{"id":99540,"date":"2021-11-03T09:00:06","date_gmt":"2021-11-03T16:00:06","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=99540"},"modified":"2023-05-15T23:01:21","modified_gmt":"2023-05-16T06:01:21","slug":"evolving-zero-trust-lessons-learned-and-emerging-trends","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/11\/03\/evolving-zero-trust-lessons-learned-and-emerging-trends\/","title":{"rendered":"Evolving Zero Trust\u2014Lessons learned and emerging trends"},"content":{"rendered":"
Looking back at the last two years, to say that our security strategies have evolved would be an understatement. Organizations around the world made overnight transitions to remote work models in response to a global pandemic, forcing them to reassess attack surface areas as they underwent an accelerated digital transformation. Meanwhile, cybercriminals seized new opportunities\u2014introducing COVID-19-themed social engineering campaigns and accelerated ransomware attacks. Nation-state actors launched increasingly bold and sophisticated nation-state attacks.1<\/sup><\/p>\n In this environment, security transformation has become key to survival. The mandate to explicitly verify every access request, focus on least privilege access overall, and constantly assume breach to maintain vigilance was made clear, as exemplified by calls from governments and businesses worldwide to accelerate the adoption of Zero Trust strategies<\/a>.<\/p>\n Sidebar:<\/strong> Zero Trust is a proactive, integrated approach to security across all layers of the digital estate that explicitly and continuously verifies every transaction, asserts least privilege, and relies on intelligence, advanced detection, and real-time response to threats.<\/em><\/p><\/blockquote>\n Microsoft has embraced Zero Trust<\/a> to defend our own estate and as a guiding principle for the development of our products. We have also helped thousands of our customers\u2014including Siemens<\/a>\u2014 deploy Zero Trust strategies, accelerate their digital transformation, and increase frequency of advanced attacks using our Zero Trust architecture.<\/p>\n <\/a><\/p>\n Figure 1: Learnings across thousands of Zero Trust deployments have informed our Zero Trust architecture, which emphasizes the critical importance of integrating policy enforcement and automation, threat intelligence, and threat protection across security pillars.<\/em><\/p>\n Today, we\u2019re publishing the new whitepaper, Evolving Zero Trust<\/a>, to share the key lessons we\u2019ve learned by embracing Zero Trust at Microsoft and supporting thousands of organizations in their Zero Trust deployments. This informs our beliefs on Zero Trust implementations needed to evolve to adapt and keep organizations protected. We\u2019re also sharing the evolution of our recommended Zero Trust architecture and maturity model that has been informed by these insights.<\/p>\n <\/a><\/p>\n This document showcases the incredible evolution and acceleration in the adoption of Zero Trust security strategies. Just a few years ago, Zero Trust was merely a new buzzword for many organizations. Today, 76 percent of large organizations have adopted a Zero Trust approach<\/a>. We hope that the lessons, trends, and positions we shared in this document are helpful in the planning and application of your own Zero Trust strategy.<\/p>\n The insights and actionable learnings in this document have been provided by a diverse group of customers, partners, and security-focused individuals working across applications, data, endpoint management, identity, infrastructure, networking, threat protection, and our own internal security organization. I\u2019d like to thank our customers and partners for their expertise and insights, as well as my colleagues for their contributions to this whitepaper, architecture, and maturity model guidance.<\/p>\n Get the complete \u00a0Zero Trust whitepaper<\/a> for key insights, Zero Trust architecture, and a maturity model to help accelerate your adoption.<\/p>\n For a repository of technical resources to help accelerate the deployment and integration of Zero Trust across all security pillars, visit the Zero Trust Guidance Center<\/a>.<\/p>\n Use the\u00a0Zero Trust Assessment tool<\/a>\u00a0to evaluate your Zero Trust security posture, maturity, and receive practical recommendations to help reach key milestones.<\/p>\n Read\u00a0the 2021 Microsoft Digital Defense Report<\/a> (MDDR) for in-depth findings about Microsoft\u2019s tracking of nation-state threat groups, specific threat actors, attack methods, and more.<\/p>\n To learn more about Zero Trust, visit Microsoft Security\u2019s Zero Trust<\/a> website.<\/p>\n To learn more about Microsoft Security solutions,\u00a0visit our\u00a0website<\/a>.\u00a0Bookmark the\u00a0Security blog<\/a>\u00a0to keep up with our expert coverage on security matters. Also, follow us at\u00a0@MSFTSecurity<\/a>\u00a0for the latest news and updates on cybersecurity.<\/p>\n <\/p>\nThe evolution of Zero Trust<\/h2>\n
Lessons learned and emerging trends<\/h2>\n
Highlights from the paper include:<\/h3>\n
\n
Learn More<\/h2>\n
\n