The 0.1.2: December Edition
Data Resilience, how many tools are “too many?”, and fried chicken!
It’s December, and therefore time for our contractually-obligated reflections on the past year (look for our 2024 predictions in January). But before we talk about security, I’d like to share the results of my latest experiments with The Food Lab’s fried chicken recipe. The results have been…gloriously delicious, and caused much joy and celebration among my family (it did necessitate a few additional visits to the gym, however).
While frying chicken is a multi-step process, if you’re comfortable with basic cooking skills it’s not that complicated and the results are well worth it (kind of like Zero Trust). What’s interesting is that you don’t need any special tools or equipment — just the basics.
As you’ll see in our opinion piece below, the same is true for Zero Trust. While modern security tools and platforms will help, you can get going and deliver substantial value with basic tools that you probably already have in place. It’s about using them correctly. See what we have to say in The View From Point Zero below. And give the fried chicken recipe a try this holiday season!
To receive future editions of this this newsletter via email, subscribe here.
News
Introducing Zero Trust Data Resilience: Extending Zero Trust to Data Backup and Recovery
Data backup and recovery systems, along with their backed-up data, are frequently the primary target of malicious actors. Given this, we need to apply security best practices – Zero Trust — and therefore we’re pleased to announce the release of new, original Zero Trust research, extending the CISA Zero Trust Maturity Model to the areas of data backup and recovery.
Our research whitepaper is freely available here. In it, we explore the security and architectural requirements for data backup, a reference architecture, and four new Maturity Model functions.
Appearance on the SSE Forum podcast
I recently had the opportunity to (virtually) sit down with the folks at the SSE Forum for a conversation about how to “sell” Zero Trust internally to the enterprise (hint – it involves business value), and good use cases to get started with. Listen here.
The Open Group Open Comments podcast
While I was out at the Open Group forum for several sessions on Zero Trust, I sat down (in person!) with Ash and Irene for a wide-ranging discussion about careers, mentorships, and recent books I’ve read. This podcast is available here.

The View from Point Zero:
By Jason Garbis, Founder of Numberline Security
Assisted by Scully, whose trained nose can sniff out malicious DNS requests traversing Wi-Fi
How many tools are too many? (i.e., Stop the Insanity)
Over the course of 2023, I met with dozens of enterprises to talk about Zero Trust strategies, approaches, architectures, and challenges. While each of these conversations is different, because each organization is in a different starting point, they do all have something in common: stage-setting. That is, up front I’ll ask some questions about their enterprise and environment, touching on the five pillars of Zero Trust. There’s usually a heavier emphasis on Identity and Networks, and a lighter emphasis on Devices, Applications & Workloads, and Data, but it depends on the organization. We’ll also talk about their overall security infrastructure, including systems and processes.
One part of this conversation is the tool enumeration, where the security team will talk about the tools the have in place, and how they’re using them. These typically sound like “We use A for our identity management system, and B for identity governance. Network security is handled by C and D, which includes IDS/IPS. We have E and F for our SIEM, G for endpoint management, and H for mobile devices…”.
In general, the number and breadth of tools in place is correlated with the scale and scope of the enterprise. That is, larger enterprises tend to have more tools in place, because they have larger and more complex environments, and have larger teams to deploy and operate these tools. This makes perfect sense. But – I’ve seen two things to be wary of.
First, some smaller organizations, with small teams, sometimes have an alarmingly large number of tools. And second, I’ve seen larger organizations who are “just getting started” with too many of the tools in their environment.
This is, honestly, disheartening. While I’m by no means advocating that enterprises should leave gaps in coverage, I’d much rather see teams have fewer tools that they leverage in-depth, fully understand, and fully utilize. The risk of only having superficial usage and understanding of a tool is the false sense of confidence it can give you, and the signals it will miss.
I’ll share one example from a financial services client – they deployed an XDR tool and began defining automated responses to detected anomalies. However, they noticed that it was just generating too many false positives, and that reconfiguring it resulted in too many false negatives. But, their SOC team loved the detailed information that the XDR tool provided. Their conclusion was to feed the XDR tool information into their SIEM so that the information was accessible, but not to trigger automated responses. This turned into a good, thoughtful use of a specific tool.
We all understand that information security is a complex problem; after all we’re creating a digital model of our enterprise and defining controls and parameters for how we expect it to work. This requires a deep understanding of the tools, telemetry, and processes. So for 2024, I challenge you and your team to look critically at your toolset, and determine which ones you can leverage for more value, and which ones you could consider retiring. As you proceed with your Zero Trust journey, there will be times when new tools are needed. But in many cases, you can deliver substantial value just by making better use of the tools you already have.
Recent and Upcoming
- Data Breach Today Panel discussion on Extending Zero Trust with Data Resilience: Why Data Backup and Recovery Matters. On-demand viewing here.
- LinkedIn Live on Zero Trust Data Resilience with Veeam: Replay available here
- Cloud Security Alliance Panel on Communicating the Business Value of Zero Trust – look for a link soon – this is planned for mid-December
Wrap-Up
Thanks for reading.
Interested in learning more? Get 30% off the new book, Getting Started with Zero Trust : Use discount code THE012 for 30% off a digital copy when you purchase it from our media store.
And if you want to see how your enterprise can reduce security complexity and unlock business agility, take our 10-minute Zero Trust Readiness Survey.
To receive future editions of this newsletter via email, subscribe here.