<?xml version="1.0" encoding="UTF-8" ?><!-- generator=Zoho Sites --><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><atom:link href="https://www.viszensecurity.com/blogs/network-security/feed" rel="self" type="application/rss+xml"/><title>Viszen Security - Insights , Network Security</title><description>Viszen Security - Insights , Network Security</description><link>https://www.viszensecurity.com/blogs/network-security</link><lastBuildDate>Wed, 24 Dec 2025 02:15:51 -0800</lastBuildDate><generator>http://zoho.com/sites/</generator><item><title><![CDATA[NEW Zero Trust Guidance for OT/ICS]]></title><link>https://www.viszensecurity.com/blogs/post/new-zero-trust-guidance-for-ot-ics</link><description><![CDATA[<img align="left" hspace="5" src="https://www.viszensecurity.com/Tue Nov 05 2024.png"/>We co-authored a guide with CSA explaining how to operationalize zero trust in OT/ICS environments, including mapping to existing guidance and frameworks like ISA 62443.]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_y63d7UHlQzm4TYmYrVfy6w" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_hCaIM6njTb6TiylAHrepQA" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm__tdMnDUrSGqXCu6iPXgHgg" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_iW34TbF8RrmexJ9-nxEjAQ" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-align-center " data-editor="true">Free resource from Cloud Security Alliance</h2></div>
<div data-element-id="elm_vtCfDzzGTna_SJlel8QRig" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left " data-editor="true"><p><span style="color:inherit;"><span style="font-size:14px;">I'm proud to share the release of a guide we co-authored with the </span><a target="_self" href="https://www.linkedin.com/company/cloud-security-alliance/">Cloud Security Alliance</a><span style="font-size:14px;"> on applying zero trust to OT/ICS and critical infrastructure. <br/><br/>Zero Trust Guidance for Critical Infrastructure</span></span></p><p><span style="color:inherit;"><span style="font-size:14px;">Applying Zero Trust to Operational Technology (OT) and Industrial Control Systems (ICS) Environments<br/>🔗&nbsp;<a href="https://cloudsecurityalliance.org/artifacts/zero-trust-guidance-for-critical-infrastructure">https://cloudsecurityalliance.org/artifacts/zero-trust-guidance-for-critical-infrastructure</a></span><span style="font-size:14px;"><br/><br/>You can download this resource (free) from CSA.<br/><br/>This was definitely a labor of love by all involved. When CSA proposed this, I had one condition: I wanted to make it real and actionable—no fluff. No page after page of confusing abstract buzzwords. <br/><br/>This document provides engineers and architects with a clear, adaptable 5-step process for applying zero trust in OT, aligning IT skills with OT demands.</span></span></p><p><span style="color:inherit;"><span style="font-size:14px;"><br/></span></span></p><p><span style="color:inherit;"><span style="font-size:14px;">Visit the link above at CSA's Zero Trust portal and create a free account to download the full document or it's accompanying (shorter) presentation deck.&nbsp;<br/><br/></span></span><span style="color:inherit;"><img src="/Tue%20Nov%2005%202024.png" alt="" style="width:240px !important;height:306px !important;max-width:100% !important;">&nbsp;</span></p><p><span style="color:inherit;"><img src="/Tue%20Nov%2005%202024-1.png" alt="" style="width:403.67px !important;height:226px !important;max-width:100% !important;"></span></p><p><span style="color:inherit;"><br/></span></p><p><span style="color:inherit;">If you're a CISO or CIO responsible for security OT/ICS environments, you'll love this resource.&nbsp;<br/><br/></span></p><p><span style="color:inherit;">And, <span style="font-weight:bold;">if your organization is interested in learning more about integrating OT/ICS into your security program,</span><a href="/contact" title="contact us" rel="">contact us</a> for advisory services and/or corporate training for your team.&nbsp;<br/><br/></span></p></div>
</div><div data-element-id="elm_XEG32kaFSAWDU1GdO7b5Fw" data-element-type="button" class="zpelement zpelem-button "><style></style><div class="zpbutton-container zpbutton-align-center "><style type="text/css"></style><a class="zpbutton-wrapper zpbutton zpbutton-type-primary zpbutton-size-md " href="javascript:;" target="_blank"><span class="zpbutton-content">Get Started Now</span></a></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Tue, 05 Nov 2024 10:56:58 -0500</pubDate></item><item><title><![CDATA[The CIO's Guide to Secure Access Service Edge (SASE) Architecture]]></title><link>https://www.viszensecurity.com/blogs/post/secure-access-service-edge-sase-architecture-a-primer-for-cxos</link><description><![CDATA[<img align="left" hspace="5" src="https://www.viszensecurity.com/Tue Jun 29 2021.png"/>Here's a quick down and dirty primer comparing the new Secure Access Service Edge (SASE) architecture to our traditional perimeter security methods.]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_iwAvcGXwSdWLLHNm2g5Nbw" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_loZ_GzKQS8CoCrbQIYKAnA" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_V1fSkzXMSE2QWIkzy6869Q" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_6yfmUNRZRhiqAnc1S4yH5g" data-element-type="text" class="zpelement zpelem-text "><style> [data-element-id="elm_6yfmUNRZRhiqAnc1S4yH5g"].zpelem-text { border-radius:1px; } </style><div class="zptext zptext-align-center " data-editor="true"><p><span style="color:inherit;"></span></p><p style="text-align:left;"><span style="font-size:12pt;">If you're tired of hearing about the &quot;new normal&quot; post-pandemic, hold on to your knickers because some of the outcomes from COVID's business impact are here to stay. Really, it's not a bad thing and we're long overdue for an overhaul of how we identify, authenticate, connect, and authorize access for users and devices. </span></p><p style="text-align:left;"><span>&nbsp;</span></p><p style="text-align:left;"><span style="font-size:12pt;">Here's a quick down and dirty primer comparing the new Secure Access Service Edge (SASE) architecture to our traditional perimeter security methods. </span></p><p style="text-align:left;"><span>&nbsp;</span></p><p style="text-align:left;"><span style="font-size:12pt;font-weight:700;">Executive View of SASE Architecture<br></span></p><p style="text-align:left;"><span style="font-size:12pt;">From the 10,000-foot view, the three most pertinent points are:</span></p><ol><li><p style="text-align:left;"><span style="font-size:12pt;">SASE is one solution offering that's part of a larger (or longer) zero trust security strategy. As you'll see in the graphic below, SASE enforces the underlying principle of a zero trust network by not extending implicit access to resources. Meaning, what a user or a device can do or access is explicitly defined in the SASE fabric. </span></p></li><li><p style="text-align:left;"><span style="font-size:12pt;">SASE is more of a service set than a single product; it's cloud-based and 'follows' endpoints and users wherever they go, or in the case of work from home -- wherever they <span style="font-style:italic;">don't go</span>. SASE vendors do this with a global cloud PoP network so endpoints connect to the cloud to access resources, vs. connecting to a traditional on-prem datacenter and then egressing. </span></p></li><li><p style="text-align:left;"><span style="font-size:12pt;">SASE is likely to deliver on promises of increased simplicity and security with decreased cost, but there will be a certain amount of vendor lock-in as well as overlap with other products related to zero trust and endpoint security that the C-suite should prepare for. </span></p></li></ol><p style="text-align:left;text-indent:0in;"><span>&nbsp;</span></p><p style="text-align:left;text-indent:0in;"><span style="font-size:12pt;font-weight:700;">Technical View of SASE Architecture<br></span></p><p style="text-align:left;text-indent:0in;"><span style="font-size:12pt;">Since this is a C-level primer, I'm not going to dive too deeply in to the nuts and bolts, but I know the CISOs and CIOs I work with, and most of you love a little technical meat. </span></p><ol><li><p style="text-align:left;"><span style="font-size:12pt;">From an implementation standpoint, how SASE is implemented and what it can (or can't) do is dependent in large part on the vendor. Some SASE vendors came from cloud access server broker (CASB) and secure web gateway (SWG) pedigree; others from firewall and network security. Mileage and roadmaps will vary. How they handle guest (or un-managed devices) as well as users that happen to be on-prem may also vary.</span></p></li><li><p style="text-align:left;"><span style="font-size:12pt;font-weight:400;">SASE has myriad features (vendor-dependent), with support for zero trust networking being just one. Re</span><span style="font-size:12pt;">placing legacy VPNs terminating to on-prem datacenters is a great way to enter the SASE world, and then continue adding features as you go. <br></span></p></li></ol><p style="text-align:left;"><span>&nbsp;</span></p><p style="text-align:left;"><span style="font-size:12pt;font-weight:700;">Graphic: SASE Architecture vs Traditional Perimeter</span></p><p style="text-align:left;"><span style="font-size:12pt;">For those of you who haven't worked with me yet, I love to draw and doodle. I don't know about you, but I'm very visual and find a picture really is worth more than a thousand words. And who has time to read a thousand words? Here are just a few highlights of the SASE graphic. </span></p><ol><li><p style="text-align:left;"><span style="font-size:12pt;">On left you see a traditional network security perimeter where we may (at best) have LAN-based connections (wired or wireless) with authentication and perhaps dynamic segmentation with VLANs or downloadable ACLs. For remote access, we see a traditional VPN model with similar features to the LAN connections. </span></p></li><li><p style="text-align:left;"><span style="font-size:12pt;">On the right you see a typical SASE architecture with enforcement and decision layers plus SASE elements shown in yellow. One of the benefits of this SASE architecture is to abstract from physically-defined connections (those we control at layers 1-3) and instead apply granular context-based enforcement at layer 7 for both on-prem and in-cloud resources. </span></p></li></ol><p style="text-align:left;text-indent:0in;"><span>&nbsp;</span></p><p style="text-align:left;"><img src="/Tue%20Jun%2029%202021.png"></p><p style="text-align:left;"><span>&nbsp;</span></p><p style="text-align:left;"><span>&nbsp;</span></p><p style="text-align:left;"><span>&nbsp;</span></p><p></p></div>
</div><div data-element-id="elm_BJ5oSqF_QliH1mm4AuBpQQ" data-element-type="button" class="zpelement zpelem-button "><style> [data-element-id="elm_BJ5oSqF_QliH1mm4AuBpQQ"].zpelem-button{ border-radius:1px; } </style><div class="zpbutton-container zpbutton-align-center "><style type="text/css"></style><a class="zpbutton-wrapper zpbutton zpbutton-type-primary zpbutton-size-md zpbutton-style-none " href="https://zc.vg/K5Fzk" target="_blank"><span class="zpbutton-content">Get more insights</span></a></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Mon, 28 Jun 2021 19:15:00 -0400</pubDate></item></channel></rss>