Group Purchasing
Group Purchasing

Navigating the Path to a State of Zero Trust in 2024

Navigating the Path to a State of Zero Trust in 2024 (PDF, 2.64MB)Published: 15 Jul, 2024
Created by:

Navigating the Path to a State of Zero Trust in 2024, published by SANS Institute in 2024, examines the organizational and technical challenges CISOs and security practitioners face when implementing Zero Trust architecture (ZTA). The paper draws on third-party research alongside SANS's own frameworks, including the DARIOM lifecycle developed for its SEC530 course, to address stakeholder buy-in, framework design, measurement, and staffing across the Zero Trust adoption journey.

Key findings:

  • More than 80% of all data breaches are attributed to employee error or negligence
  • Humans were involved in 68% of breaches in 2024, either through error or social engineering, according to Verizon's Data Breach Investigations Report (DBIR)
  • Over 40% of successful social engineering attacks were business email compromise (BEC) or CEO fraud schemes, with a median cost of $50,000 per breach, per Verizon's DBIR
  • Supply chain attacks go undetected for an average of 235 days after initial entry, according to IBM's 2023 Cost of a Data Breach Report
  • Gartner forecasts that 45% of organizations worldwide will have experienced supply chain attacks by 2025, a three-fold increase from 2021
  • 39% of organizations in a World Economic Forum study became collateral damage from a third-party cyber incident
  • Nearly 50% of IT professionals describe collaboration between security risk management and business risk management as poor or nonexistent, per NIST
  • More than 63% of enterprises struggle to implement Zero Trust frameworks, according to Forrester research
  • Gartner predicts that by 2026, only 10% of large enterprises will have a mature and measurable Zero Trust program in place

Across every dimension examined, the paper frames Zero Trust not as a product to install but as an organizational shift that succeeds or fails based on culture and buy-in as much as technology. The consistent theme is that human factors, stakeholder alignment, and change management determine whether a Zero Trust framework actually matures, while the technical architecture itself is the more solvable half of the problem. The paper structures Zero Trust adoption around seven system components: user, devices, network and environment, applications and workloads, data, visibility and analytics, and automation and orchestration, and references CISA's Zero Trust Maturity Model 2.0 as the standard for phased rollout.

FAQ

More than 80% of all data breaches are attributed to employee error or negligence, and Verizon's 2024 DBIR found humans were involved in 68% of breaches through error or social engineering. 

Supply chain attacks go unnoticed for an average of 235 days after the initial entry point, according to IBM's 2023 Cost of a Data Breach Report. 

Forrester research found that more than 63% of enterprises struggle to implement Zero Trust frameworks, often due to organizational resistance and poor alignment between security and business risk management rather than purely technical obstacles. 

The median cost per BEC breach is $50,000, according to Verizon's 2024 Data Breach Investigations Report. 

Gartner predicts only 10% of large enterprises will have a mature and measurable Zero Trust program in place by 2026. 

Meet the Expert

SANS Institute
SANS Institute

SANS Institute

Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.

Read more about SANS Institute