Darktrace announced its ability to extend its detection and autonomous response capabilities to zero trust technologies, including Zscaler, Okta, and Duo Security.
These API integrations allow organisations to accelerate their adoption of zero trust architecture by feeding data into Darktrace’s self-learning AI engine to identify and neutralise anomalous behaviours.
Zero trust technologies enforce guardrails for organisations with rules and policies designed to reduce risk exposure by eliminating unnecessary access and privileges across critical IT systems, thus creating a more secure infrastructure. Yet there is still a risk of malicious activity even with proper architecture and policy enforcement – advanced monitoring and threat detection are critical elements of a zero-trust strategy, which assumes that a breach is underway at any given moment.
“Against the growing threat of advanced cyber-attacks, zero trust architecture has emerged as one way of supporting the shift to new ways of working,” said Max Heinemeyer, Vice President of Cyber Innovation at Darktrace. “The shift to remote and hybrid work has increased the attack surface for organisations and underscores the importance of securing the identity of each user. Although traditional zero-trust policies minimise risk, and zero trust architectures reduce the overall attack surface, organisations need to assume attackers will still inevitably breach their perimeter defences, including identity controls.”
Darktrace can instantly identify and trigger a proportionate response to contain the attack when malicious activity occurs despite the enforcement of zero trust rules and policies. When deployed with Zscaler, the scope of activity visible to Darktrace widens, and its AI technologies can analyse, contextualise, and ultimately act when necessary.
Upon detecting unusual behaviour, Darktrace’s Autonomous Response can directly take appropriate action via the Zscaler API, ranging from actions as granular and surgical as blocking connections between two endpoints to a complete termination of all device-specific activity.
“While Zscaler’s Zero Trust Exchange reduces the attack surface and enforces cyber security policies, the integration with Darktrace AI behavioural detection and response allows customers to correlate Zscaler telemetry with data from across the enterprise to improve threat response further,” said Amit Raikar, Vice President, Business Development and Technology Alliances at Zscaler.
Darktrace’s integrations with Okta and Duo Security are similar, where within zero trust architectures, the administrative users become the top targets because they can affect the accessibility and vulnerability of the entire digital environment. Darktrace can alert and act on the anomalous behaviours of these accounts, including unusual and potentially unsanctioned activity. Unique to Darktrace, it may also detect unusual administrator activity around newly added user permissions and third-party software to allow lists or anything that might widen the range of risk exposure.