"The practice of “zero trust” is particularly important here. Any device or software outside the organization cannot be trusted". Great approach but it is amazing how many breaches are still happening due to lack of basic prevention measures taken
O_o
https://en.m.wikipedia.org/wiki/Zero_trust_security_model
"... sometimes known as perimeterless security, describes an approach to the design and implementation of IT systems. The main concept behind zero trust is “never trust, always verify,” which means that devices should not be trusted by default, even if they are connected to a managed corporate network such as the corporate LAN and even if they were previously verified."