Q1. How will 5G impact security? How should organizations be preparing for a 5G future?
Standalone 5G is more secure than previous network generations but expanded attack surfaces will create opportunities for new threats and an increase in unpatched existing threats. In our annual AT&T Cybersecurity InsightsTM Report, we found that 56% of respondents believe that 5G may require a change to their security approach to accommodate network changes.
With 5G, a shared responsibility model, similar to the public cloud, is likely to emerge. This should enable enterprises to focus on assessing their cybersecurity posture and how they are going to address risks with IoT devices and other endpoints as well as applications that access the 5G network. Organizations also need to consider security for all the data being created and stored on the network.
The use cases for applications optimized for a 5G network are virtually endless including smart cities and remote surgery to others that are emerging for businesses including private 5G on campus, multi-access edge compute and industrial IoT. What is necessary to make these ideas a reality? Applications. The applications making these ideas a reality are no longer limited to back office business applications. These are now mission critical and in some cases life critical applications. The software behind these applications must function properly, perform fast enough, and be highly secure. Cyber adversaries will attempt to target these new applications through un-remediated vulnerabilities. Focusing on non-functional requirements, which includes security, is something organizations should be focused on. Disciplined software engineering practices should include security from the beginning.
Adopting a Zero Trust mindset allows organizations to be proactive about securing the data, users, applications, and endpoints attached to the network. Ninety-four percent of our Insights Report participants are on a Zero Trust journey – either researching, implementing, or completing it.
Q2. What are some of the security and business advantages of SASE? Why might a managed services approach be essential for SASE?
SASE allows organizations to modernize the network, simplify security, and improve the user experience and visibility. Network performance is accelerated while network reliability is improved, connecting remote users directly to the internet for faster access to business-critical data. Visibility is centralized across users, devices, and locations to apply granular security policies that follow users whether they are on or off the network to deliver a consistent, productive experience and reduce security risks. As a cloud-delivered solution, SASE is also highly scalable, allowing organizations to expand or contract as business needs change to add new users, locations, or acquisitions.
While the transition to a SASE framework may take time to fully implement, organizations that adopt this approach sooner rather than later will benefit and maintain a competitive advantage over other companies in the market. A managed services approach to SASE brings network and cybersecurity technical expertise together with design configuration, deployment and 24/7 management from a single provider. This helps provide consistent, high-performance access to applications while enabling and protecting the global workforce at the edge.
Our team helped architect and deploy a solution for dozens of [one] healthcare service provider's remote sites, including an international call center, and thousands of remote employees. The solution included deploying SD-WAN at the remote sites, which improved application performance within the clinics and the call center, and improved network performance overall. The customer also deployed a cloud-native, secure web gateway solution, which centralized and simplified security policy management and improved access management and control for employees and the business whether on site or working from home. By virtualizing its network and security controls, the customer can save on its infrastructure costs and quickly adapt to the needs of its business, whether by adding more remote sites to meet patient demand or provisioning new employees.
Q3. What is AT&T Cybersecurity's plans at Black Hat USA 2021? What can security leaders expect to hear from AT&T at the event?
AT&T Cybersecurity activities at Black Hat USA 2021 will kick off on August 3 with our participation in the Virtual CISO Summit as we present two sessions, "Safer to Innovate" and "Today's CISO – Leading a Resilient Enterprise." As the role of CISOs has evolved, these sessions will offer best practices for creating a security-first mindset across an organization and how a risk-based approach to cybersecurity can best help defend against increasing cybersecurity threats.
While this year's Black Hat is a hybrid event, AT&T Cybersecurity consultants and product experts are ready to meet attendees at our virtual booth and we will also have technical sales consultants and sales staff at the live event. Our virtual booth will feature our Managed Security Services and Consulting offerings for Threat Detection and Response, DDoS Defense, Vulnerability Management as well as content on protecting the remote workforce, Zero Trust, 5G and cybersecurity, and more.
In addition, we will be presenting a virtual joint session on SASE with Palo Alto Networks that will cover the tenets of an effective SASE solution and benefits of a managed service. Also, attendees interested in understanding more about Zero Trust will benefit from our two virtual workshops, "Part 1: Zero Trust Fundamentals" and "Part 2: Zero Trust for the Mature Organization."