This article was originally published on WashingtonExec.
In today’s dynamically changing cyberthreat environment, everyone is a target. Security leaders face the ongoing, daunting challenge of protecting their organizations from increasingly sophisticated cyberattacks and AI-related threats. To do so, many organizations are turning to Zero Trust frameworks.
Zero Trust is a security approach intended to verify access at every point across the network. Permission is required for any component of one system to talk to another. The goal is to limit risk and ensure the organization is as prepared as possible to confront attacks.
However, Zero Trust can have unintended consequences. Overly onerous controls applied in unnecessary places can create burdensome obstacles for employees, customers, and partners, negatively impacting the efficiency of business operations and employee productivity.
As a leading space solutions provider, SES continuously works to strike the right balance in implementing Zero Trust security to protect both its complex satellite constellations in orbit and its highly sensitive communications and business networks on the ground. The following best practices have helped guide that approach:
- It’s About Strategic Risk, Not Technology: Zero Trust should be regarded as a business and risk management initiative first, as opposed to simply an IT project. Leaders should begin by identifying their most important assets, understanding the potential consequences of a breach, and determining where additional protections are needed. The goal is to make informed decisions as to where security investments will have the greatest impact.
- Not Everything Needs the Same Level of Protection: Not all organizational systems are equal. Some are more critical than others. A one-size-fits-all security strategy can create unnecessary complexity and frustration. Don’t try to make one very stringent policy work for everybody. Organizations should identify their most sensitive systems and apply those stronger Zero Trust controls where the stakes are highest, while opting for a more flexible approach for those less critical systems.
- Balance Security with Business Needs: The most effective Zero Trust security programs deliver security without impeding employees’ ability to do their jobs productively and efficiently. Employees, customers, vendors, and partners typically require some degree of access to information, systems, data, and applications. If security controls become overly burdensome and frustrating, security leaders may create inefficiencies that hurt the business.
- Adopt a Phased Roll-Out Approach: Implementing Zero Trust across an entire organization can be an overwhelming proposition. Rather than attempting to do it massively and all at once, organizations should start methodically with a layered approach, rolling out manageable projects and building from there. Create security zones to roll out programs in a systematic way. An incremental approach allows security leaders and teams to identify what works in real time and make the necessary adjustments as the program expands.
- It’s an Ongoing Process: Cybersecurity is never a one-and-done exercise. Business priorities change and threat environments grow more complex over time. Organizations should continuously monitor the effectiveness of their Zero Trust controls to ensure security measures remain properly aligned with business objectives and threats. Analyzing data and gathering feedback from users can help inform opportunities to improve and rally the much-needed support from the C-suite and Board.
Effective Zero Trust programs strike a balance between protecting assets and maintaining a positive experience for all stakeholders. As cyber threats continue to evolve, security leaders that pursue a thoughtful, flexible, and long-term strategic approach to Zero Trust will be better positioned to protect their organizations while still enabling the business to operate effectively.
The author, Vinit Duggal, is Senior Vice President of Service and Network Engineering at SES.


