International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1710599

1710599 Vol 3 · Issue 2 Download Paper

Toward Zero-Trust Networking: A Holistic Paradigm Shift for Enterprise Security in Digital Transformation Landscapes

Tahir Tayor Bukhari Oyetunji Oladimeji Edima David Etim Joshua Oluwagbenga Ajayi

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity

Abstract

As enterprises undergo digital transformation, traditional perimeter-based security models have become increasingly inadequate for addressing modern cyber threats. The proliferation of cloud computing, remote workforces, Internet of Things (IoT) devices, and hybrid IT environments has expanded attack surfaces, exposing organizations to advanced persistent threats, lateral movement, and insider risks. Zero-Trust Networking (ZTN) emerges as a holistic paradigm shift that challenges conventional assumptions of implicit trust within organizational boundaries. By enforcing a ?never trust, always verify? approach, ZTN emphasizes continuous authentication, least-privilege access, and micro-segmentation to secure enterprise networks across heterogeneous infrastructures. This explores the conceptual and practical foundations of ZTN, highlighting its relevance in contemporary digital transformation landscapes. It examines the architectural components of zero-trust systems, including identity and access management (IAM), multi-factor and adaptive authentication, software-defined perimeters (SDP), and continuous monitoring. Implementation strategies, such as phased deployment, policy-driven automation, and AI-assisted threat detection, are analyzed to provide enterprises with actionable guidance for transitioning from legacy security models to a zero-trust paradigm. This also addresses the benefits and limitations of ZTN adoption. Benefits include enhanced security posture, reduced attack surface, regulatory compliance, improved risk management, and scalability across hybrid and multi-cloud environments. Challenges encompass technical complexity, integration with legacy systems, human factors, and cost considerations. Emerging trends, such as AI-driven continuous authentication, IoT and edge integration, and cloud-native security protocols, are discussed to outline the future trajectory of enterprise zero-trust architectures. By synthesizing theoretical principles, architectural strategies, and practical considerations, this positions Zero-Trust Networking as a critical enabler for resilient, adaptive, and secure enterprise networks. Its adoption represents a strategic imperative for organizations seeking to safeguard assets, ensure compliance, and optimize security in increasingly distributed and dynamic digital transformation ecosystems.

Keywords

Zero-Trust Networking, Holistic Paradigm Shift, Enterprise Security, Digital Transformation Landscapes

References

[1] Alonso, J., Escalante, M. and Orue-Echevarria, L., 2016. Transformational cloud government (TCG): transforming public administrations with a cloud of public services. Procedia Computer Science, 97, pp.43-52.

[2] Anwar, S., Mohamad Zain, J., Zolkipli, M.F., Inayat, Z., Khan, S., Anthony, B. and Chang, V., 2017. From intrusion detection to an intrusion response system: fundamentals, requirements, and future directions. algorithms, 10(2), p.39.

[3] Bellavista, P. and Montanari, R., 2017. Context awareness for adaptive access control management in IoT environments. Security and Privacy in Cyber‐Physical Systems: Foundations, Principles and Applications, pp.157-178.

[4] Bughin, J., Hazan, E., Sree Ramaswamy, P., DC, W. and Chu, M., 2017. Artificial intelligence the next digital frontier.

[5] Buyya, R., Srirama, S.N., Casale, G., Calheiros, R., Simmhan, Y., Varghese, B., Gelenbe, E., Javadi, B., Vaquero, L.M., Netto, M.A. and Toosi, A.N., 2018. A manifesto for future generation cloud computing: Research directions for the next decade. ACM computing surveys (CSUR), 51(5), pp.1-38.

[6] Carretero, J., Izquierdo-Moreno, G., Vasile-Cabezas, M. and Garcia-Blas, J., 2018. Federated identity architecture of the European eID system. IEEE access, 6, pp.75302-75326.

[7] Chen, Z., Xu, G., Mahalingam, V., Ge, L., Nguyen, J., Yu, W. and Lu, C., 2016. A cloud computing based network monitoring and threat detection system for critical infrastructures. Big Data Research, 3, pp.10-23.

[8] Chui, M. and Francisco, S., 2017. Artificial intelligence the next digital frontier. McKinsey and Company Global Institute, 47(3.6), pp.6-8.

[9] Coppa, I., Woodgate, P.W. and Mohamed-Ghouse, Z., 2016. Global outlook 2016: spatial information industry. Australia and New Zealand Cooperative Research Centre for Spatial Information, Melbourne.

[10] Dixit, V.H., Kyung, S., Zhao, Z., Doupé, A., Shoshitaishvili, Y. and Ahn, G.J., 2018, March. Challenges and Preparedness of SDN-based Firewalls. In Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization (pp. 33-38).

[11] Fadhil, M., Owen, G. and Adda, M., 2016, May. Bitcoin network measurements for simulation validation and parameterisation. In Proceedings of the Eleventh International Network Conference (INC 2016) (p. 109). Lulu. com.

[12] Gonugunta, K.C. and Leo, K., 2018. Oracle Analytics to Predicting Prison Violence. International Journal of Modern Computing, 1(1), pp.23-31.

[13] Grainger, A., 2016. Trade facilitation. In The Ashgate Research Companion to International Trade Policy (pp. 127-142). Routledge.

[14] Greenhalgh, T., Wherton, J., Papoutsi, C., Lynch, J., Hughes, G., Hinder, S., Fahy, N., Procter, R. and Shaw, S., 2017. Beyond adoption: a new framework for theorizing and evaluating nonadoption, abandonment, and challenges to the scale-up, spread, and sustainability of health and care technologies. Journal of medical Internet research, 19(11), p.e8775.

[15] Grimaccia, F., Bonfante, F., Battipede, M., Maggiore, P. and Filippone, E., 2017. Risk analysis of the future implementation of a safety management system for multiple RPAS based on first demonstration flights. Electronics, 6(3), p.50.

[16] Gupta, P.K., Tyagi, V. and Singh, S.K., 2017. Predictive computing and information security. Singapore: Springer Singapore.

[17] Haani, V. and Ananya, D., 2018. Shifting Paradigms in Cyber Defense: A 2015 Perspective on Emerging Threats in Cloud Computing and Mobile-First Environments. International Journal of Trend in Scientific Research and Development, 2(6), pp.1711-1731.

[18] Hashmi, M., Governatori, G., Lam, H.P. and Wynn, M.T., 2018. Are we done with business process compliance: state of the art and challenges ahead. Knowledge and Information Systems, 57(1), pp.79-133.

[19] Hoesly, R.M., Smith, S.J., Feng, L., Klimont, Z., Janssens-Maenhout, G., Pitkanen, T., Seibert, J.J., Vu, L., Andres, R.J., Bolt, R.M. and Bond, T.C., 2018. Historical (1750–2014) anthropogenic emissions of reactive gases and aerosols from the Community Emissions Data System (CEDS). Geoscientific Model Development, 11(1), pp.369-408.

[20] Hwang, J., Bai, K., Tacci, M., Vukovic, M. and Anerousis, N., 2016. Automation and orchestration framework for large-scale enterprise cloud migration. IBM Journal of Research and Development, 60(2-3), pp.1-1.

[21] Khan, M.S., Siddiqui, S. and Ferens, K., 2017. A cognitive and concurrent cyber kill chain model. In Computer and Network Security Essentials (pp. 585-602). Cham: Springer International Publishing.

[22] Khan, S., Parkinson, S. and Qin, Y., 2017. Fog computing security: a review of current applications and security solutions. Journal of Cloud Computing, 6(1), p.19.

[23] Kumar, A., Brown, O. and Oscar, E., 2017. From Vulnerability to Vigilance: Building Secure National Cloud Networks with Zero-Trust Architecture.

[24] Kwon, J. and Johnson, M.E., 2018. Meaningful healthcare security. MIS quarterly, 42(4), pp.1043-A7.

[25] Lai, C., Jacobs, N., Hossain-McKenzie, S., Carter, C., Cordeiro, P., Onunkwo, I. and Johnson, J., 2017. Cyber security primer for DER vendors, aggregators, and grid operators. Tech. Rep., 12.

[26] Lu, C.H., 2018. IoT-enabled adaptive context-aware and playful cyber-physical system for everyday energy savings. IEEE Transactions on Human-Machine Systems, 48(4), pp.380-391.

[27] Mahjabin, T., Xiao, Y., Sun, G. and Jiang, W., 2017. A survey of distributed denial-of-service attack, prevention, and mitigation techniques. International Journal of Distributed Sensor Networks, 13(12), p.1550147717741463.

[28] Maimó, L.F., Gómez, Á.L.P., Clemente, F.J.G., Pérez, M.G. and Pérez, G.M., 2018. A self-adaptive deep learning-based system for anomaly detection in 5G networks. Ieee Access, 6, pp.7700-7712.

[29] Makhdoom, I., Abolhasan, M., Lipman, J., Liu, R.P. and Ni, W., 2018. Anatomy of threats to the internet of things. IEEE communications surveys & tutorials, 21(2), pp.1636-1675.

[30] Malhotra, Y., 2017. Stress Testing for Cyber Risks: Cyber Risk Insurance Modeling beyond Value-at-Risk (VaR): Risk, Uncertainty, and, Profit for the Cyber Era. SSRN.

[31] McAloone, T.C. and Pigosso, D.C., 2017. From ecodesign to sustainable product/service-systems: a journey through research contributions over recent decades. In Sustainable Manufacturing: Challenges, Solutions and Implementation Perspectives (pp. 99-111). Cham: Springer International Publishing.

[32] Mohammed, A., 2018. Best Practices for Auditing Security Operations Centers (SOC) for Compliance and Threat Detection. Advances in Computer Sciences, 1(1).

[33] Momen, N., Pulls, T., Fritsch, L. and Lindskog, S., 2017, August. How much privilege does an app need? Investigating resource usage of android apps (short paper). In 2017 15th Annual Conference on Privacy, Security and Trust (PST) (pp. 268-2685). IEEE.

[34] Nagar, G., 2018. Leveraging Artificial Intelligence to Automate and Enhance Security Operations: Balancing Efficiency and Human Oversight. Valley International Journal Digital Library, pp.78-94.

[35] Nelson, L.A., Bethune, M.C., Lagotte, A.E. and Osborn, C.Y., 2016. The usability of diabetes MAP: a web-delivered intervention for improving medication adherence. JMIR Human Factors, 3(1), p.e5177.

[36] Ng, A.C.K. ed., 2018. Contemporary Identity and Access Management Architectures: Emerging Research and Opportunities: Emerging Research and Opportunities.

[37] O’Reilly, P.D., Rigopoulos, K.G., Witte, G.A. and Feldman, L., 2018. 2017 NIST/ITL cybersecurity program: Annual report.

[38] Omopariola, M. and Lead, C.D., 2016. Zero-Trust Architecture Deployment in Emerging Economies: A Case Study from Nigeria [online]

[39] Parwez, M.S., Rawat, D.B. and Garuba, M., 2017. Big data analytics for user-activity analysis and user-anomaly detection in mobile wireless network. IEEE Transactions on Industrial Informatics, 13(4), pp.2058-2065.

[40] Pirc, J., DeSanto, D., Davison, I. and Gragido, W., 2016. Threat forecasting: Leveraging big data for predictive analysis. Syngress.

[41] Puyang, T., Shen, Q., Luo, Y., Luo, W. and Wu, Z., 2017, May. Making least privilege the low-hanging fruit in clouds. In 2017 IEEE International Conference on Communications (ICC) (pp. 1-7). IEEE.

[42] Rapuzzi, R. and Repetto, M., 2018. Building situational awareness for network threats in fog/edge computing: Emerging paradigms beyond the security perimeter model. Future Generation Computer Systems, 85, pp.235-249.

[43] Rotsos, C., King, D., Farshad, A., Bird, J., Fawcett, L., Georgalas, N., Gunkel, M., Shiomoto, K., Wang, A., Mauthe, A. and Race, N., 2017. Network service orchestration standardization: A technology survey. Computer Standards & Interfaces, 54, pp.203-215.

[44] Rudd, E.M., Rozsa, A., Günther, M. and Boult, T.E., 2016. A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions. IEEE Communications Surveys & Tutorials, 19(2), pp.1145-1172.

[45] Santos, H., Pereira, T. and Mendes, I., 2017, March. Challenges and reflections in designing cyber security curriculum. In 2017 IEEE World Engineering Education Conference (EDUNINE) (pp. 47-51). IEEE.

[46] Saurabh, P. and Verma, B., 2016. An efficient proactive artificial immune system based anomaly detection and prevention system. Expert Systems with Applications, 60, pp.311-320.

[47] Schulenberg, J.L., 2016. Police decision-making in the gray zone: The dynamics of police–citizen encounters with mentally ill persons. Criminal Justice and Behavior, 43(4), pp.459-482.

[48] Serpanos, D. and Wolf, M., 2018. Internet-of-Things (IoT) Systems. Architectures, Algorithms, Methodologies.

[49] Shah, R., Attwood, K., Arya, S., Hall, D.E., Johanning, J.M., Gabriel, E., Visioni, A., Nurkin, S., Kukar, M., Hochwald, S. and Massarweh, N.N., 2018. Association of frailty with failure to rescue after low-risk and high-risk inpatient surgery. JAMA surgery, 153(5), pp.e180214-e180214.

[50] Tan, S., De, D., Song, W.Z., Yang, J. and Das, S.K., 2016. Survey of security advances in smart grid: A data driven approach. IEEE Communications Surveys & Tutorials, 19(1), pp.397-422.

[51] Tavčar, J. and Horvath, I., 2018. A review of the principles of designing smart cyber-physical systems for run-time adaptation: Learned lessons and open issues. IEEE Transactions on Systems, Man, and Cybernetics: Systems, 49(1), pp.145-158.

[52] Tourani, R., Misra, S., Mick, T. and Panwar, G., 2017. Security, privacy, and access control in information-centric networking: A survey. IEEE communications surveys & tutorials, 20(1), pp.566-600.

[53] Tyagi, A.K. and Niladhuri, S., 2016, August. Providing trust enabled services in vehicular cloud computing. In Proceedings of the International Conference on Informatics and Analytics (pp. 1-10).

[54] Vanickis, R., Jacob, P., Dehghanzadeh, S. and Lee, B., 2018, June. Access control policy enforcement for zero-trust-networking. In 2018 29th Irish Signals and Systems Conference (ISSC) (pp. 1-6). IEEE.

[55] Ward, D. and Metz, C., 2018. Role of Open Source, Standards, and Public Clouds in Autonomous Networks. In Artificial Intelligence for Autonomous Networks (pp. 101-144). Chapman and Hall/CRC.

[56] Weichhart, G., Molina, A., Chen, D., Whitman, L.E. and Vernadat, F., 2016. Challenges and current developments for sensing, smart and sustainable enterprise systems. Computers in Industry, 79, pp.34-46.

[57] Yellanki, S.K., 2016. Smart Services and Network Infrastructure: Building Seamless Digital Ecosystems. Global Research Development (GRD) ISSN: 2455-5703, 1(12), pp.1-23.

[58] Yilmaz, A.K. and Flouris, T., 2017. Corporate risk management for international business. Springer.

[59] Yunis, M., Tarhini, A. and Kassar, A., 2018. The role of ICT and innovation in enhancing organizational performance: The catalysing effect of corporate entrepreneurship. Journal of Business Research, 88, pp.344-356.

[60] Zhou, Q., Elbadry, M., Ye, F. and Yang, Y., 2018, April. Heracles: Scalable, fine-grained access control for internet-of-things in enterprise environments. In IEEE INFOCOM 2018-IEEE Conference on Computer Communications (pp. 1772-1780). IEEE.

How to cite this paper

Tahir Tayor Bukhari, Oyetunji Oladimeji, Edima David Etim, Joshua Oluwagbenga Ajayi "Toward Zero-Trust Networking: A Holistic Paradigm Shift for Enterprise Security in Digital Transformation Landscapes" Iconic Research And Engineering Journals Volume 3 Issue 2 2019 Page 822-835
Tahir Tayor Bukhari, Oyetunji Oladimeji, Edima David Etim, Joshua Oluwagbenga Ajayi "Toward Zero-Trust Networking: A Holistic Paradigm Shift for Enterprise Security in Digital Transformation Landscapes" Iconic Research And Engineering Journals, vol. 3, no. 2, Aug. 2019
Tahir Tayor Bukhari, Oyetunji Oladimeji, Edima David Etim, Joshua Oluwagbenga Ajayi (2019). Toward Zero-Trust Networking: A Holistic Paradigm Shift for Enterprise Security in Digital Transformation Landscapes. Iconic Research And Engineering Journals, 3(2).
Tahir Tayor Bukhari, Oyetunji Oladimeji, Edima David Etim, Joshua Oluwagbenga Ajayi "Toward Zero-Trust Networking: A Holistic Paradigm Shift for Enterprise Security in Digital Transformation Landscapes" Iconic Research And Engineering Journals, vol. 3, no. 2, Aug. 2019.
@article{1710599,
      author = {Tahir Tayor Bukhari, Oyetunji Oladimeji, Edima David Etim, Joshua Oluwagbenga Ajayi},
      title = {Toward Zero-Trust Networking: A Holistic Paradigm Shift for Enterprise Security in Digital Transformation Landscapes},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {3},
      number = {2},
      pages = {822-835},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1710599.pdf},
      abstract = {As enterprises undergo digital transformation, traditional perimeter-based security models have become increasingly inadequate for addressing modern cyber threats. The proliferation of cloud computing, remote workforces, Internet of Things (IoT) devices, and hybrid IT environments has expanded attack surfaces, exposing organizations to advanced persistent threats, lateral movement, and insider risks. Zero-Trust Networking (ZTN) emerges as a holistic paradigm shift that challenges conventional assumptions of implicit trust within organizational boundaries. By enforcing a ?never trust, always verify? approach, ZTN emphasizes continuous authentication, least-privilege access, and micro-segmentation to secure enterprise networks across heterogeneous infrastructures. This explores the conceptual and practical foundations of ZTN, highlighting its relevance in contemporary digital transformation landscapes. It examines the architectural components of zero-trust systems, including identity and access management (IAM), multi-factor and adaptive authentication, software-defined perimeters (SDP), and continuous monitoring. Implementation strategies, such as phased deployment, policy-driven automation, and AI-assisted threat detection, are analyzed to provide enterprises with actionable guidance for transitioning from legacy security models to a zero-trust paradigm. This also addresses the benefits and limitations of ZTN adoption. Benefits include enhanced security posture, reduced attack surface, regulatory compliance, improved risk management, and scalability across hybrid and multi-cloud environments. Challenges encompass technical complexity, integration with legacy systems, human factors, and cost considerations. Emerging trends, such as AI-driven continuous authentication, IoT and edge integration, and cloud-native security protocols, are discussed to outline the future trajectory of enterprise zero-trust architectures. By synthesizing theoretical principles, architectural strategies, and practical considerations, this positions Zero-Trust Networking as a critical enabler for resilient, adaptive, and secure enterprise networks. Its adoption represents a strategic imperative for organizations seeking to safeguard assets, ensure compliance, and optimize security in increasingly distributed and dynamic digital transformation ecosystems.},
      keywords = {Zero-Trust Networking, Holistic Paradigm Shift, Enterprise Security, Digital Transformation Landscapes},
      month = {August},
  }