Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 27 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why are you ignoring NIST, NSA and the NCSC?

ZT is a journey of competency from basic to advanced capability whose policies and processes will be evolving continuously

by Kevin Bailey
April 1, 2021
in Insight
Why are you ignoring NIST, NSA and the NCSC?
Share on FacebookShare on Twitter

Between August 2020 and February 2021, “the agencies”, National Institute of Standards and Technology (NIST), National Security Agency (NSA) and National Cyber Security Centre (NCSC) had all published final or preliminary (beta) guidance for Zero Trust (ZT) that is applicable to all sizes of organisations. I would suggest to you that the agencies are experts in the field of cybersecurity. So why are these being ignored by vendors, analysts and consultancies to promote products and services?

Nowhere in the agencies’ guidance could I find where they infer that organisations’ existing security products are inadequate or that ZT requires you to implement new products in order to adopt, embrace or migrate to their ZT principles.

John Kindervag first coined the phrase “Zero Trust” and published his first blogs on the subject in 2010. Anyone that follows me, will know that I have never been a fan of the term. I feel it only adds fuel to the [existing] fire of security fear, uncertainty and doubt, implying that ZT promotes negativity. But this doesn’t mean I don’t wholeheartedly believe in the principals behind the term.

If you’ve read my papers on User Isolation Protection, I challenge businesses to review their existing identity and access products and policies. Personally, I don’t know why John didn’t simply call it ‘Always Verify’ from the outset, or others change its name? Maybe it wasn’t catchy enough, impactful or marketable?

ZT has value now

The agencies’ ZT principles should have been a no brainer for SolarWinds. The latest blame is pointed at a company intern for a critical lapse in password policy that apparently went undiagnosed for years. As Robin Oldham remarked in his weekly infosec newsletter “If true —then the company’s culture, practices, technical solutions, or assure activities must also have therefore been pretty spectacularly lax. This wasn’t about the product being used, but the processes and policies.

The Research

Driven to help security leaders and vendors, I wanted to know why vendors and influencers ignore the agencies’ guidance of ZT? Approaching this in the manner of a security leader I allocated [a rare] 30 minutes to search for the agencies key phrase ‘Zero Trust’.

Findings

The mildly encouraging statements from 5 of the 26 security related providers was the high point of the research.

  • The agencies didn’t show up in the 4 pages of 49 results that I reviewed, not surprising as they don’t have the volume of search traffic as commercial vendors or invest in paid advertising.
  • 22 results were from security vendors, 2 research groups and 2 consultancies.
  • I came across a security vendor that nailed the agencies’ basis of ZT principles.
    • “Zero trust isn’t something you can buy or implement. It’s a philosophy and a strategy. And to be frank, at [redacted], we wouldn’t even characterize zero trust as a security strategy. It’s an IT strategy done securely.”
  • 2 security vendors directly referenced NIST ZT and 1 promoted the NSA ZT model.

Everything was about the how product aligned to an interpretation of ZT, rather than revealing ZT value and acting as an advisor to the security leader.

  • All 26 ZT providers exploited ZT positioning for a unique product or service recognised by research group reports.
  • Modified terminology (ZTS, ZTNA, ZTXEP, ZTVDC, ZTDP) from the agencies’ principles of ZT is believed to reap greater vendor acceptance. These alternatives didn’t provide anything new and failed to fully explain how their framework.
  • All providers immediately hit the sales cycle and started on the feeds and speeds and why “they are a leader in ZT”.
  • Emphasis was about how they could replace what may already be in situ to resolve their targets ZT environment, none approached this from an advisory perspective for security leader value.

Everyone loves a report, but not the ones from “the agencies”

  • Four providers required something in return – data, money, registration.
  • When you consider the earlier comment “Zero trust isn’t something you can buy or implement…”, why was 60%+ of the report scoring against the product and minimal against advisory capability and agencies’ alignment?

SynergySix Guidance

[As a security leader] I would always listen and be guided by the agencies above all others. Why? They are independent, have no commercial interest, use diverse panels of experts and are trusted in their opinions by peer security leaders.

If alternatives reports were compelling enough, let me read them and then I will contact you. If not, it means that you [author] missed the point, not the me. I don’t have time or wish to pay for a report that could be of no use.

Security Leaders

ZT is a journey of competency from basic to advanced capability whose policies and processes will be evolving continuously. Resist approaching this from a product perspective, they are there to support your guiding principles. Any lack of alignment to the agencies’ recommendations may hinder your guiding principles and design concepts. So, ensure that you lead with a secure IT strategy mindset and then ensure your product(s) of choice can ride the journey to advanced capability.

Security Vendors

Whatever your belief, trust in the agencies’ ZT principles and models that have been developed that as evolved help your clients’ IT strategy embrace a ‘security-first’ mentality. Relating to the agencies’ guiding principles and design concepts triggers the recognition of terminology/workflow/process/policy by the security leader. Your engagement is advisory led (service/consultancy) not product led, identifying how your offering advances successful processes, policies and the availability of data for the benefit of the client. Only once the advisory engagement is underway should you suggest that the client revert to challenging the security product(s) installed.

Tilt the advantage to the business

A ZT architecture model as defined by the agencies is to help tilt the advantage of security authorisation, access and policy protection in favour of the business rather than the cyber adversary. Raising awareness and helping security leaders protect access, authentication and privacy of their business is a challenge, but NIST, NSA and the NCSC have provided the guidelines and design principles to evolve every size of business to achieve this aim.

Wouldn’t it be beneficial to have the security leader reaching out to you [vendor] so they could learn how you can assist with their objective of aligning to the Zero Trust guiding principles and design concepts.

 

Contributed by Kevin Bailey – Director & Founder, Synergy Six Degrees

Kevin Bailey is the Principal Analyst & Director for Synergy Six Degrees, a cybersecurity go-to-market consultancy. A GTM specialist for over 20 years in the research, evaluation and integration of technology and processes across data, cyber security, SaaS and emerging technologies.

Kevin holds a MSc Marketing (Distinction) and Postgraduate Diploma in Marketing (PDipM), is a member of The Chartered Institute of Marketing (MCIM), an active STEM ambassador and contributor to the UK government All Party Parliamentary Groups (APPG) for Blockchain and Artificial Intelligence.

Kevin is a judge for the 2021 GSMA Global Mobile Awards (GloMo’s) for Authentication & Security.

You can follow Kevin on LinkedIn and Twitter at @baileyk62 

ShareTweet
Previous Post

VMware urges customers to patch critical vulnerabilities in vRealize Operations platform

Next Post

North Korean hackers targeting Google researchers

Recent News

Keeper Security launches Microsoft Teams integration for privileged access management

Keeper Security launches Microsoft Teams integration for privileged access management

June 26, 2026
UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol