The Chief Zero Trust Officer: a new role for a new era of cybersecurity
IN RECENT times, cybersecurity has become a staple discussion topic in boardrooms. Ongoing geopolitical tensions and economic uncertainty have made the threat of cyberattacks even more pressing, with businesses of all sizes and across all industries feeling the heat. From the potential for a devastating ransomware attack to a data breach that could compromise sensitive consumer information, the risks are real and potentially catastrophic. Organisations are cognisant of the need for better cyber resilience and preparation. Merely reacting to an attack is no longer enough. Companies must proactively prepare for the inevitable in their approach to cybersecurity.
A cybersecurity approach that has gained the most traction in recent years is the concept of Zero Trust. The basic principle behind Zero Trust is simple: trust nothing; verify everything. The impetus for a modern Zero Trust architecture is that traditional perimeter-based cybersecurity models are insufficient in today’s digital landscape. Organisations must adopt a holistic approach to security based on verifying the identity and trustworthiness of all users, devices, and systems that access their networks and data.
Zero Trust has been on the radar of business leaders and board members for some time now. Cybersecurity and Internet firm Cloudflare’s “The journey to Zero Trust in Asia Pacific” study revealed that 85 per cent of organisations in Singapore are aware of Zero Trust. However, Zero Trust is no longer just an idea; it has become a mandate. With remote and hybrid work being encouraged and cyberattacks continuing to escalate, businesses realise they must change their cybersecurity approach. Such shifts in strategy can be challenging to implement. Cloudflare found that 65 per cent of firms have begun implementing Zero Trust methods and technologies. There is still plenty of room for the proliferation of Zero Trust here in Singapore.
Why a C-level for Zero Trust, and why now?
Many large companies find that their Zero Trust initiatives are stuck in the implementation phase. A lack of clear leadership and accountability is often a problem. Who exactly is responsible for driving the adoption and execution of Zero Trust within the organisation? This is where the role of a “chief zero trust officer” (CZTO) could make a difference and become commonplace in large organisations over the next year.
Large organisations need strong leaders to steady the ship and ensure the business runs smoothly. Businesses assign the ultimate leadership responsibility to people with titles that begin with the word chief, such as chief executive officer (CEO) or chief financial officer (CFO). These positions exist to provide direction, set strategy, make critical decisions, and manage day-to-day operations and they are often accountable to the board for overall performance and success.
Large enterprises need a single person responsible for driving the Zero Trust journey. This leader should be empowered with a clear mandate and have a singular focus: getting the enterprise to adopt Zero Trust. This is where the idea of the CZTO was born. “Chief Zero Trust Officer” may seem like just a title, but it holds a lot of weight. It commands attention and can overcome many obstacles to Zero Trust.
In Singapore, under the Cybersecurity Agency of Singapore’s (CSA) cybersecurity strategy, the government is setting an example by adopting a zero trust method to safeguard its applications and IT systems by verifying that all activities on them are safe. Such an approach, championed by the government, could eventually seep into the private sector and lead to a stronger demand for CZTOs.
Overcoming barriers to adoption
Chief Zero Trust officers can help organisations overcome various technological roadblocks in implementing Zero Trust. Understanding and implementing the complex architecture of some vendors can take time, demand extensive training, or require consultancy to acquire the necessary expertise. Identifying and verifying users and devices in a Zero Trust environment is also challenging. It requires an accurate inventory of the organisation’s user base, groups they belong to, and their applications and devices.
On the organisational side, intra-team coordination is vital for effectively implementing Zero Trust. Breaking down the silos between IT, cybersecurity, and networking groups, establishing clear communication channels, and regular meetings can help engender a cohesive security strategy. Resistance to change can also be a significant obstacle. Leaders should use techniques such as leading by example, transparent communication, and involving employees in the change process to mitigate it. Proactively addressing concerns, providing support, and upskilling employees can also help ease the transition.
Responsibility and accountability – no matter what you call it
Do organisations need a CZTO? Could someone already managing security within the CTO or CISO office be assigned the role? Companies should assign the title based on the level of strategic importance to the company. So, whether it’s chief zero trust officer, head of zero trust, VP of zero trust, or something else, the title must command attention and come with the power to break down silos and cut through bureaucracy.
New C-level titles are not new. Recent examples include chief digital transformation officer, chief experience officer, chief customer officer, and chief data scientist. The ‘chief zero trust officer’ title is likely not even a permanent role. However, the person holding the role will have the authority and vision to drive the Zero Trust initiative forward, supported by company leadership and the board of directors.
Getting to Zero Trust security is now a mandate for many companies, as the traditional perimeter-based security model is no longer enough to protect against today’s sophisticated threats. To navigate the technical and organisational challenges that come with Zero Trust implementation, the leadership of a CZTO is crucial. The CZTO will lead the Zero Trust initiative, align teams, and break down barriers to achieve a smooth rollout. The role of CZTO in the C-suite emphasises the importance of Zero Trust in the company. It ensures that the Zero Trust initiative is given the necessary attention and resources to succeed. Organisations that appoint a CZTO now will be the ones that come out on top in the future.
John Engates is field chief technology officer at Cloudflare
TRENDING NOW
Could stablecoins be the future of money?
Once staunchly pro-China, Malaysian Chinese businesses are now distancing themselves from Beijing
Vietnam’s data-centre investment rush faces reality check on power and site constraints
‘My grandfather’s legacy’: Sherman Kwek lays out three-year plan for CDL to drive returns