Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 5 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The new age of cybersecurity

by The Gurus
November 15, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

The very successful digitisation trend over the past 20 years has produced huge efficiencies in every type of corporation and government. But the dark side is that the security industry has largely failed to evolve the standard security architecture to keep pace with these broader changes in IT.
 
The firewalled perimeter remains the primary defence in IT security. Yet every major data breach in the pandemic of breaches taking place around the world shows how simply firewalls can be bypassed. If a government worker clicks on the wrong email and falls prey to a phishing attack, a hacker can leapfrog the firewall and browse at will through the government agency’s digitised records and applications.
 
The explosion of IT systems, networks, users, Clouds and devices has caused the size of the typical enterprise’s attack surface to expand exponentially. Any user or device can be the weakest link and become the steppingstone to a major data breach.
 
Billions of dollars in venture capital over the past five years has been poured into start-ups trying to improve IT security. Yet industry statistics show that today the typical data breach still goes undetected for months. That’s an eternity for malware and Advanced Persistent Threats to be loose in your systems. And most of the largest vendors continue to make a lot of money selling the same old security architecture, doing nothing to truly fix the problem.
There are new security techniques that are proving to be effective and that do not require the enterprise or agency to cut off Internet connectivity.  One such strategy is called the “Zero Trust” or “No Trust” model.
The old security architecture is built with the idea that you can use a firewall to keep unauthorised people out of the enterprise systems. This internal network is considered to be “trusted” and users who are authenticated and given access are likewise assumed to be “trusted.” This trust model is obsolete as every major data breach since the Target hack has shown.
Instead, enterprises are starting to adopt a “No Trust” model that assumes no network, user, device or application can ever be fully trusted. Instead, you assume that the network is already compromised, that a user actually is a hacker with stolen credentials, or that a device contains malware. With that assumption, how do you design the IT security architecture to minimise the damage?
IT security architects are deploying more sophisticated internal controls, segmenting and isolating applications by enforcing stronger rules on who should access them, even when the user is inside the network. Role-based access control is one such technique, inspecting the internal network traffic at various points and blocking attempts to access applications by users who don’t meet certain rules. Another technique is to use strong encryption to isolate internal applications so that if a hacker compromises a network device, the hacker cannot access the application traffic flowing through it.
But in addition to these better internal controls, the security industry as a whole must focus on making security easier to deploy and easier to manage. The typical security architecture is fragmented and splintered across IT silos, with different tools, different access policies, and different controls in the LAN, WAN, Internet, mobile network, Cloud, data centre and elsewhere. This means setting up and managing consistent, uniform security policies across all of these silos is extremely hard.
Until the security industry makes it easier for organisations to deploy a simpler, more consistent security architecture, the gaps left by fragmentation are going to remain the gateway for hackers to exploit. It is only by changing the way the security architecture is viewed that positive advances in the industry will really be seen.

ShareTweet
Previous Post

Artificial Intelligence may hold the key to sustaining the data centre industry

Next Post

Teenager Pleads Guilty to TalkTalk Hack Offences

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol