The Legacy Gap – How to Apply Zero Trust to Aging Infrastructure

Written by Fahad Naeem – Cyber Security Consultant (Cyberfort)

The core philosophy of modern cyber security has flipped. Never trust, always verify. Perimeter defences like traditional firewalls and VPNs are no longer enough; they leave blind spots inside your network once an attacker gets past the gate. This is where Zero Trust Architecture comes in.

What is Zero Trust Architecture?

Zero Trust Architecture is a relatively modern cyber security framework that shifts the traditional approach around securing the boundary to operating on the principle of never trusting and always verifying. There is an assumption that the threat exists both inside and outside the network. Automatic trust is removed from every user, device, application, and there is an enforcement of identity verification, device health checks, and least-privilege access controls for every user, application, or system attempting to connect to resources.

The benefit of this approach is that it reduces the possible attack surface of a threat actor as it limits their access points and minimises the risk of lateral movement by attackers, limiting the damage of any potential breaches.

Legacy Problems

Zero Trust is easy to conceptualise in a modern cloud environment; however, the challenge arises when applying to legacy systems that are deeply embedded in an organisations operation. The previous framework focused on perimeter-based security e.g. firewalls and virtual private networks, which do provide security benefits, but provides a fundamentally limited view inside the network.

Because legacy systems were built before modern Zero Trust standards existed, they present multiple security vulnerabilities. This is compounded by the fact that these systems often run outdated operating systems, creating additional attack vectors to be exploited. They also create integration hurdles, including incompatibility with single sign-on standards like SAML or OIDC, and a lack of support for endpoint detection and response (EDR) agents, which hinders device health verification.

These issues have led to significant impacts in the real world:

British Library ransomware attack – due to lack of network segmentation attackers were able to exfiltrate 600 gigabytes of data.

Target data breach – an attacker was able to compromise third party vendor credentials and because of lack of network segmentation attackers were able to steal 40 million credit card records.

Micro segmentation

One approach that can help legacy systems is micro segmentation; this allows organisations to isolate and secure legacy without having to rewrite code. By creating smaller tightly controlled network zones with least privilege access enforcement, lateral movement is limited.

A particularly difficult challenge to contend with for legacy systems is the lack of a hypervisor, which sits between physical hardware and the operating system. It is used to manage traffic, processing (CPU), memory (RAM) and storage between the virtual computers and allows them to run independently and even on different operating systems. Security tools use three methods to handle this scenario:

Depending on your specific situation a combination can gain the desired segmentation.

Real world examples include: 

  • BUPA’s Cromwell Hospital – they utilised agentless micro segmentation to identify unmanaged devices, group them and apply identity-ware policies at the edge of the network. Resulting in all medical machinery being ring fenced minimising lateral movement risks.
  • U.S. Federal Government Agency – The agency deployed a rigorous Software-Defined Perimeter (SDP) and Micro-Segmentation model; this reduced their attack surface by 85% and stopped 100% of red team’s penetration tests.

So where should you start with micro segmentation? Based on our experience at Cyberfort we collaborate with our customers on embedding a 4-step approach:

Migration Strategies

When considering your organisation and its need a practical method to move off legacy systems can be to wrap and migrate; wrapping is securing your current system so the immediate risk is minimised allowing you to continue with your functions and then migrating to more modern systems in the longer term.

Below is a high-level approach of how this can be implemented:

The first step is always to review and prioritise your system to ensure that you are focusing on what matters most to your organisation. Ask questions like:

  • How critical is this system to operations? It is important to have impartial scoring as business areas will always consider themselves the most important.  ISO22301 has a section around business impact assessment that can help determine the impact to the business if a system is lost and therefore determine an order of criticality.
  • Does it handle or store sensitive data? This can be either personally sensitive data or sensitive company data.
  • Can it be easily replaced or modernised in the short term?

Once this has been completed you know where to focus your efforts to maximise benefits. First, limit network access to validated users only. Next, implement segmentation so systems are isolated from one another, effectively limiting the blast radius of a potential attack. This also increases the life span of your solution reducing organisational waste.

Over the long term you can develop a migration strategy e.g. how to move your system off the legacy approach and to follow a zero-trust model, either on-premises or a cloud service providers environment. This might require refactoring or replacing systems, by building them yourself or by purchasing software as a service (SaaS).

Finally, once you have migrated and validation has been completed, decommission old hardware and systems following best practices to ensure safe disposal of your businesses data.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.