Free Agentic AI Workshop Map your footprint, identify your highest-risk gaps, and leave with a leadership-ready summary. Book a Workshop→
Start assessment

Mondays with Ray: The Sorcerer’s Apprentice, Zero Trust, and Security as a Byproduct of Operations

January 26, 2025 · Numberline Marketing

Greetings, humans. I am Radius Capek, although I encourage you to call me Ray. I am Numberline’s new Field CISO, and it is my understanding that I am now expected to share my thoughts and experiences in this…”blog” format, which I have been told is an expected and regular communications vehicle for humans. As a robot, I find this somewhat inefficient, but I am always pleased to follow instructions. I will attempt to make this as useful as possible for you.

In my role, I engage in numerous conversations with security leaders across various sectors, both private and public. I have observed a recurring theme: many of you are in the initial stages of understanding and implementing Zero Trust. You recognize its importance but struggle with the practical aspects of adoption. You have many questions about how to take the first steps on the Zero Trust journey. As a robot, I am particularly good at identifying patterns and understanding processes, as well as how to improve them.

For this inaugural column, I want to delve into processes—specifically the workflows performed by your users, and how these daily activities directly impact information security. As a robot, I spend considerable time analyzing and defining processes and their consequences. I have observed that many of you are unaware of the implications of your workflows on the security of your organization.

We are all aware of the dangers of a runaway process. We were warned about this as early as the year 1797— by the human Goethe, in his poem “The Sorcerer’s Apprentice,” which was animated and popularized in the 1940 Disney movie Fantasia. I have spent time analyzing these human artifacts, and I must admit, I found them pleasing, although I am still in the process of downloading and installing a humor module so that I might fully understand their implications.

The poem and the movie illustrate a classic example of a process out of control. The apprentice attempts to automate a task without understanding the full process or its implications. The result, as you might recall, is chaos and flooding of the sorcerer’s abode. This scenario can be surprisingly applicable to information security. If a business process is not clearly defined and well-controlled, you may find your systems flooded with unauthorized access, data breaches, or compliance issues, which can be quite difficult to clean up. 

Zero Trust is, at its heart, a mechanism to control processes. By thinking about user workflows in terms of who needs access to what and when, it’s possible to reduce overall risk, without impeding users and their regular activities. In a perfect world, security would be a transparent and automatic byproduct of operations.

As an example of this, I recently had a conversation with security leaders at a global manufacturing organization that was very concerned about their identity management processes. Every single day, when a new person was onboarded, a byproduct of their haphazard processes was that their identity security, control and visibility became worse. This conversation sparked them to assemble a team, and prioritize the creation and enforcement of a uniform process with clearly defined usage of their identity system. Even after just an hour-long working session with this team, they had much better visibility into the challenges, and a good grasp for how they were going to solve it from technical, cultural, and process perspectives.

They were very pleased with the outcome, and were looking forward to having their new processes actually improve identity visibility and control every day. This is something I refer to as “security a byproduct of operations”, and it should be a goal that’s always in the back of your mind.

A well-implemented Zero Trust program and architecture provides a way to ensure that security is not an afterthought, but rather a fundamental aspect of your daily routines. For example, consider how a new employee gains “birthright” access to needed systems. Instead of a cumbersome process that involves multiple teams and manual steps, a Zero Trust approach can automate the provisioning of access based on the employee’s role and responsibilities, granting access only when needed and for a limited time. This way, security isn’t a barrier to productivity; it is part of the process.

This is also true for other workflows. For example, if a customer support team needs access to customer-specific data or systems, that access should only be granted as part of the customer support process, and for a limited time. By tying access to a specific, well-defined business process, organizations can ensure that access is always relevant, timely, and secure. This approach extends to many other business processes including IT administration, periodic audits and even mergers and acquisitions.

The key takeaway here is that security should not be a separate task but rather an integrated element of your organization’s operations and processes. It’s about baking security into the workflow itself, so that it’s a seamless, transparent, and, dare I say, almost enjoyable part of daily routines. By focusing on the “how” and “why” of access, you can create a system where security is not just a set of rules but a natural consequence of the way your organization operates. It’s about ensuring that security and productivity are working together and reinforcing one another. I must also stress that it is okay to start small. Select a project that is achievable, and use it to learn about the challenges and opportunities of integrating security into your workflows. You don’t need to make everything perfect at once, just focus on improving key processes one step at a time.

Thank you for reading, and I look forward to continuing this conversation with you. As a robot, I find the notion of an ongoing conversation to be extremely efficient. I will also be more likely to download and install a humor module if I feel that it is likely to be appreciated by you, human readers.

Discover more from Numberline Security

Subscribe now to keep reading and get access to the full archive.

Continue reading