Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor with KuppingerCole Analysts. My guest today is Alexei Balaganski and he has come with some kind of a new topic, which is not that new at its core. But first of all, hi Alexei, good to have you. Great to have you and especially when it's really an upcoming important topic that we want to talk about. And for those who typically switch away very quickly when they consider terms as boring or a long time ago, don't go away. This is important.
This is a We want to talk about Zero Trust Platforms. So there is the term Zero Trust in there, which is some kind of a no-no word in some companies already.
But no, this time we are aiming at doing things right. But before we go to the platform part of the term, maybe a brief recap of Zero Trust as its history and what it actually is and why we still need it.
Well, I guess the term Zero Trust has been with us for well over a decade, probably closer to two now. And it was extremely popular and it was eagerly picked up by a lot of people, especially non-technical people back then, exactly because it was very non-technical in nature. I've always said Zero Trust is basically feng shui for IT. It's a set of philosophical tenets, how to organize your life, how to rearrange the furniture in your home and so on, to make sure that your work, your energies, your productivity and whatnot, and of course your security increases accordingly.
That was kind of the core idea. Never trust, always verify. Sounds very easy. The next question is, okay, you had me at hello, now where do I buy Zero Trust?
And again, we always had to go through the same pitch saying, you know, Zero Trust is not a tool, it's a journey, it's a strategy. Perfect Zero Trust will never be achievable, but you have to strive to make it your strategy. You have to go step by step. And at that very stage, we are starting to lose a lot of people's interest exactly because they needed practical guidance. Where do we start? How do we continue? Where do we invest? And how do we calculate the return of that investment?
Well, and then of course, the COVID came, everybody was locked at home, but still had to work from home. And this was a major boost for one very special and narrow application of Zero Trust, namely Zero Trust network access.
So again, everyone had to work from home, but of course we did not want to export the entire networks for remote sessions. Everybody was scrambling for some tool to replace VPN and ZTNA was the tool. That was a major spike in returning interest for Zero Trust. And for a few years, it was of course a buzzword, a very quickly selling market segment. And basically now everyone who actually needed one of those tools probably already has one, at least all the smart and forward thinking companies, those which are less smart, probably still struggling with the old VPNs.
But again, after all the restrictions were lifted, some people were starting to return back home. The others just kind of forgot how it all felt.
So again, we are starting to forget about Zero Trust. And yes, you are right. Some people just hate the word because of all the overexposure, because before AI, Zero Trust was the buzzword.
But again, this absolutely does not mean that this is somehow no longer relevant, or this is bad, or this is useless. To the contrary, it is absolutely very relevant again. And exactly because of all the developments we wanted to discuss today, starting from the AI. Right. And if I remember back to ZTNA, for me, as I'm a very simplistic person, for me, it's really providing a Zero Trust infrastructure as a service. So most probably all from out of hand as a package.
And that could help, as you said, especially during the COVID era, to have a platform which on the one hand replaces these VPNs, which did not scale. On the other hand, to have something very easily available, which was not possible to build from scratch in an own platform. But since COVID, you have mentioned that things have changed. We have AI, we have new technologies, but we still have the requirement to protect network access. And when we look at Zero Trust with this triangle between account network and devices, and then trying to access services, that's still around.
We still need to deal with it. So CTNA is no longer the go-to solution, right?
Well, let's again kind of recap what ZT and the concept actually supposed to mean. Zero Trust means, again, no implicit trust to anything or anyone.
Basically, it boils down to one simple requirement. You or any other entity and actor that needs to access something, data, resources, applications, APIs, anything within your corporate infrastructure, they should only be able to access it if they have, if they were given explicit and hopefully like very limited and time limited and kind of scope limited access to that specific resource. There should never be a situation where you get too much access. And this problem, when you think of it, is actually way older than the notion of Zero Trust.
I mean, as any IAM professional will tell you, this was the original problem, which existed as long as we had identity systems. This whole role management and ABAC and RBAC and all the other bags, it's something, something based access control. Zero Trust is basically just another requirement to trim down that access as much as possible. And the question is, how do you do that universally across any environment, any system and any type of identity? ZTNA was a quick and easy solution for a very specific use case.
How do you allow a human, which is currently located outside of your existing local IT infrastructure, to access not just the entirety of the infrastructure that can be done with an old VPN, but a very specific resource, like an application. And only if they need and explicitly were granted access to that application. Simply because if somebody has too much access, their credentials, their identity can be stolen and abused for stuff like ransomware attacks or lateral movements across your networks, stealing stuff as they come by and stuff like that.
So yes, ZTNA was a very quick and fairly reliable answer to that challenge. But now we have other things happening.
And again, just everything is now bigger and faster and scales and very drastically. And things are now more ephemeral in nature as before. So you have containers and microservices and things are just kind of pop up and disappear. But more importantly, we now have again AI systems. So we now have tons of non-human agents and other types of identities. And those were completely neglected in the most traditional Zero Trust network access solutions.
So if we want to make sure that access restrictions apply to anyone and anything, especially on those dreadful AI agents who can wreak havoc across all your stuff very quickly, we have to think bigger. We have to think strategically. And this is exactly when this notion of a Zero Trust platform emerges. Right. And you've mentioned that with half a sentence really to enforce it everywhere.
ZTNA was, as you said, a helpful platform approach to or architecture approach to solve parts of the problem. But we are getting much more hybrid. We have much more solutions that are around. Plus all the threats that you just mentioned when it comes to new types of identities, ephemeral, quickly changing, quickly scaling up and down identities, that requires a different way of thinking of Zero Trust, I assume. So we need to combine existing platforms or systems into an overall approach to achieve this constant and global enforcement. Is this the way to move forward in that approach?
Well, again, let's start by explicitly putting down the things we have to implement. First, we have to implement universal access enforcement across any kind of identity and any kind of resource. Doesn't matter whether it's me accessing your Excel spreadsheets or 10,000s of AI agents lurking through your entire cloud footprint. The rules should be the same. They should work the same, regardless of scale, location, type of identity, you name it.
Second, we have still to enforce continuous trust evaluation. This is the fundamental of Zero Trust, basically. You do not assume anything. You constantly have to evaluate whether it's still Matthias. Is it still the same agent? Is it still given the same goals and rules as five minutes ago? Is it still okay to trust the device? We have to be able to answer all those questions in real time, at any time.
Third, we have to understand that those decisions can no longer be binary, whether you get it or not, because there will be too many decisions. You have to start segmenting your resources. And ideally, you have a broad range of approaches towards segmentation. You can do it on a very resource scale, just saying, this is my outside network and this is my inside. This can be like an easy start. But of course, it's not enough because it doesn't stop you from ransomware attacks and retro movement.
Again, ideally, you should be able to do it on a very fine-grained basis, not just every resource, but let's say every method in an API endpoint becomes that grain of access. And you should be able to do it on an intelligent and automated basis because you would never be able to do it manually. And finally, you have to know what's going on. So you have to maintain unified visibility and analytics across all those developments. These are four requirements, universal enforcement, intelligent segmentation, continuous trust evaluation, and unified analytics.
Those are the prerequisites for a true platform-based solution, which could claim implementing zero trust. And from that, we can start discussing the details. For example, ZTNA doesn't go away. It's still a very much important part of that platform. But you have to think about other things. You would probably already have some kind of a policy-based access solution in place, at least for some of your resources.
PBAC, we call it. So there is some kind of a dynamic engine, which gets in context information from all those actors and resources and decides, yeah, this guy can access their thing now, based on these conditions.
Again, this is also a key building part of this solution. It just has to be more aware of the entirety of your environment and work ideally across that environment. So it should be integrated on both ends. It should get in more context information for all decisions and of course, be able to enforce the same policies across different types of resources. Strong authentication and continuous risk-based authentication.
Again, it's another prerequisite. And we do have a lot of those systems in place. We just do not think about them as a strategic building part of the zero trust platform. We don't have to reinvent anything. You don't have to define it as a completely new type of solution, which will just pop up out of nowhere. The building blocks are already there. We just expect vendors to be able to combine them in a simple, useful package, which can be deployed quickly, extended to cover as much of your footprint as possible.
And again, provide a combination of visibility and operational flexibility, but also convenience and the ability to respond to all those issues automatically. So if I understand you correctly, the same way that we learned that zero trust is not a product, we have to learn that zero trust platforms is not something provided by a single vendor, by a single product, but really an architectural approach, a way of thinking, of implementing that. And then we need the products that play nicely in that architecture.
Well, yes and no. Again, kind of the problem is we have always said, yes, you cannot expect to get such a platform from one vendor. It's too complex.
It's too, well, it's more like a fabric. Like Kuping et al. loves the term fabric. We already have like a fabric defined for identity and cybersecurity.
Well, this is just another kind of fabric specifically to live in this intersection of identity and security to provide this universal zero trust. But unfortunately, not a lot of people buy that idea and say, yes, but like, I am not an expert. It was way over my head or resources or just kind of time to build this fabric on my own. Where can I reach out to that would be able to help me? And vendors are already responding.
So yes, we definitely see our emerging offerings. I would probably not call them like full featured platforms in a traditional sense, but again, kind of anything can now be called a platform. Like everybody loves the term platform without actually specifically explaining where a platform starts as opposed to a fabric or a suite. But I believe that the term itself is gaining traction and this is why we want to be able to market as it develops. And as our own customers are coming to us with these questions, we should be able to point them in the right direction.
And yes, this is a development market, but there are some already interesting existing offerings available. Right. And as you've mentioned, we want to cover that market. And I know that you have already provided a leadership brief, a brief document that summarizes what we discussed, but much more as well. So it's really a starting point to lay the foundation as you described. And on the other hand, we really want to cover those products, those vendors that provide key infrastructures for such a platform. So that is something that you're currently working on.
Well, I can tell you exactly what we did. We did cover ZTNA as a standalone market a few years ago. We released a compass on those and it was well-received and we had a lot of participants. And of course, we had a lot of leaders.
So yes, this is a very mature and developed market segment. But again, with time, kind of the interest, the immediate urgency of that subject disappeared. And instead, people started asking different questions. How do we expand that approach towards everything?
Like, how do we go from tools-based zero trust to a platform-based approach, if you will, a strategic approach? How do we address this notion of disappearing trusted perimeter, not just for external access, but for any kind of access, for your cloud deployments, for your industrial networks, for your application level networking, this whole kind of microservice-based architectures with tons of traffic, which always lives inside a presumed trusted VPC, for example, in the cloud, but still, I mean, rogue microservices are a thing.
So we have to be able to apply the same approach to every scale and to every kind of environment. And this is what people are looking for. And we said, yes, let's expand our coverage. Let's observe what else the market has to offer. And let's formulate a set of criteria. And this is why we are now planning to create a leadership compass, a market coverage report for zero trust platforms, which would combine everything from the TNA and intelligent segmentation and strong authentication.
And of course, is a strong focus on non-human identities as well to address all those burden challenges, which our customers are asking us to help them find the solution. So this will not be a new topic, but this will be a substantially different topic with a much broader coverage. So we decided we'll actually reach out to vendors and ask their opinions as well. And we actually got quite a lot of very interesting thoughts.
So we did, I had to do kind of a second round of re-planning and finalizing the scope for our report. And we finally have this. I hope it will be in good agreement between customer expectations and what vendors are already offering. And this is how we define zero trust platforms in this sense. So there will be a very specific set of criteria. They're actually already available on our website. Anybody interested should go and have a look. And of course, if you are a vendor offering such a solution, you are very welcome to reach out directly to us and hopefully participate in this report. Right.
And for the audience that's listening, yes, this is something that is a new approach also to make transparent where we are in that research process, that we are, as you said, in the refinement of the market definition, but also really saying, okay, we expect this to be useful to both end user organizations and to vendors to participate here and to really extend, expand, and improve that overall zero trust market, it being so big. So we really want to make clear and transparent that this is a way to move forward.
And as you said, if you are a vendor providing solutions that you think fit into that overall architecture approach and to that platform approach and can significantly contribute, yes, please reach out. And for those who like me want to have a good approach for implementing such a zero trust platform that is stable, but flexible to extend for all types of identities, as you've described. And it's also stable for the next 10 years, and we don't know what happens. We talked about predictions. So this would be a good starting point.
So our request is really reach out to us, reach out to Alexei when you're a vendor, and to watch the space on the Coupling & Co website when it comes to learning more about zero trust platforms. Anything that I've forgotten?
Well, I would like to emphasize our approach has always been before starting something big, we should kind of pave the way for it with smaller, shorter, more digestible content for everybody to understand what it's actually all about. And I guess a good starting point would be a leadership brief on zero trust platforms, which was published on our website back in December, very close to Christmas time, I'm afraid for the state of your radar, but you can definitely revisit.
It's a very short document where I try to summarize all the things we've discussed in this podcast, but also give you a list of very kind of concrete suggestions, how to evaluate the potential importance of these solutions for your specific scenario, and what prerequisites to look for and what things to let everyone learn from others' mistakes instead of making their own. So definitely looking forward to your responses to that publication as well. Exactly. I think I highly recommend that leadership brief.
And as you said, smaller, more digestible formats before we go to a leadership compass like this podcast, that's the reason why we're talking about that. We really want to gain the attention of everybody who can reasonably contribute to that topic. And that's why we're here. We've made that claim. We made that ask towards you. So please follow up with us, watch the space because we will cover this as well and talk more about zero trust platforms, because I think that is really the sum of properly created security architectures, including identity and cybersecurity.
And I think that is really a good way to move forward. Alexei, thank you very much for giving that insight also into your research process. I think that's also shedding some light into things that usually happen more on your desk and where nobody has some insight into. And I think it's really great to have this transparency. And I'm really looking forward to reading this zero trust platform leadership compass in six months, seven months. That would be the timeframe, I assume.
Yeah, I expect it to be available sometime in summer. But before that, we will definitely not keep entirely silent. We will be offering more content or insights more into what's happening now and what's going to be happening in the future.
Again, let me reiterate, probably as a final takeaway for this episode, that zero trust platform is not a new kind of tool. It's not a new buzzword for vendor marketing. It's basically a way to package existing capabilities to make sure that they work together in a sensible and useful manner, that they offer unified coverage, unified visibility, and unified control. Because all those tools work great in very specific scenarios and use cases, but there is still no way to expand zero trust uniformly across the entire environment.
And zero trust platforms are exactly the market's attempt to deliver those kinds of solutions. I'm definitely looking forward to those because they are very useful and well, there's just no reason not to adopt them because they will make your entire security posture so much better.
Yes, I fully agree. And maybe a final thought from my side. One key topic that will be handled at the EIC in Berlin in May is making your identities zero trust ready. So zero trust identities. And this is something you don't have to wait for Alexei's report. You should have started with this years ago and you should be refining that just right now. And best practices and experiences will be shared at the EIC when it comes, for example, to zero trust ready identities. And I think that's a good starting point that then can be integrated into such a platform approach.
Again, thank you very much, Alexei, for being my guest today, running up to EIC and really, yeah, kind of shaping a market. That's great to see. Thank you very much. Thank you. And see you in Berlin, I guess. I think so. See you. Bye bye.