- Event counts and blocked attacks measure activity, not protection.
- Zero Trust can be measured on two dimensions: readiness (business alignment) and fitness (operational state).
- Readiness is a periodic assessment with strategic, tactical and operational representatives together in the room; fitness comes continuously from your data.
- Strong on one axis does not compensate for the other: fitness without readiness is fragile, readiness without fitness is a slide deck.
Measuring security is hard. Not because we lack the data, but because most of what we measure does not answer the question we have.
Walk into any security review and you will see the same slides. Number of events. Number of blocked attacks. IOCs matched. Campaigns tracked. All of it is real data and all of it is useful, but mostly to threat intelligence teams. For an organisation that simply wants to not get breached, it tells you very little.
Take the number of events. What does it mean if that number goes up? It could mean you are under attack, but also that you improved your security. It could mean someone put a new device on the edge or that a noisy appliance started logging more verbosely. There are so many variables that the number(s) do not tell how well you are protected. A month with twice as many events is not twice as dangerous, and a quiet month is not a safe one.
So we end up reporting on activity instead of protection. And activity is often not what we aim for, most of us want a better security posture and simply not getting breached.
Measure prevention, not activity
The question is a different one: how well do we protect ourselves? Not how much noise came in, but how much of our infrastructure is covered and how well.
That is a prevention question, and Zero Trust is the strategy built to answer this. It is a structured way of deciding what needs your protection (your protect surfaces).
This is the first post in a short series. In this one I cover the two dimensions you should measure when it comes to Zero Trust; readiness and fitness. I also explain why the relationship between them makes or breaks a Zero Trust initiative. The scoring itself and how it maps onto CMMI maturity levels, is for the next blog post.
Two dimensions
There are two angles that matter when you look at Zero Trust in an organisation:
Dimension 1
Zero Trust Readiness
The alignment of the business.
Dimension 2
Zero Trust Fitness™
The current state of operations.
They are genuinely different measurements. Readiness is a periodic assessment. Fitness is continuous and comes straight out of your data. You need both, because an organisation can be strong on one and weak on the other, if that is the case your security posture will deteriorate over time as explained later.
In our Zero Trust reports we plot them as a quadrant. Like the Gartner magic quadrant, top right is where you want to be.
Readiness: Business Alignment
Misalignment is the primary reason why Zero Trust implementations fail. In almost every case the initiative started on one side of the organisation and never made it to the other.
If management decides Zero Trust is the new direction without involving the operational teams, the teams think and if you are lucky actually say out loud, “what do they know about our operations?” If IT operations starts a Zero Trust initiative on its own, management kills it by pointing at the budget, whether that budget is money or time. Either way the initiative bleeds to death and each team will blame the other for it.
This is why we built a Zero Trust Readiness Assessment. It measures how ready the business is on three levels: strategic, tactical and operational. And that means representatives of all three levels have to be in the room. Not a survey sent around by email, not one person filling it in on behalf of the others. All together.
That requirement is the whole point, and it has proven remarkably effective. When everyone is aligned, operational Zero Trust work simply gets done. A maintenance window for a change is no longer a negotiation, because the reason for the change is understood at every level. And the budget, mostly time, is available, since Zero Trust can largely be operationalised with the tooling you already have.
Signal
Alignment also decays. Businesses change, priorities shift, people come and go, and the Zero Trust programme quietly slides down the list. That is why the assessment is not a one-off. For most organisations once a year is enough; during an active Zero Trust project or in a fast-moving organisation, every six months is better.
In the quadrant this is the vertical axis. An organisation that was assessed recently sits at the top. One whose assessment is a year or more old sinks towards the bottom, a little further with every month that passes. It is deliberately unforgiving, because alignment that was true eighteen months ago is not alignment.
Fitness: Current Operational Status (your security posture)
Once the business is aligned, the next question is the current operational status, your security posture and if you are improving over time.
The biggest thing Zero Trust gives you here is insight. By defining your protect surfaces (step 1 of the 5 steps) you get a clear picture of your IT landscape. For every protect surface it is clear what it is, why it exists, what data it holds, who owns it, which compliance frameworks are applicable and how important it is to the business. From that information it is easy to define what controls should be in place.
Nobody will argue that the protect surface “guest WiFi” needs different controls than the CRM system, as an example EDR is often not needed on a “guest WiFi”. Yet in most environments we still do not make that distinction. This is not an oversight, we stop making the decision when systems get interesting. We will do it for the “guest WiFi”, but not for CRM, HR, ERP, CCTV, building management, the public website. They are all often in the same (or routable) network without specific controls. With this in mind, it becomes relatively easy to measure your current state, your fitness.
Question 1
Do we know our environment and is the information up-to-date?
Protect surface metadata is important. Is the business owner for CRM still with the company? Is the security contact still in that role? These findings will tell you how well you are in control.
Question 2
Are the right controls in place?
For every protect surface you assign which controls it should have, either from your own requirements and/or from a compliance framework. Then you check which of those are actually implemented. This will give you per protect surface, a straight answer to “how well is this protected”.
Question 3
How large is the blast radius?
Which protect surfaces are allowed to talk to each other and which are not? The guest WiFi being isolated is obvious. But we still regularly see CRM, HR and CCTV able to reach each other without restriction. This allows for lateral movement and it turns one compromised system into an organisation-wide incident, this is how most cyber-incidents evolve into catastrophic incidents nowadays.
All this information you should already have, we store it in our AUXO™ portal and it is the reason why our fitness score can be retrieved live. It will also change when your environment changes. This score is plotted on the horizontal axis of the quadrant.
Why both are important
The four corners of the quadrant describe situations most people will recognise.
Top left
All talk and no traction: a recent assessment, strong intentions, very little built. The commitment is real but nothing has landed yet.
Top right
Mature Zero Trust: assessed recently and actually implemented. That is the goal, and it is a state you maintain rather than reach.
Bottom left
Early stage: foundations forming. Fine as a starting point, a problem as a destination.
Bottom right
Fragile or unsanctioned: a lot has been implemented, but the last assessment is long overdue. Usually this is a good engineer “sometimes even called a hero” or a good team doing the right thing without a mandate. It works, right up until that person leaves or until someone asks who approved this.
Signal
Being strong on one axis does not compensate for the other. Fitness without readiness is fragile. Readiness without fitness is a slide deck.
Conclusion
Measuring security is hard, but measuring Zero Trust is not. You need two perspectives. First is business alignment because without alignment the initiative will bleed to death regardless of how good the technical plan is. Second, what is the current state, because plans without execution will protect no one.
Both are measurable by following the five steps of Zero Trust and simply measuring each of them. You can do this yourself with a spreadsheet and discipline. We built it into AUXO™, our platform, so you can see where you stand on any given day.
In the next post I will go into how the Zero Trust score is built up and how it aligns with CMMI.
Related reading
- Zero Trust isn’t hard
- Navigating Zero Trust, part 1
- The crucial role of business alignment in Zero Trust
- Zero Trust as a new year’s resolution
- You don’t need additional AI security tooling
Get in touch
Where does your organisation sit in the quadrant?
Reach out to plan a Zero Trust Readiness Assessment with your strategic, tactical and operational teams, and see how your fitness score is measured live in AUXO™.
Reach outFAQ
How do you measure Zero Trust?
On two dimensions. Readiness measures business alignment through a periodic Zero Trust Readiness Assessment with strategic, tactical and operational representatives together. Fitness measures the current operational state continuously from your data: whether protect surface information is up to date, whether the right controls are in place, and how large the blast radius is. You need both.
Why don’t event counts tell you how secure you are?
Because the number has too many explanations. More events could mean you are under attack, but also that you improved your security, added a device on the edge, or that a noisy appliance started logging more verbosely. A month with twice as many events is not twice as dangerous, and a quiet month is not a safe one. Event counts measure activity, not protection.
What is Zero Trust readiness?
Zero Trust readiness is the alignment of the business. It is measured with a Zero Trust Readiness Assessment on three levels: strategic, tactical and operational. Representatives of all three levels take part together, not through a survey sent around by email. When everyone is aligned, operational Zero Trust work gets done, because the reason for a change is understood at every level.
What is Zero Trust fitness?
Zero Trust fitness is the current state of operations: your security posture. It comes continuously from your data and answers three questions. Do we know our environment and is the information up to date? Are the right controls in place for each protect surface? And how large is the blast radius, meaning which protect surfaces are allowed to talk to each other?
How often should you run a Zero Trust Readiness Assessment?
Alignment decays as businesses change, priorities shift and people come and go. For most organisations once a year is enough. During an active Zero Trust project or in a fast-moving organisation, every six months is better. An assessment that is a year or more old counts for less with every month that passes.
Why do you need both readiness and fitness?
Being strong on one does not compensate for the other. Fitness without readiness is fragile: a lot gets built, but it depends on one engineer or team working without a mandate. Readiness without fitness is a slide deck: strong intentions, very little implemented. Mature Zero Trust means both a recent assessment and controls that are actually in place.
