{"id":14196,"date":"2022-04-25T15:41:33","date_gmt":"2022-04-25T14:41:33","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/2022\/04\/25\/eight-guiding-principles-for-zero-trust-in-banking-and-financial-services-today\/"},"modified":"2023-05-25T12:02:44","modified_gmt":"2023-05-25T11:02:44","slug":"eight-guiding-principles-for-zero-trust-in-banking-and-financial-services-today","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2022\/04\/25\/eight-guiding-principles-for-zero-trust-in-banking-and-financial-services-today\/","title":{"rendered":"Eight guiding principles for Zero Trust in banking and financial services today"},"content":{"rendered":"\n<p><em>Security leaders will be familiar with the term &#8216;Zero Trust&#8217; &#8211; an approach crucial as vulnerabilities and attacks are becoming more damaging to organisations. Hila Meller, BT Vice President Security, Americas, EMEA and APAC, discusses some of the guiding principles for Zero Trust in banking and financial services. <\/em><\/p>\n\n\n\n<p>When it comes to adopting a Zero Trust approach, many organisations in the financial services sector already have most of the constituent parts required. In fact, we estimate organisations already have between 60%-80% of the security building blocks that banking and financial services organisations need to adopt a Zero Trust approach. But moving from existing approaches to a new security model is a challenge. What needs to come next is a change of stance and a unification process to protect the business as it evolves.<\/p>\n\n\n\n<p>In the following whitepaper, <a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__www.globalservices.bt.com_en_insights_whitepapers_why-2Dyou-2Dneed-2Dto-2Dturbo-2Dcharge-2Dyour-2Dzero-2Dtrust-2Djourney&amp;d=DwMFAw&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=an5Q-c1TF26QV9xfmzBlkeQ6mM4UdqYNphA42PAtre0&amp;m=w6oxfCrdv531QejVLWkeYEWX1e9-4Wk7hAqmM_bG2G4&amp;s=_9FO1i1aScJ8_lQjJOmdZ1RHgfyiD1xVFE_wJJ3NURo&amp;e=\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Why you need to turbo-charge your Zero Trust journey<\/em><\/a>, we identify eight guiding principles for Zero Trust in banking and financial services.<\/p>\n\n\n\n<p><strong>#1 Identify your goal and pull it through your planning<\/strong><\/p>\n\n\n\n<p>Form your security strategy around the fundamental assumption that you will always be operating a dynamic network in a hostile environment. Centre your thinking around how you can best use automated processes to create security rules that change dynamically in response to context. But remember that automating a broken process is a swift route to failure; make sure you\u2019re training your AI to make correct decisions about risk so it can automate the appropriate response.<\/p>\n\n\n\n<p><strong>#2 Assess existing capability before investing in more<\/strong><\/p>\n\n\n\n<p>Don\u2019t rush to spend money on \u2018Zero Trust\u2019 point products because you may be duplicating capability or investing in areas that aren\u2019t a priority for your organisation. Instead, optimise the value you already have in your security estate by establishing what latent capabilities you possess. For example, layer one, two and three segmentations along with very narrow access lists could be a fruitful first step on your Zero Trust journey.<\/p>\n\n\n\n<p><strong>#3 Focus on removing peer-to-peer protocols<\/strong><\/p>\n\n\n\n<p>Segmentation is your key defence in a Zero Trust environment, but you won\u2019t be able to segment your network if you\u2019re running peer-to-peer protocols. A vital part of any attacker\u2019s kill chain is the ability to pivot from one host to another, but if you limit their ability to move easily, then you neutralise entire classes of attack. Think about how 5G architectures cut out peer-to-peer connections, forcing every call to go through a central gateway \u2013 this model should be your aim.<\/p>\n\n\n\n<p><strong>#4 Control access to core assets<\/strong><\/p>\n\n\n\n<p>Leverage your security investments to secure your cloud and data centre servers, using Zero Trust segmentation to coordinate traffic authorisations across your estate. This needs to be universal so it\u2019s as watertight as possible and servers only accept traffic sent by authorised users. Consider investing in red teaming ethical hacking exercises to check the security of your key assets.<\/p>\n\n\n\n<p><strong>#5 Incorporate user identification<\/strong><\/p>\n\n\n\n<p>Limit your exposure to risks by only opening ports in your environment when they\u2019re needed. Make user identity the first key to access your systems and make sure permissions are revoked as soon as the user logs out.<\/p>\n\n\n\n<p><strong>#6 Build in security-by-design to your projects<\/strong><\/p>\n\n\n\n<p>Investigate how containerisation can be a springboard for your security DevOps, providing a pre-certified and pre-configured software \u2018container\u2019 that you can build on to create automation and machine-to-machine application service models. Containerisation is an ideal opportunity to leave waterfall cycles of patching behind, offering instead security that flexes with context.<\/p>\n\n\n\n<p><strong>#7 Segment, segment, segment<\/strong><\/p>\n\n\n\n<p>Introduce micro-segmentation to segregate \u2013 and protect \u2013 your network at a granular workload level. This will give you the real-time visibility you need as you monitor application behaviour and connections to understand what is talking to what and to identify risks. It will also give you the level of control you need to improve your breach containment, preventing lateral movement and reducing the blast radius of any attack.<\/p>\n\n\n\n<p><strong>#8 Activate your human firewall<\/strong><\/p>\n\n\n\n<p>Remember the user in all this and make it easy to do the right thing and hard to do the wrong thing. Educating and motivating your workforce to follow protocols and stay vigilant against potential attacks is just as important as any other aspect of your Zero Trust security journey.<\/p>\n\n\n\n<p>When you\u2019re operating in an environment that\u2019s constantly shifting in ways that open up new vulnerabilities, adopting a Zero Trust approach is essential. Getting it right is about extracting and extending value from your existing investments rather than jumping straight into new ones. Once you\u2019ve identified latent capabilities that you can leverage immediately, employing these eight principles will alleviate the challenges of moving to a new security model.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security leaders will be familiar with the term &#8216;Zero Trust&#8217; &#8211; an approach crucial as vulnerabilities and attacks are becoming more damaging to organisations. Hila Meller, BT Vice President Security, Americas, EMEA and APAC, discusses some of the guiding principles for Zero Trust in banking and financial services. When it comes to adopting a Zero [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":19798,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,17,1645,42,43],"tags":[859,114,1845,364],"class_list":["post-14196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-finance","category-enterprise-security","category-insights","category-thought-leadership","category-top-stories","tag-banking","tag-bt","tag-financial-services","tag-zero-trust"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/14196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=14196"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/14196\/revisions"}],"predecessor-version":[{"id":14535,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/14196\/revisions\/14535"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/19798"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=14196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=14196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=14196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}