviour and to protect assets such as mobile endpoints. I cannot foresee many organisations starting to neglect those areas just because they have implemented a ZTA solution. 

There’s no doubt that we are moving to ZTA and it’s an approach that promises to better protect our distributed workforces and businesses. But, realistically, teams are going to want to amortise their existing investments so we need to look at how the transition can be made smoothly by utilising existing tools and in a way that doesn’t expose the flank of the enterprise. To do that, we’re going to need to consider ZTA as part of an effective DiD for some time to come.

Phil Robinson

Phil Robinson has worked in information security for over 25 years and is the founder of Prism Infosec which offers cutting edge penetration testing, red teaming and security consultancy services of cloud and traditional on-prem architectures and enterprise applications. Phil has been instrumental in the development of numerous penetration testing standards and certifications. He was involved in the original formation of the Council for Registered Ethical Security Testers (CREST), chaired the management committee of the Tiger scheme and established key CESG Certified Professional (CCP) roles on behalf of the British Computer Society (BCS), and has also contributed toward the Open Source Testing and Security Manual (OSSTMM). An Associated Member of the ISSA, an (ISC)2 CISSP, ISACA CISA and a CHECK Team Leader, Phil has worked as a CLAS Consultant / Senior CCP Security and Information Risk Advisor and in this capacity has delivered cybersecurity advice and guidance to HMG departments and agencies. He regularly speaks about penetration testing and e-crime to help promote cybersecurity awareness and industry best practice.

  • Phil Robinson
    Does Zero Trust mean Defence in Depth is dead?

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}