
Cybersecurity Standup · 2024-07-09 · 15 min
Key moments - from our scoring
Substance score
32 / 100
Five dimensions, 20 points each
Jason Garbis brings a decade of experience in zero trust (formerly software-defined perimeter) to discuss how enterprises can design and execute effective zero trust programs. He contrasts his two books: the comprehensive Zero Trust Security and Enterprise Guide, which examines zero trust implications across VPNs, networks, cloud services, and identity management systems; and the more accessible Getting Started with Zero Trust, which outlines five practical on-ramps including VPN replacement, cloud migration, DevOps administrator access, and business process access. Garbis emphasizes that zero trust is fundamentally a security strategy, not a technology purchase - a critical distinction as enterprises increasingly recognize they must simplify complexity and focus on getting basics right rather than over-engineered solutions. He also discusses government leadership from CISA and NIST, the Secure by Design initiative as a self-regulatory framework superior to checkbox compliance, and his hope that zero trust will mature from buzzword status into implicit best practice within five years.
The Zero Trust Security and Enterprise Guide is comprehensive and technical, analyzing zero trust implications across VPNs, networks, cloud services, and identity management, plus program design strategies. Getting Started with Zero Trust is shorter and more accessible, outlining five practical on-ramps (VPN replacement, cloud migration, DevOps access, business process access) with before-and-after scenarios for first zero trust projects.
Zero trust is a security strategy and lens for evaluating risk, not a product to buy. It requires implementing least privilege, detecting compromises, and containing blast radius across all aspects of digitized enterprise operations.
Secure by Design is a framework of guidelines published by CISA that enables software vendors and enterprises to self-regulate without the burden of checkbox compliance often imposed by legislation, delivering better security outcomes.
The five on-ramps are VPN replacement, cloud migration, DevOps administrator access, business process access, and identity governance - all common ways organizations begin their zero trust journey.
Jason hopes zero trust will become so embedded in security philosophy that it becomes implicit best practice, no longer discussed as a buzzword but rather as a foundational strategy applied across enterprise operations.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is a 15-minute trade-show floor promo chat that cycles through generic Zero Trust talking points and book promotion with almost no novel ideas per minute. The few substantive claims - the federal government's role, the 'stop the madness' complexity fatigue - are stated but never unpacked with depth or mechanism.
Zero Trust definitely went through a phase of being a buzzword. And I think we're fortunate that it's been supplanted by AI as the latest buzzword.
zero trust is a security strategy. And what that means is it's something you do. It's not something you buy.
Every take here is a well-worn Zero Trust cliché - strategy not a product, least privilege, blast radius, AI replaced zero trust as the buzzword. Nothing contrarian, first-principles, or counterintuitive surfaces; the conversation reproduces the standard industry consensus without interrogating it.
zero trust is a security strategy. And what that means is it's something you do. It's not something you buy.
How do I apply least privilege? What happens if this machine or this network or this device is compromised? How do I defend myself against that? How do I contain the blast radius?
Jason Garbis is a credible, long-tenured Zero Trust practitioner - co-chair of the CSA Zero Trust working group, two published books, ~10 years in the space, founded an independent advisory firm after time at RSA. He is a legitimate educator/advisor, though more consultant than a CISO or operator who has deployed Zero Trust at enterprise scale.
I work with enterprises for the most part, providing independent and vendor agnostic guidance on how to define and execute on effective zero trust strategies.
I co-chair the zero trust working group at the Cloud Security Alliance.
Concrete evidence is almost entirely absent - no named client examples, no metrics, no timelines beyond 'close to 10 years,' no dollar figures. The five named on-ramps (VPN replacement, cloud migration, DevOps, administrator access, business process access) are the only specific taxonomy offered, and they are not explained with data.
looking at VPN replacement cloud migration DevOps administrator access and business process access Those are all very common ways that organizations get started with zero trust
the SEC actually criminalizing certain activities. That hasn't really made its way to regulations yet.
The host consistently defers, agrees, and compliments rather than probing - calling Jason 'one of my favorite people,' praising book-writing as 'a huge accomplishment,' and offering zero pushback on any claim. Questions are broad and future-gazing rather than pointed follow-ups designed to extract specific, testable insight.
Jason, you've written two books. That's a huge accomplishment. What is it like to be an author?
I have both of these books signed by the author himself. So thank you for doing that for me.
Computed from the transcript - who did the talking, and the words that came up most.
Hey everyone, welcome back to "Cybersecurity Stand Up," your favorite spot for all things cybersecurity. Today, we’re coming at you live from the lively Tics Booth at South Moscone. We've got the amazing Jason Garbis with us, and trust us, you don’t want to miss this! Jason’s the go-to guy for all things Zero Trust. He’s been at it for nearly a decade, and he's here to drop some serious knowledge. We'll chat about the Secure by Design initiative, striking the right balance between compliance and actual security, and his two must-read books on Zero Trust.
Transcribed and scored by The B2B Podcast Index.
You do have proactive things that are happening, like the Secure by Design initiative that CSI published. I thought that was great. You know, hopefully that would be kind of the landing point for us, which is a set of guidelines, something that's a framework, but it's not compliance driven. It's not driven by legislation to hopefully allow us, software vendors as well as enterprises, to really self-regulate in a way that gets the best outcomes, which is what we want, but It doesn't burden organizations with too much checkbox compliance, which can be, unfortunately, the byproduct oftentimes of legislation.
Okay, hi, everyone. Welcome back to Cybersecurity Stand-Up, your favorite cybersecurity podcast. I am at the Updix booth, number 427 in South Moscone. But I got to say, the floor is bustling.
It's a little sweaty, a little loud, and it's very, very fun. And today I have a returning guest for the podcast, Jason Garbus. Jason has got to be one of my favorite people right now because I can feel that I have a lot to learn from him, which is one of my favorite things. Jason, in case people haven't heard of you, which they probably have, can you tell them a little bit about yourself and what you do at the moment?
Yeah, sure thing. So thank you for having me here. So what I do is I do a lot of work around Zero Trust. I work with enterprises for the most part, providing independent and vendor agnostic guidance on how to define and execute on effective zero trust strategies.
And I've been limited in the zero trust world for close to 10 years, even before we called it zero trust. So what I'm doing now is I have an independent business where I provide these advisory services called Number Line Security. I also chair, co-chair the zero trust working group at the Cloud Security Alliance. And that's a really interesting volunteer role.
And if folks are interested in learning more about zero trust or getting involved, the CSA is a great organization to do that. We're always looking for motivated and interested volunteers. So through those roles, I had the opportunity to talk to a lot of different enterprises about how they're approaching zero trust. And that really prompted me to write the books that we're going to talk about, as well as to try to coalesce all of this into a consulting framework and a consulting approach around determining or designing effective zero trust programs.
Let's talk about your books right now because I have them in front of me and I want to read them immediately. So if you've listened to the podcast before with Jason's episode, you've probably heard us talking about this one, which I have with me, which is getting started with Zero Trust. But the real deal, which is what, a pound and a half heavier? He's got some real punk factors.
Yeah, exactly right. It's the Zero Trust Security and Enterprise Guide. So Jason, can you tell me a little bit about what's the difference between these two books? What can people find in each one?
So the first book, so the Zero Trust Security and Enterprise Guide, is much more comprehensive. And it talks about definitions of zero trust. It gives our perspective on it. And it also does an analysis of what does zero trust mean for every facet of security and IT infrastructure?
What does it mean for VPNs and for networks? What does it mean for cloud services? What does it mean for your typical identity management systems? So it looks at all those facets.
And then the last third of it really talks about how to design an effective zero trust program, ways to overcome obstacles, et cetera. The second book is an easier read. It's shorter. And what it does is it outlines five different what I call on ramps towards zero trust and analyzes each of those and explains, here's how you can approach it and use this as a way for your first zero trust project.
So it looking at VPN replacement cloud migration DevOps administrator access and business process access Those are all very common ways that organizations get started with zero trust And for each of those we talk about the before and the after whether you could do that with traditional tools and ways to be successful with it. So the audience for these books feels a little different. What would you say it is for each of these? I'd say that in both cases, if you're a security practitioner or a security architect, even an enterprise architect, that both of those could be useful for you.
And the first book is definitely a little heavier and a little bit more technical. There's not code in any of them, but there's a little bit more advanced concepts in terms of integration and interactions. So when I had you on the pod previously, I asked you a little bit about your background. But I'd love to hear just a little bit more about like before Zero Trust was called Zero Trust.
What were you doing? What was your position like? Like, how did you get to where you are now? I don't know how far back in time you want to go because I'm pretty old.
So I started my career as a software engineer, and I did that for close to 10 years. I really enjoyed that role. It was a long time ago using now obsolete technologies. But the concepts of building network and building distributed systems really stuck with me.
And then I moved into a series of technical consultant roles and product management roles mostly for middleware and integration companies. And then about, gosh, it's almost 15 years ago at this point, I started working at an identity management company. So we focused on identity governance and automated identity lifecycle. And that really got me with both feet into the security world.
So I stayed at that company for a couple of years. We got acquired by RSA and I stayed there for a few years. And then I moved into what at the time was called the software defined perimeter. Today we call Zero Trust.
It really grew into the industry tsunami that we're a part of today. So I was able to, when I joined that company, I discovered the Cloud Security Alliance and the software defined perimeter working group. So I joined the working group. I started to volunteer and help lead research white papers and ultimately rose up to be one of the co-chairs of that as we also grew the scope of it to match what was happening in the industry around zero trust.
Amazing journey. And one thing else we talked briefly about this, I think, on the podcast before is that how much has changed in the past five years, basically, with cloud security specifically. When it comes to zero trust, what's changed or what's evolved within the framework of zero trust in regards to cloud security specifically? We've seen a lot more, I would say, maturity and rigor for sure.
And part of it is driven by the investment that the U.S. federal government has put in, really taken a leading role, which is pretty remarkable and I think pretty unprecedented. So it's great to see CISA and NIST putting in effort and publishing these documents that are really, really useful for the industry.
And they're useful in a way that is really independent of the infrastructure, whether it's cloud infrastructure or whether it's on-premises are hybrid, these concepts really apply. I think that Zero Trust definitely went through a phase of being a buzzword. And I think we're fortunate that it's been supplanted by AI as the latest buzzword. So now we can get away from it being a buzzword and focus on actually delivering value with it.
And that's really where we are, I think, in its phase is I spent a lot of time talking to enterprises and there's a pretty big spectrum of their relative readiness or their actual progress on the journey. But there is a ton of interest and a lot of people really want to know, well, how do I get started? How do I do it quickly? Which is one of the reasons that motivated me to write the second floor.
Really cool. And I mean, you're really right that in terms of the trends that we're seeing, especially when you look around the trade show floor like this, I would say last year I saw AI on everybody's booth, no matter what they were doing or if it was like relevant or not. But this year I not seeing it as much Have you had a chance to walk around yet I really haven looked at it from that perspective I think everyone is talking about AI for sure And maybe they just assume that of course we doing AI right So in terms of other trends that you seeing maybe emerge right now or that are like at the top of their game, anything that you're seeing that you either love or that you hate, that you're responding to?
Well, I hate vendors that, you know, just try to be buzzword compliant and don't have any real substance behind it. and I certainly hate ones that are a little bit too aggressively selling as opposed to trying to deliver value. I think that on the enterprise buyer, there's definitely a trend toward recognizing that we're at a kind of a stop the madness moment, right? Let's try to recognize that we have too much complexity in our environment, and we want to really try to simplify things, get the basics done well, and not try to deploy or purchase something that's over-engineered and more complex for us to effectively manage.
I hope that's a, you know, get out of the madness moment because I want us to get through that. Like it's time, you know? Yeah, exactly. No, it's really, it's unfortunate that the threat landscape and the adversaries are taking advantage of all these new tools that are becoming more effective and the stakes are too high for us not to up our game.
It's also really interesting to hear your thoughts about the regulations that have come down. And Like, obviously, when you have government bodies that are facilitating change in a specific industry, that is momentous. It's kind of unprecedented was the word you used, and I agree with you. Is there anything that you predict coming down from the government that might also impact the cybersecurity industry or maybe zero trust frameworks in a positive way?
Anything you're expecting or hoping for, maybe? I think that there's, I mean, there's certainly legislation that has happened, for example, in European Union around privacy. We haven't seen that here. there's definitely a more assertive regulatory governance that's happening, like the SEC actually criminalizing certain activities.
That hasn't really made its way to regulations yet. You do have proactive things that are happening, like the Secure by Design initiative that CISA published. I thought that was great. Hopefully that would be the landing point for us, which is a set of guidelines, something that's a framework, but it's not compliance driven.
It's not driven by legislation to hopefully allow us as software vendors as well as enterprises to really self-regulate in a way that gets the best outcomes, which is what we want, but doesn't burden organizations with too much checkbox compliance, which can be, unfortunately, the byproduct oftentimes of legislation. I hear that. And I really like compliance. It's the kind of weird thing.
I feel there's a lot of positivity and compliance, but that's not an opinion you hear very often when it comes to compliance, I think. It is not. So I'll just, you know, I like it. So sue me.
Yeah. You know, one thing I also want to ask you about is the fact that you've written two books. That's a huge accomplishment. What is it like to be an author?
What was that process like for you? I really enjoy the writing process. It is labor and time intensive. So, you know, it is a conscious decision to say, okay, for the next, you know, 8, 10, 12 months, I know that I'm going to have to take weekend of the evening time and not do other things, you know, with my family.
You know, I remember so many evenings when I was writing the first book of, hey, dad, why don't you sit with us? We're watching this movie or this show. I'm like, no, sorry, I can't. I got to finish this chapter.
And, but you know, it's, I'm a runner too. I've run one marathon and about four half marathons. And it's a matter of just putting in the time sometimes and grind it out. So I do like the writing process.
It's not always easy. And some days you sit down and you work for three hours and you be like wow I wrote a chapter And other days you sit down you write you work for three hours you write I wrote two pages Not because you stuck but because the thought process and the amount of research you need to do to get it right just requires that That must certainly be the case specifically with the technical material. Would you say that is the case? Oh, yeah, absolutely.
No, there's a lot of research that has to come in. I mean, that's not just putting down my ideas, which in itself is hard because they have to mesh. but doing so in a way that reflects areas that maybe I don't have at my fingertips. And I have to do some research and write in and talk to people about this, get validation, get feedback.
Really cool. Okay, so I want to also talk about sort of a forecast. Like what if, let's say that five years from now, we're back here at RSA. You're sitting at my little podcast table.
I've got in the middle of a booth somewhere. What do you think we're going to be looking around seeing? What are some conversations we're going to be having in five years' time? Is Zero Trust going to be right up there in terms of hot topics?
I hope that in five years, Zero Trust has become so baked into our philosophy that it's just kind of become implicit. It's like best practices. So I don't know what we're going to be talking about in five years. I hope it's not blockchain.
It's going to be some other buzzword, right? But I think that Zero Trust is a little bit unique because it's not a technology. It's a strategy. And it's a set of lenses that we use to look at our world through.
And as we learn new things, if they work, they should be added to our arsenal of best practices that we apply. If there was one thing you feel like is being lost in the ether when it comes to zero trust, like maybe people who are seeing it, they know of it as a buzzword. Maybe they think it's something it's not. But what's one thing that you wish you could communicate to a more general population, even within the industry, about zero trust?
Well, it's certainly that zero trust is a security strategy. And what that means is it's something you do. It's not something you buy. And the reason that that's the case is that we have reached the point where our enterprises are 100% digitized.
So everything that we're doing is driven by, tracked, and managed by software. And what does that mean? That means that everything that everyone in our companies is doing every single day needs to be secured. And that's why zero trust has to be a strategy.
You have to look at everything that everyone is doing and look for the weak points there and say, all right, how do I apply least privilege? What happens if this machine or this network or this device is compromised? How do I defend myself against that? How do I contain the blast radius?
How do I detect that? All these things that we struggle with as enterprises because this is complicated stuff. That's a nice reality check as well. It's like okay to acknowledge that it is complicated and fast moving.
Yeah, absolutely. Well, in case people want to find you and or your books, both of them, where can they find you? So I would encourage people to look at my website, numberlinesecurity.com.
I'm also pretty available on LinkedIn, so feel free to reach out to me and we can start a conversation there. And then your books are available wherever books are sold? What are we talking here? Yes, wherever books are sold.
Yes. Wonderful. Jason, thank you so much for your time. You've come on the pod digitally before, and it's a privilege to meet you in person.
I have to also tell the audience that I have both of these books signed by the author himself. So thank you for doing that for me. I really appreciate it. And I hope you have a beautiful rest of the show and learn lots of really cool things.
Thanks for your time. Great, thank you. Thanks for joining us, everyone. And we'll see you next time out in cyberspace.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.