Skip to content

Zero Trust Doesn’t End at Login: Why Security Teams Must Control What Happens Next

Zero Trust security requires more than authentication and network access controls. ThreatLocker CTO Michael Jenkins explains why organizations must restrict what users, applications and processes can do after access is granted.

For years, security teams have been told to trust nothing and verify everything. But according to ThreatLocker CTO Michael Jenkins, too many organizations still stop their Zero Trust efforts at the point of access.

In the latest episode of CYBR.HAK.CAST, Jenkins joined hosts Michael Farnum and Phillip Wylie to discuss why effective Zero Trust security must extend beyond determining who or what gets into an environment. An authorized session, after all, isn't necessarily a safe session.

Full episode and related article:

Zero Trust and Cybersecurity Careers With Michael Jenkins
ThreatLocker CTO Michael Jenkins talks Zero Trust, cybersecurity career growth, skills, relationships and lessons learned along the way.
AI-Powered Ransomware Puts More Businesses at Risk
AI-powered ransomware attacks don’t need sophisticated new techniques to create more risk. ThreatLocker CTO Michael Jenkins says automation lets cybercriminals target more businesses with less work, putting smaller organizations increasingly in the crosshairs.

Farnum described seeing organizations approach Zero Trust almost like an endpoint firewall: prevent unauthorized connections, authenticate the ones that remain and assume the job is largely finished.

Jenkins said the model has to go much further. “I've spent years convincing people that Zero Trust is every aspect, it's every layer,” Jenkins said. “It's about making sure that, yeah, you lock down so you're not letting anybody in, but when they get in, you need to restrict what they're doing as well.”

Jenkins compared it to securing a house. Locking the front door controls who gets inside. But once someone enters, homeowners don't normally give them unrestricted access to every room, closet and possession. Businesses shouldn't treat software that way either.

Zero Trust must reach the application level

Jenkins argued that organizations should apply the same least-privilege thinking used for employees to individual applications.

Security teams can restrict an application's ability to access files, reach portions of the network or launch other applications. If that trusted application is later compromised, those controls can contain the damage rather than giving an attacker freedom to move throughout the environment.

“If it can only do what it's supposed to do, you don't have to worry about it going rogue,” Jenkins said.

That becomes particularly important as attackers increasingly use legitimate tools and living-off-the-land techniques to evade security controls.

But moving toward that level of Zero Trust doesn't require enterprises to lock down everything overnight.

Jenkins recommends what he calls a “draw a line in the sand” approach: establish where the organization stands today, prevent the security posture from deteriorating further and then progressively tighten controls.

“Let's not get any worse,” Jenkins said. “And then you start tightening areas as you go.”

Education is part of that process. Users are more likely to accept tighter controls when security teams explain why they're being implemented instead of suddenly imposing sweeping restrictions.

The larger lesson is that Zero Trust isn't something an organization simply deploys.

It is an operating model built around continuously reducing what users, applications and processes are allowed to do — even after they have been authenticated and authorized.

For organizations still waiting for the perfect Zero Trust architecture, Jenkins' advice is simpler: start.

“It's an ongoing experience,” he said. “Our businesses are a lot safer if we actually just take that first step as soon as possible.”

Latest