Zero Trust Strategy – Anudeep Parhar, Entrust
Anudeep Parhar, COO at Entrust, shares experiences in leading zero trust strategies across the organization, suppliers and business leadership. While security teams know the importance of Zero Trust, getting to a Zero Trust framework is a multi-year project, one that requires trusted partners, and the entire organization, to build your framework on a solid foundation.
Transcript
This is techstrong tv, But the great pleasure of being joined by Anad Pahar, who is c o o at Entrust. Welcome aep. Thank you, Mitch.
It's, it's a pleasure to be on the show and look forward to speaking about, uh, some of the topics on, on top of mind. Yeah, I'm excited to, to get into it. Cause we're gonna talk about some, uh, you know, what we're learning about implementing Zero Trust.
I'm always anxious to get into that, but I want to give you a chance, please introduce yourself, tell us a little bit about you and tell us about Entrust. Absolutely. Uh, so my name is an Pahar, as you mentioned, uh, the Chief Operating Officer at Entrust and Entrust is, uh, you know, we are, we are a cybersecurity firm, which, uh, deals with securing payments identities and providing infrastructure so we can secure your enterprises.
And we've been in business for a very long time. Uh, and we have secured both physical and digital assets for industries of all kinds. And, uh, I have been with, with interest for about seven years now, and it's been, it's been a pleasure.
We've built a really good business and it's a really exciting business. I'm still, still, uh, cannot pay to get to work every day, so it's, it's a fun place to be. Uh, but as a a, my personal background, I'm, I'm a technologist by trade and training.
This is, uh, essentially the only scale I have. Uh, but I'm a business person, my profession. So I've been on both ends of building and selling software as well as selling, uh, buying, printing software for, for organizations of various sizes and geographies.
So, so that's, that's what I do. I'm a similar kind of background. I think that brings a unique perspective when you've actually, I've actually bought my own products that I've created one case.
So, but, uh, it, It's a, it is an interesting and unfortunate place to be when, uh, the profile of my buyers, uh, I, I represent the company that builds technology for people who, who, who are pink, who are in my roles. The buyers are my personal. So it's a unique position to be in.
Definitely, uh, much easier to relate what's happening in your customer's world. Well, speaking of that, so, um, you know, we're very much on this Zero Trust journey. I think when it started, we all weren't sure if it was just another Gartner category or is it, what is it?
And kind of, people have grappled with that, but I sense that a lot more folks have really kind engaged in starting on that. But it's not a feature to turn on your router. It's not a, if we add this, you know, here's the policy now we're zero trust.
It's really a multi-pronged, probably multi-year strategy. I'd love to hear your experiences about where, where you see customers are engaging on that, uh, that path. Absolutely.
And I'll start with what you mentioned in, you know, like all of these terms that become, you know, these are acronyms that, that, that, that are euphemisms for, you know, like you mentioned, for analysts to start pushing a particular way of doing it. Uh, so it's been zero trust, the moniker has been around for a while. It has gone through a, without would say, a reasonable maturity in terms of specifics of what to do and also what benefits are.
Mm-hmm. Uh, you know, what, why would somebody want to do this? So lemme sort of start with where the, why would somebody want to think about Zero Trust, which is as a moniker, it's, it's a very, it's a anab patent monitor.
The whole world is built on trust, and here we're saying zero trust. So it's not about no trust, it's basically saying that the traditional mechanism of establishing and assigning trusts are not valid anymore. So, so let me, let, let me explain that more simply.
Uh, you know, all IT networks, any organization, say, let's take a look at, so the demarcation of cope before cope largely, uh, the last 10 to 15 to 20 years. Organizations, enterprises have been networks, which is per, uh, which is a, you know, some of the military terms in terms of saying, establish the perimeter, protect the perimeter, don't let anybody in. But the fundamental assumption there is that anything that you care about is within the perimeter.
And also that nobody, nobody can get in. That's prevention. Stopping is your, is your key strategy.
Now, now it's been happening for a while post Covid or during Covid. Uh, it accelerated where the perimeter, so to speak, dissolved. You know, all of us are working from home, we are working from remote locations.
So the perimeter is wherever the user, wherever your endpoint, where your machine, where your, where your, uh, device is. And with that, what's happened is that the, the idea of trust, the traditional idea of who is allowed access to what is, is not valid, which means is just because you're in corporate network doesn't mean you should have access to airplane because of the, the set issues. com, your marketing automation, all of these softwares are running in a public cloud, which is not part of your perimeter.
So new new paradigms have to start existing in terms of saying, how do you assign trust for both authentication as well as authorization? So that's sort of how it started a few years ago when Zero Trust started taking prevalence in, in a post world. So essentially comes on with the basic principles that, uh, that the Zero trust paradigm is based on is always trust, never, always verify, never trust.
Mm-hmm. So essentially keep verifying, uh, just because you carry particular device or you are on a particular note, but shouldn't give you Right. The set application.
Second thing is, uh, is context based authentication. To be able to say that it's not just where you are accessing it from or how you're accessing the patterns of accessing are important as well. You know, because of remote nature of work, bring your own device.
You can access corporate networks from our corporate assets, from your own home devices and from a hotel wifi network. Mm-hmm. Uh, so, so the, the trust is a little different.
The last thing is just because of the, you know, the increased activity in and the business benefit that the threat actors are getting from hack or, or, or doing, uh, events in organizations, just the business benefit for them. You see the, the sheer scale and the number of incidents have gone by up. So there is incentive for bad people that actually try to get into people's networks.
And with the, the trust that existed, you know, the, the actual damage, both in terms of just commercial damage to organizations, reputational damage and just downtime, you know, in organizations have been obliterated because they have been, uh, they have been, uh, hacked or unauthorized access has been done, ransomware, et cetera. So all of that, the concept of trust changes. So the last thing that, uh, the principle that that zero trust says is assume that you've been breached.
So your behavior, IT organizations should organize their thinking, their technology, their processes, purely from a point of view saying, assume that the FAT act is inside your perimeter. How do you stop natural movement? How do you minimize the damage which has led to this new concept of cyber resilience?
We're saying zero trust enables building resilience, infrastructure and architecture is, and interest, of course, you know, being the business of vbm, uh, we provide the technology as well as the services that enable, uh, application of zero trust. So I'll stop there and turn it back to you. Hopefully that gives, give some color to I think it does.
That's that's awesome. And I think about, you know, you mentioned covid. I think even just, uh, the acceleration from that time of things like cloud native software, architectures, essentially more porous application services and APIs being used, all, you know, across applications and kind of the network is now all the way to the app microservice level.
So everything we talk about in those, the idea of, I'm gonna protect this and you can't get into it, and we're okay if we're behind whatever that protection is, now, everything can be breached, right? Everything will be a assume it will be breached at some point. So how do you protect, how do you react also when that happens in that world?
I'm curious your perspective, because it's not just a technology, right? It's, it's kind of an ecosystem of internally, whether it's senior, um, senior levels of support, you know, into your kind of engineering and, and security teams, but also ecosystem, ecosystem of vendors, partners, you know, like entrust folks like that. It, it is a multi-pronged strategy you've gotta take That's absolutely right.
Given sort of how the concept has evolved, and especially people who are not in the technology roles or information technology roles, CIO ceases, usually they, they, because of the line, the line of business they represent, they understand these concepts. But because this is an additive to increasing budgets, this is additive to increasing con uh, existing controls. Uh, you need more, uh, in a senior leadership or executive leadership sponsorship, you need people to understand, you need audit committees of your board, your cyber risk committees to understand why this is a issue and why we need to, uh, need to put some of these controls in place.
And usually that goes back to both an education, you know, CSOs and CIOs need to put active work into educating their board, the senior leadership teams, not from a threat marketing point of view. It just not saying, Hey, if you don't do this, you're gonna lose your business. It's more around saying having a a, a more mature or robust cybersecurity posture in this day and age, especially in these economic circumstances, is an essential growth enable it.
I almost could extent of saying just like look at concepts like D E I and E S G as growth enablers, not just tax on a corporation. You know, there is a lot of organizations that want business with you if you don't have a high enough side press posture. So the CIO c doesn't need to start that education, but the senior leadership teams, their boards so that there is support that this is an essential growth enabler.
And then, then go down the organization to build a zero trust mindset. So you can do that at entrust. Those are the, the kinds of things that we have done with our board.
We are quite proud that, uh, you know, that our board as well as our senior leadership team actually understands some, supports us very well. We, you think about both software and just everything, all the technology role that plays in our business is the digitization of business. Yes.
Correct. It, it, it is enabler cuz it's definitely gonna be a disabler if, if it's not addressed. Where do you, where do you find customers are in this, in this journey, in this process?
Um, do they see benefits pretty quickly as they start to engage and think about identity differently and how to, how to secure things so that, uh, assuming things will get breached? What's, what's that like from your customer standpoint? I think it's, uh, you know, it depends.
It's not, not not as crisp answered as I would like. Uh, but that sort of lends itself to that. This is not a project.
Zero trust is not a project, it's not a task, it's not, it's the traditional project management controls, not here. This is a maturity model. Mm-hmm.
Uh, which I really like that, uh, because that sort of beats the customer where they are. It meets an organization where the organization is, it is not a step one to 10. You have to do all of them.
You have to measure your less caution. You have to understand the risk appetite, work with the, with your leadership team to figure that out and get to sort of figure out what controls you should put in place. There is something, so to speak for everyone.
And as your investment, as your posture allows, cause your business allowed, you can keep going up that shift curve. So, so that's sort of how you look at it. Even as recently, you know, the, the, the federal agency here, the Csaw Agency, which is the, the, you know, which publishes a lot of these, uh, maturity models and controls for the federal government, has published a really good maturity model for zero Trust.
Which essentially to your point says, and I'm, I'm paraphrasing, is that it's more than just access and authorization. It's not all about who should have access to when and what. It's also around the resilience of saying you should be encrypting your key data stores.
Uh, because once you assume breach, even if the threat act has gotten past your, uh, your access and authorization mechanism, at least your current jewels or your key databases are secure and encrypted. Uh, with, with, with, with, with reasonable higher shortage technology. And then if you go further, there is also things like in in, in more, uh, assure organizations where you are moving towards phishing resistant, uh, uh, authentication and, and access control.
For example, multifactor authentication is very well understood. Everybody gets it that this is an essential way of stopping and auth, stopping phish attacks and understanding how the access is controlled. But the bad actors have got past that as well.
We were recently at the RSA show in San Francisco and e if I was to count how many times be heard hackable mfa, it was really interesting. You know, you, I've done this long enough that multifactor authentication was considered sort of the holy grail. Once you do that, that path a lot of issues.
But at this business we have been able to breach and, and, and break that as well. So we are moving towards, or are asking our customers more mature customers to move towards what is called certificate based authentication, which means is it's not only who you are to control access, but also from where I, which device, if you're accessing, if an asset that you don't want to be accessed from any device using high assurance certificates, you can control access. Uh, so there are some, you know, mechanisms for that.
But generally speak from an industry perspective. I think like all products, there are, uh, there are early adopters in this particular case, uh, you know, financial institutions and any, any businesses or industries with a higher, uh, regulatory obligation. Those are the early adopters.
Those go first. A second is large organizations, your Fortune, you know, uh, uh, fortune 1000, fortune 500 organizations who have uh, uh, higher risk, uh, partial as well. And you know, they go this first.
Uh, and with the newer technology, especially if you see a lot of this technology and processes are available as a service hub, it is increasingly becoming that even smaller organizations can start consuming design service. But generally speaking, from a maturity perspective, you see, you know, financial institutions, uh, large governments and mid-size governments, as well as any organization that is, uh, uh, that has higher regular Tokyo obligations. Those go first.
Well, last we were, we have a few minutes left. I'd love to give your perspective. I host a show called CISO Talk, and one of the things we, we discuss a lot is the changing role of the CISO and how much communication with the board, with even investors as well as internally, has really changed that role.
And I think Zero Trust is part of the reason why that's changed because of its effect on the organization. Do you see the same thing? Yes, absolutely.
You know, some of the, you know, we live in fortunate times where the, uh, you know, even in my lifespan, we've seen the both of the internet, the birther programming languages, the cloud, now we are in, in the age of zero trust and artificial intelligence and everything is, is scaling at at an amazing pace. And given this, the way I look at it is some new technology, uh, uh, unfortunately it is, it is democratized for every, for both good and bad. Mm-hmm.
And essentially good and bad actors and essentially organizations and CSOs have to both take an offensive approach as well as a defensive approach, which increasingly becomes, uh, uh, a different role for, uh, you and upcoming c c uh, CSOs. Because traditionally it was more of defensive, but now you've taken goal to figure out how you enable growth with some of these technologies rather than just trying to protect what you have. So certainly it's changing quite a bit, uh, as we go forward with the roles of CIOs and CSOs.
Fantastic. Kennedy Davidson been great talking with you. Um, so I know you do obviously, uh, entrust does a ton of work in this area and well-respected, uh, long-standing, uh, company and partner.
Uh, are there some assets or good information places people can go to kinda learn more about some of the thinking around Zero Trust and other things that are happening at Entrust? Certainly. Uh, and this is a good place for me to plug our Interest Cybersecurity Institute.
So we, we formed this about, about a year and a half, two years ago with the explicit intent when you are just in middle of Covid coming out to educate our stakeholders internal and external. This is a neutral environment. This is not just a talk about our products, uh, but I would recommend, uh, your audience go to Interest Cybersecurity Institute and learn about AR zero trust, all the other things post quantum artificial intelligence, how this is gonna change.
Uh, there is both written materials as well as art in video podcasts. Wonderful. We'll includes some of those links in the description for the video, uh, on deep.
It's been fantastic. Thank you for joining us an Pahar c o o with interest. I hope you come back again soon.
Certainly. Well, it's, it's a pleasure. Thank you.
Thank you.