Location
Hilton Waikoloa Village, Hawaii
Event Website
https://hicss.hawaii.edu/
Start Date
7-1-2025 12:00 AM
End Date
10-1-2025 12:00 AM
Description
Information sharing is paramount to operating within the modern business domain. However, with information sharing comes the risk of data breaches. One of the key challenges facing organizations is the ability to trace, and therefore trust, digital information flows. Due to its central philosophy of verifying network traffic before trusting it, zero trust security is an approach to cyber defense architecture that is rapidly gaining popularity across organizations. Although fully adopting zero trust should greatly reduce an organization’s likelihood of suffering a breach, organizations adopt zero trust in varying degrees. In this manuscript, we aim to better understand how zero trust has been adopted over the last decade, using Verizon’s Data Breach Incident Report dataset as a representative sample whereby we may infer lack of zero trust adoption via observable breaches. We find that certain aspects are positively correlated with breach occurrences, while others are negatively associated.
Recommended Citation
Menard, Philip; Reyes, Elizabeth; and Bateman, Ray, "Understanding Zero Trust Security Implementations via the MITRE ATT&CK and D3FEND Frameworks: Uncovering Trends Across a Decade of Breaches" (2025). Hawaii International Conference on System Sciences 2025 (HICSS-58). 2.
https://aisel.aisnet.org/hicss-58/dg/cybersecurity/2
Understanding Zero Trust Security Implementations via the MITRE ATT&CK and D3FEND Frameworks: Uncovering Trends Across a Decade of Breaches
Hilton Waikoloa Village, Hawaii
Information sharing is paramount to operating within the modern business domain. However, with information sharing comes the risk of data breaches. One of the key challenges facing organizations is the ability to trace, and therefore trust, digital information flows. Due to its central philosophy of verifying network traffic before trusting it, zero trust security is an approach to cyber defense architecture that is rapidly gaining popularity across organizations. Although fully adopting zero trust should greatly reduce an organization’s likelihood of suffering a breach, organizations adopt zero trust in varying degrees. In this manuscript, we aim to better understand how zero trust has been adopted over the last decade, using Verizon’s Data Breach Incident Report dataset as a representative sample whereby we may infer lack of zero trust adoption via observable breaches. We find that certain aspects are positively correlated with breach occurrences, while others are negatively associated.
https://aisel.aisnet.org/hicss-58/dg/cybersecurity/2