Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Your Zero Trust Program is Half-Scoped.

Solution Category Network Security
Type Webinar
Organization ForeScout Technologies
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Examines why identity-centric Zero Trust programmes leave significant security gaps
  • Addresses emerging attack techniques that bypass multi-factor authentication and single sign-on controls
  • Focuses on extending Zero Trust to IoT and OT devices that cannot support traditional security agents
  • Relevant to cybersecurity leaders in healthcare, manufacturing, energy, financial services and public sector organisations
  • Features Dr. Chase Cunningham, a recognised authority on Zero Trust architecture

Introduction

This webinar challenges a fundamental assumption underpinning many enterprise Zero Trust programmes: that verifying user identity represents the core of a mature security posture. Hosted by Forescout and featuring Dr. Chase Cunningham alongside Joe Malenfant, the session targets cybersecurity professionals responsible for Zero Trust strategy in complex device environments. The discussion arrives at a critical moment, as threat actors increasingly demonstrate the ability to circumvent identity controls entirely, exposing organisations that have narrowly scoped their Zero Trust initiatives.

About This Event

Titled “Your Zero Trust Program is Half-Scoped,” this virtual session positions itself as an unfiltered conversation that questions prevailing industry assumptions. Dr. Chase Cunningham, widely known as “Dr. Zero Trust,” brings extensive experience in security architecture and has become a prominent voice in advocating for comprehensive Zero Trust adoption. The webinar format combines expert commentary with practical guidance, aiming to move beyond theoretical frameworks toward actionable implementation strategies.

The Limitations of Identity-Centric Security

Many organisations have invested heavily in identity verification as the foundation of their Zero Trust programmes. Multi-factor authentication, single sign-on platforms and identity governance tools have become standard components of enterprise security stacks. However, recent threat research reveals that attackers have developed sophisticated techniques to bypass these controls without ever compromising credentials directly.

The webinar examines specific attack vectors including ConsentFix phishing campaigns, SSO vishing operations and OAuth device-code abuse. These methods exploit trust relationships and authentication flows rather than attempting to steal passwords or intercept authentication tokens. For security teams that have treated identity as the definitive Zero Trust control, these techniques represent a significant blind spot.

Extending Zero Trust to Unmanaged Devices

A central theme of the discussion concerns devices that cannot accommodate traditional endpoint security agents. Industrial control systems, medical equipment, building automation controllers and countless IoT sensors operate within enterprise networks yet remain outside the scope of agent-based security tools. These devices often run proprietary operating systems, lack the computational resources for security software, or cannot be modified without voiding warranties or regulatory certifications.

The session introduces the concept of “five universals” in Zero Trust architecture, providing a framework for ensuring that security controls apply consistently across all network-connected assets. This approach recognises that Universal Zero Trust Network Access must account for the full spectrum of devices, not merely those capable of running modern endpoint protection.

Industry Context and Operational Challenges

Organisations in sectors such as healthcare, manufacturing, energy and financial services face particular challenges when implementing comprehensive Zero Trust programmes. These environments typically contain substantial populations of operational technology and specialised equipment that predates modern security architectures. The convergence of IT and OT networks has expanded attack surfaces while complicating security governance.

Regulatory requirements in critical infrastructure sectors increasingly mandate security controls that extend beyond traditional IT assets. Security leaders must demonstrate visibility and control over devices that were never designed with cybersecurity in mind, creating tension between operational continuity and security objectives.

Who Should Attend

The webinar is designed for CISOs, security architects, network security engineers and IT managers responsible for Zero Trust initiatives. Product security leaders and practitioners working in environments with significant IoT or OT deployments will find the content particularly relevant. The discussion assumes familiarity with Zero Trust principles while challenging attendees to reconsider the scope and completeness of their current programmes.

Practical Guidance for Zero Trust Expansion

Rather than presenting Zero Trust as a product to be purchased, the session emphasises that effective implementation requires continuous expansion of scope. The recurring message that “Zero Trust doesn’t fail—it gets scoped too small” encapsulates the core argument. Identity verification represents a starting point rather than a complete strategy, and organisations must systematically extend controls to encompass network segments, device types and data flows that may currently operate outside their Zero Trust perimeter.