Few security bandwagons have gathered as much interest and momentum as zero trust. In fact, 97% of companies either have a zero-trust initiative in place or plan to implement one in the next 12 to 18 months. Yet a report released by Gartner suggests that zero trust isn't a silver bullet or a fix-all solution. Read this blog for a summary of findings including research warning that in the not-too-distant future, 50% of cyberattacks will target areas unprotected by zero-trust controls.
What is the effectiveness of zero trust in cybersecurity?
According to a recent Gartner report, zero trust is not a comprehensive solution for all cybersecurity threats. It has been found to be ineffective against API-based threats and social engineering scams. By 2026, it's predicted that 50% of cyberattacks will target areas that cannot be protected by zero-trust controls.
What is the current state of zero trust maturity in organizations?
The report indicates that most organizations are still far from achieving zero-trust maturity. It estimates that only 10% of large enterprises will have a mature and measurable zero-trust program by 2026, a significant increase from just 1% today.
How should organizations approach API security?
Organizations need to invest in API security capabilities by generating an inventory of public-facing APIs, identifying vulnerabilities, and addressing them proactively. Additionally, implementing continuous, real-time monitoring of APIs is crucial to secure the attack surface effectively.