This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Zero Trust enables… business value?

Download resources

About this session

Brad Doctor, who leads security architecture, engineering and vulnerability management at VMware, opens his GoSec 2021 keynote with the scale of VMware's own environment: 64,000 devices managed by Workspace ONE, nearly 1,000 VeloCloud appliances, over 100 applications micro-segmented with NSX on the way to 400, 91,000 persistent VMs and 7,000 ESXi hosts. He defines zero trust as an architecture rather than a product, built on three principles: nothing is trusted by default, authentication and authorization precede everything, and trust is re-verified on every access. The foundations are automated identity governance, passwordless authentication with certificates or FIDO keys, and real-time adaptive trust driven by endpoint telemetry such as patch status, disk encryption and XDR alerts. He walks through the access flow (Workspace ONE UEM as policy enforcement point, Workspace ONE Access as decision point) and argues it can coexist with legacy data centres through micro-segmentation. The business value: simpler cyber-insurance conversations, developers freed from building authentication, standardised operations that cost less, and the agility that let VMware go fully remote in a weekend without missing a delivery quarter.

We all know that Zero Trust has value in terms of technical security, but what about its impact on the bottom line? After all, given Zero Trust involves organizational and process changes—as well as addresses the new White House cybersecurity executive order—it’s easy to view it only as a necessary expense. Join Brad Doctor as he leads an exploration into how he and his team discovered and unlocked Zero Trust’s surprising little secret—it offers tremendous business value! By articulating a solid business case with a clear vision and strategy, your team can accelerate Zero Trust adoption and ensure your company is more competitive than ever. 

Key takeaways

  • Define zero trust as three principles (no default trust, authenticate and authorize first, re-verify every time) and evaluate products against them rather than the label.
  • Eliminate passwords for user and admin access; use certificates or FIDO keys with step-up authentication for sensitive apps or degraded endpoints.
  • Feed endpoint telemetry (patch level, disk encryption, security agent health, XDR alerts) into access decisions so trust adapts in real time.
  • Micro-segment applications one at a time; it works inside legacy data centres and is the fastest path to a zero-trust deployment.
  • Sell the program on business value: one way to authenticate, one way to manage endpoints and demonstrable real-time posture simplify cyber insurance and cut operating cost.

Speakers

Brad Doctor
Brad Doctor
Head - Security Engineering and Architecture · VMware
Innovative thought leader and information security professional with over 20 years of experience and over 20 patents in various technology domains. As the head of security engineering, architecture and offensive security at VMware, Mr. Doctor has… Read moreRead less

Innovative thought leader and information security professional with over 20 years of experience and over 20 patents in various technology domains. As the head of security engineering, architecture and offensive security at VMware, Mr. Doctor has been at the forefront of cloud security architecture and engineering for over 10 years, and has led design and engineering efforts for several commercially successful security products and services .

Resources

Tags

More from GoSec 2021

Also from Brad Doctor

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.