Public sector organizations are facing a crisis of heightened susceptibility to cyberthreats, due to their dependence on legacy IT systems and processes. At the same time, their vast collections of citizens’ data make these organizations attractive targets for cyberattacks, which are increasing in frequency and sophistication with artificial intelligence (AI) tools.

“AI has undoubtedly contributed to the significant rise in cyberattacks, including in the public sector, with the most recent data showing a very significant increase in AI-driven attacks such as AI-enabled phishing, deepfakes, and automated malware. Whilst there are benefits to be obtained by the deployment of AI tools across the public sector, we must not ignore the increased attack surfaces that adversaries could exploit,” says Freha Arshad, managing director of Accenture Security’s Health & Public Service Practice.

The need to modernize public sector network architectures for improved resilience against modern attacks and attack vectors is clear.

Legacy architectures often leave “flat” internal networks, vulnerable cloud workloads, and nonsecure devices open to increased risk exposure. These outdated infrastructures lack the agility and zero-trust principles needed to protect against cyberattacks, which can rapidly exploit vulnerabilities, move laterally, and compromise critical systems at unprecedented speed.

A zero-trust strategy can eliminate or reduce many threats and improve operational resilience. Instead of making perimeter-based “implicit trust” assumptions, zero-trust platforms ensure that users, workloads, and applications are granted exactly what’s required and that their identity is verified.

Transitioning to modern cloud-based networks based on zero-trust architecture is the logical path to a more performant, resilient infrastructure that can securely enable AI tools, but it can be a complex and costly process. This is especially true for large entities that are struggling with technological debt and limited budget flexibility and are challenged in attracting top cyber talent due to compensation constraints. A strategic step-by-step path to modernization is required.

“Some of these public sector monolithic systems are gigantic and could take years to transform, so it is critical to focus on what is most exposed and to work on a road map that looks to modernize those estates and applications on a prioritized-risk basis,” says Arshad.

Start with a big-picture view to guide your network transformation to a zero-trust model, including these first steps, before deploying new technologies or retiring legacy solutions:

  1. Identify critical assets. Categorize critical data and applications that must be secured.
  2. Assess the current environment. Identify gaps and risks; list users, devices, and applications accessing network resources.
  3. Adopt a zero-trust philosophy. Enforce least-privilege access, and verify requests for access.
  4. Establish a robust policy framework. Define access policies; incorporate role-based access and continuous monitoring.
  5. Deploy core zero-trust technologies. Replace virtual private networks (VPNs) with modern solutions such as Zero Trust Network Access. Use network traffic-monitoring tools to ensure visibility across all traffic and devices.
  6. Remember the humans. Prioritize the user experience as a foundational element of any zero-trust strategy.

Deciding to reduce legacy network technology is the first step on the path to network transformation and dramatically improved cyber resilience.

“With a modern zero-trust architecture (ZTA), you’re not building on a fragile foundation of legacy technologies; instead, you’re evolving with the threat landscape,” says Zscaler Public Sector Field CTO Patrick Perry. “A truly cloud-native ZTA platform eliminates technical debt by continuously adapting to new risks, ensuring your security scales seamlessly as threats grow more sophisticated.”

Learn more about implementing cyber resilience in the public sector through zero-trust transformation. Or read about cyber resilience in FSI and manufacturing.

Share
Share