Zero Trust
Overview
Zero-Trust security. Switch from a perimeter-based (firewall and VPN) model of access to a user to resource model.
Implement strong, simple identity. Identity for both a person, but also a system. Decouple the identity from the corporation: make it affinitive to the user, a single identity.
Enforce entitlements and authorisation in the network.
This micro-segmentation is simpler to use, more accessible, and, more secure. It reduces the lateral-traversal, it empowers the users, it increases the audit capability. And, its more economical, more scalable. Everybody wins.
Articles
-

The Epitome of Absolute Trust: Why Legacy Virtual Private Networks Are a Liability
Legacy virtual private networks are a liability, acting as an ethernet cable into your deep infrastructure. With active exploitation of obsolete protocols on the rise, organisations must abandon absolute trust. Discover why modernising access through an Identity-Aware Proxy is the only pragmatic defence against perimeter zero-day vulnerabilities.
-

Defence in Depth: Zero Trust is a Critical Layer, Not a Panacea
“Defence in Depth” strategy, explaining why zero trust is a critical layer in protecting critical infrastructure. From the medieval castle analogy to the “lizard brain” risks of AI-amplified human engineering, learn why layered security and strong authentication are more important than ever in 2026.
-

Securing the Flow: GAO Highlights Persistent Cyber Threats to Water and Wastewater Systems
A recent Government Accountability Office report reveals that nearly 170,000 water systems are increasingly vulnerable to sophisticated cyberattacks. Because the air gap is dead, traditional virtual private networks no longer provide adequate protection. Agilicus AnyX secures critical infrastructure by implementing Zero Trust Architecture, replacing perimeter-based defences with precise, identity-based access and mandatory Multi-Factor Authentication.
-

NERC CIP Compliance for Small Independent Power Producers: A Pragmatic Approach
With the April 1, 2026 enforcement date for NERC CIP-003-9 past, small Independent Power Producers (IPPs) face unique regulatory pressures. This post explores a pragmatic approach to securing low-impact assets, replacing legacy VPNs with a zero trust architecture that automates vendor access controls and simplifies audit evidence retention.
-

Cyber Security Is Physical Safety: Lessons From a Thermal Runaway
A report on a recent B.C. EV charger fire reveals the danger of relying on software for physical safety. Learn why hardware interlocks and zero trust are non-negotiable for remote maintenance.
-

Water utility cybersecurity: The nearly £1 million lesson from South Staffordshire Water
The £963,900 ICO fine against South Staffordshire Water highlights the fatal flaw in perimeter-based security. Learn how Agilicus Zero Trust architecture addresses identity failures and the ‘legacy headache’ in critical infrastructure.
-

Fortifying Critical Infrastructure: The Shift from Defensible to Isolated
CISA’s Critical Infrastructure Fortify initiative demands a fundamental shift in how we secure our most vital assets. By assuming connectivity is unreliable and networks are already compromised, we must move toward proactive isolation. Discover how Agilicus AnyX enables a ‘disconnected yet connected’ Zero Trust architecture that replaces the vulnerable VPN perimeter with secure, identity-based access.
-

Securing Canada’s Critical Energy Infrastructure: Navigating New Cybersecurity Regulations with Zero-Trust Architecture
For Canadian energy and utility operators, complying with stringent new cybersecurity mandates like the Canadian Standards Association Z246.1:21, Alberta Regulation 84/2024, and British Columbia Utilities Commission guidelines is no longer optional. Discover how Agilicus AnyX enables operators to seamlessly implement multi-factor authentication, strict network segmentation, and zero-trust remote access for legacy industrial control systems—without ripping and replacing existing infrastructure or relying on vulnerable virtual private networks.
-

The Fragility of Interdependence: Securing the Industrial Mesh
The £1.9bn JLR breach exposed supply chain fragility. Download the Agilicus whitepaper to learn how Zero Trust secures the industrial mesh against cyber threats.
-

Digital Disenfranchisement: Stop Treating Your Frontline Like Second-Class Citizens
Are your bus drivers and contractors stuck using paper because IT can’t secure their devices? It’s time to stop the ‘Digital Disenfranchisement’ and use Zero Trust to safely connect everyone, everywhere.
-

The 4-Day Warning: New SEC Cyber Rules Hit the Factory Floor
Consequently, trying to scope an attack in a sprawling operatioanl tech network is like trying to find a needle in a haystack, except the haystack is currently on fire, and you are not allowed to use water because it might short-circuit the only machine that is still running.
-

Cleaning Up the Mess: How One Disgruntled Contractor Trashed a Network (And How to Stop It)
An ex-contractor’s revenge cost a firm $862K. This cybersecurity story reveals a critical flaw in vendor access and how to prevent it.
-

Ditch the Digital Ostrich: How Zero Trust is Saving Municipalities (and Their Wallets) from Cyber Chaos
Facing rising cyber insurance costs? For municipalities, risky VPNs are a major hurdle. Learn how Zero Trust secures systems and lowers insurance risk.
-

Your Air Gap is a Lie, and Other Inconvenient Truths About Industry 4.0
For years, the security model for water systems has been the air gap—a mythical wall where everything inside is trusted and everything outside is not. The problem? That air gap already has a bunch of holes in it, and Industry 4.0 is making more.
-

You Have a Login, But You Shall Not Pass: The Magic of Fine-Grained Authorisation
Authentication gets you in the door, but fine-grained authorisation decides which rooms you can enter. This principle ensures users access only the specific resources they need, making your systems more secure by rendering everything else invisible to them.
-

AI-Powered Cyber Threats: Protecting Your Critical Infrastructure
AI amplifies cyber risks for critical infrastructure, making attackers more effective. CISA’s FY23 report shows 80% of successful attacks exploit identity weaknesses like valid accounts and spearphishing. AI isn’t creating new vulnerabilities, but leveraging existing ones. Implementing Zero Trust and universal Single Sign-On significantly reduces these risks, making organizations a harder target.
-

CityWorks CVE Breaches IIS
CityWorks breach leads to lateral traversal through IIS and onwards into your network. Protect it with Agilicus AnyX while you work on upgrading.
-

Krooked Kriminals Krack Krispy Kreme
Krispy Kreme materially impacted by cyber security issue, files SEC-8K disclosure.
-

CityNews The Mike Farwell Show Interview
This morning I was interviewed on the Mike Farwell Show (CityNews). You can check the interview here @ 54:50.
-

SolarWinds Gives Federal Agencies Labour Day Present
SolarWinds Web Help Desk CVE-2024-28986 (rated 9.8 our of 10) is now included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, indicating its active use in cyber attacks, giving affected agencies until September 5, 2024 to fix the flaw under Binding Operational Directive 22-01. How fun.
-

10 Billion Reasons Shared Passwords Are Bad: RockYou2024
Shared password bad. 10 billion passwords leaked. Your team installed some shadow IT remote access solution with a shared password.
-

Get Thee From BGP Rockwell: Ethernet/IP Is not Internet
You wouldn’t download a PLC, would you? Rockwell Automation alert on public access to PLC, and a Shodan search to fact check it.
-

Begone Ivanti Industrial VPN Sayeth CISA
ED 24-01 directs agencies to instantly remove Ivanti Industrial VPN from industrial operations. Defence In Depth, Zero Trust give you more time to react.
-

Using Zero Trust to Enable Secure Remote Access to SCADA for Water Systems
This blog post explores the challenges of securing remote access to SCADA systems and how Zero Trust can act as a solution.
-

Zero Trust vs. VPN: A Comprehensive Comparison for Secure Remote Access
In this blog post, we’ll dive into the Zero Trust vs. VPN security model differences and why the former is ultimately the far superior choice for secure, seamless remote access.
-

SSH for Remote Access: Every User, Every Device, Every Application
In this blog post, we’ll delve into the challenges of enabling SSH for remote access and how you can do so without compromising security through Zero Trust.
-

Simplifying Secure Access: Enabling Rockwell Automation Remote PLC Access Without a VPN
In this post, we’ll explore the limitations of VPNs and delve into how to enable Rockwell Automation remote PLC access.
-

Split Horizon VPN: Unsafe At Any Speed
Split Horizon VPN’s are used to avoid breaking video conferencing. They are unsafe. See paper for route injection issues.
-

NIST sp 800-63A: Introduce Yourself
Who are you? Identity involves knowing who you are, and then later proving it. NIST sp 800-63A enrollment is the first step, let’s talk about that!
-

The Security Risks of Using VPNs in Water and Wastewater Facilities
What are the risks of using VPNs in water and wastewater facilities? We’ll help you answer that question and understand what to do instead.