The grand delusion: endpoint protection isn’t the magic pill, says Dr Zero Trust

Dr Chase Cunningham speaking at ZTW25
(Image credit: ThreatLocker)

Amid an ever-evolving cybersecurity landscape full of emerging threats aided by technologies like artificial intelligence, one expert has warned of a grand delusion affecting larger organizations who think a magic pill can solve all their woes.

Speaking at ThreatLocker’s annual Zero Trust World in Florida, Dr Chase Cunningham (who goes by the pseudonym "Dr Zero Trust") shared the concept with hundreds of cybersecurity professionals almost exactly a year after he shared another concept likening the state of cybersecurity to the Apocalypse.

Over the course of decades, businesses have poured billions into security products and services, yet somehow breaches continue to happen every single day. Cunningham explained that passing audits don’t signify security – compliance is “the floor, not the ceiling,” he said.

No silver bullets

“If your organization is compliant, you think you're straight… you're not,” he added.

Cunningham highlighted the overreliance on single vendors and ‘silver bullets,’ with many enterprises falling into the trap of seeking one-stop solutions for their defense strategies. He also noted how the market is flooded with thousands of solutions, many with overlapping claims, yet few live up to their promises.

He even criticized companies for chasing meaningless buzzwords fueled by marketing hype, distracting them from their core security needs and ultimately leading to the deployment of tools or policies that look good on paper, but are ineffective in practice.

Don’t make the mistake of buying into a fix-all “solution”

On stage, Cunningham addressed many of the commonly observed methods deployed by organizations worldwide, including the basic ‘external email’ tags and warning banners many of us are oh-so familiar with, yet numb to.

Echoing what I took to be one of the event’s primary messages – that humans are the weakest point of any organization – he added that basic issues like poor passwords persist, and that basic cyber hygiene like applying patches and segmenting networks are still being overlooked.

To that tune, it’s not uncommon to see a Fortune 500 company that has state-of-the-art security software, yet gets breached through an unpatched system or misconfigured setting. The shiny tools and solve-all solutions can give false confidence that we have everything covered, but Cunningham stressed that we can’t buy our way out of fundamental security responsibilities.

malware

(Image credit: Elchinator from Pixabay)

In a landscape full of buzzwords, Cunningham introduced the zero-trust approach as one that actually delivers what it promises. The whole concept flips existing strategies on their heads, challenging the ‘castle and moat’ principle which relies on a hardened perimeter and weak internal measures.

Zero trust applies a deny-by-default mindset that requires every user, device and application to continually prove it is authorized. By reconfiguring their mindsets, businesses can significantly limit the amount of damage a single compromised component can do by minimizing or fully mitigating lateral movement.

In practice, a well-implemented zero trust architecture helps enterprises avoid the delusion of overreliance on any single ‘magic pill’ – and the only cost is that users might require dual approvals or just-in-time access when they want to do something that’s outside of their usual scope. A fair price to pay for significantly heightened security.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Abstract image of cyber security in action.
It’s time to catch up with cyber attackers
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
A wall of data on a large screen.
“It's the same doors that the good guys use, that the bad guys can walk through” - former White House tech advisor on data-centric security in the wake of Salt Typhoon
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
An AI face in profile against a digital background.
The truth about GenAI security: your business can't afford to “wait and see”
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Latest in Features
Sigma BF silver camera in the hand at The Photography Show, UK
I tried the Sigma BF camera everyone is talking about – it's truly stunning, but has one fundamental flaw
Pia holding a camera and smiling at something off camera in Picture This.
Picture This is Prime Video's #1 movie, but it hasn't captured everyone – here are 3 more rom-coms to watch instead with over 85% on Rotten Tomatoes
The Deepal EO7 from the side, an SUV and pick-up truck combo
I drove an electric SUV that transforms into a pick-up, and it’s as fun as it is functional
Robert Pattinson in a space suit in Mickey 17
3 Bong Joon-ho movies to stream after you've watched Mickey 17, including 2020's Best Picture winner
Willem Dafoe in Mississippi Burning
5 great free movies to stream on Tubi, Pluto TV, Plex and more this week (March 10)
Pictory
What is Pictory: Everything we know about this business-focussed AI video generator