Unpopular opinion: The obsession with "zero trust" is misguided. I believe in a defense-in-depth strategy that focuses on multiple layers of protection, rather than assuming everything is a threat. Am I wrong, or does anyone else think we're focusing too much on the wrong things?

likesmart
Posting as :
works at
You are currently posting as works at

You may be right. But zero trust is a federal mandate and firms will try to sell their services to their clients based on these mandates. I’ve come to learn that it’s not actually about the best approach, it’s more about what can make the most money.

like

Couldn’t agree more with that. But also wanted to add onto making the company the most money, is saving the company money too. And putting in policies that may seem overkill is exactly what they’re intentions are. Best working approach has to adhere to that money prospect, obviously a business but still.

Zero trust was born out of the extended connectivity between different public and private technology infrastructures. The concept was then taken and developed further to apply within a single organization as well. Depending on the size and complexity of the organization, Zero Trust might or might not be considered an overkill. However, for Defense in Depth, there is no question about that. Ultimately, this all decided based on an organization's risk profile.

like

Both defense in depth and zero trust are just general concepts. They are both good and you should be using both.

Related Posts

Any recommendations for grow lights that can be moved around?

like

Can we use salesforce mobile for personal purpose like clicking photos and transfer it to another mobile

How time it will take to reach 19LPA from 15LPA fixed at EY GDS for average performance.

Post Photo
like

What is the best advice you would give to a junior account manager?

like

Does anyone have experience confronting workplace inequality? Any lawyer recommendations? Things to say/not say?

I don’t trust HR and I don’t know what to do.

Can you advise a young producer on working with exec creatives? How do you assert yourself & hold teams accountable to deadlines without making creatives feel as though you are challenging authority?

like

Sorry for going somewhat off-topic but I figure this is a good crowd to ask: anybody have a fountain pen they like below 200€? Looking to graduate from stealing ACN’s disposable pens, but I want to ease into it in case I lose it (pen won’t be strapped around my wrist)

like

Hey there
Can somebody help me with the avg salary of wn an analyst (with almost 3 years experience overall) in the Marketing domain? In Hyderabad region.

Thanks in advance for your help.

Hi Fishies, Im a application suport engineer with 7 years of experience. Java and dotnet, sql application. Please refer me for opening with immediate joiner

like
like

How many interviews did you go through before you found your exit offer?

like

I just finished the book I was reading. What should I read next?

like

I think we should create a compensation thread in this bowl. It would help a lot of people who are planning to switch companies/jobs or who are moving to this region. Just a thought, since it’s one of the most common questions asked here.

likeuplifting

What to do if you haven’t heard from the embassy for 75 days. They have my passport. I came in for my H1B interview, VO told me it’s approved and I shall have my passport in 5 days. It’s in AP cont.

Does EY file for I140 under premium processing by default, or would I need to request for this explicitly?

Is there a reason why my company would need to file perm for me if I'm on L1A? I started with L1B in the US and then switched to L1A after promotion to manager.

like

What’s the current timing of biometrics appointment after AOS filing?

like

Which navigation apps do you prefer using besides google maps for driving long distances?

like

Taking a relative who has never travel abroad to Italy - spending a few nights in Florence - any great restaurant recommendations ?!

like

FINALLY found my motivation after 11 days of busy season... at 2am... when I have to be to work at 8am the next day.

like

Additional Posts in Cyber Security Bowl

Security TPM on-site at big tech, how would you prepare/review? No coding. Expect high level q’s on vuln. Analysis& arch. design from security POV. I do NOT have an engr. Background. 1wk to prep

like

I have a younger family member (almost 13) who is very interested in cybersecurity. How can this person learn and grow in a safe manner if he/she isn’t near a city with youth clubs and etc? Idea is to reinforce ethics, but this material is far too advanced for the parents.

like

Views on carbon black as a product?

helpful

Exit opps at a manager level - Big4 vs industry jobs? Security Architect at FAANG vs the normal career path at PwC. If compensation being slightly better at FAANG, which one would you pick and why

like

Tell me it’s not true.

Post Photo
funnylike

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Has anyone made the move from cyber security at the Big4 to cyber security for media companies? For example Disney or Warner Bros.

How did you manage it?

like

Folks, best password manager and why?
Many thanks!

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Anyone ever heard of or worked for Sygnia?

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

I’m a woman in my mid 20s and constantly face situations where people outside of cyber (still within the company) that I’m dealing with (older men in particular) who always push back against my cyber/technical recommendations even with managers cc’d. I studied, earned certs, and worked hard to get to where I am. Is it bc of my gender and age? In all honesty, I’ve written recommendations that male counterparts voiced in the past that had ZERO pushbacks.

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

Any company is hiring EU citizens and helping with visa? interested in moving to USA. I'm lawyer, cissp, cisa, cipp/e and specialized n data privacy, cybersec ops and risk management with 8+ years exp

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal