Eliminating risks from IoT and OT devices with Zero Trust

Eliminating risks from IoT and OT devices with Zero Trust

Author: Canadian Government Executive December 11, 2020 Duration: 26:13

In its October 2019 Zero Trust eXtended Ecosystem Wave Report, Forrester calls IoT (Internet of Things) and OT (Operational Technology) device security, "one of the hardest problems to solve within the enterprise." As unmanaged devices become commonplace on networks, security and risk professionals must rethink the concept of identity and expand their Zero Trust initiatives to include such devices.

During last year as well, Forrester named Forescout as a Zero Trust platform, thanks in part to foundational capabilities that align very closely with Forrester's ZTX framework.

To explain how the Zero Trust framework works within the Forescout platform, we have joining us today on CGE Radio Jonathan Jesse, Sr. Systems Engineer & Customer Evangelist, with Forescout Technologies.

As a part of his role at Forescout, Jonathan leads the Operational Technology Subject Matter Expert group to help others understand, sell, and use the SilentDefense product. Throughout his time at Forescout, Jonathan has helped solve problems for State and Local governments in the States, higher education in both Canada and the United States and also Fortune 500 customers in both the United States and Canada. Prior to being at Forescout, Jonathan spent 11 years as an Endpoint Security Consultant which shapes how he talks about securing the Enterprise of Things.

Hear about what Zero Trust is all about, why companies are interested in this architecture, how Zero Trust work, understanding Forescout's solution of the Zero Trust framework, enabling your organization to achieve Zero Trust, continuous visibility and assessment of devices, simplify micro-segmentation planning within the context of the Zero Trust framework, and how to return to the workplace in a secure way.

Forescout Research Labs recently announced that it has discovered AMNESIA:33, which is a set of 33 vulnerabilities impacting millions of enterprise IoT, OT, and IT devices worldwide. These vulnerabilities affect four open-source TCP/IP stacks and attackers could leverage them to execute malicious code, perform denial of service attacks and expose sensitive information. 

Of these vulnerabilities, four are considered critical and it's important to begin immediately mitigating the risk posed to your organization. To view the resources available, visit Forescout.com/AMNESIA:33 or:

To learn more best practices and tools for Zero Trust with Google BeyondCorp, visit https://research.google/pubs/pub43231/.


For decades, Canadian Government Executive has been the essential print and digital publication for those navigating the complex machinery of the public service. Canadian Government Executive Radio extends that legacy into audio, creating a direct channel for conversation about the policies, technologies, and leadership shaping governance from town halls to Parliament Hill. This podcast moves beyond press releases and official statements to explore the real-world implementation of ideas. Each episode features candid discussions with deputy ministers, city managers, IT directors, and frontline innovators who are tasked with turning legislation into action. You’ll hear about the challenges of digital transformation, the intersection of cybersecurity and citizen services, and the evolving nature of public sector leadership in a time of rapid change. It’s a forum for the people who build, manage, and protect the programs that define Canadian society. By focusing on the practical expertise of senior officials and the technologists enabling modern government, this series provides context and clarity that you won’t find in daily news coverage. Tune in for a nuanced perspective on how decisions are made, how technology is adopted, and how public service executives are steering their organizations toward the future. This is where policy meets practice, offering listeners an insider’s understanding of the forces that govern.
Author: Language: English Episodes: 100

Canadian Government Executive Radio
Podcast Episodes
Rethinking Citizen Services with IBM's Cloud Modernization Centre [not-audio_url] [/not-audio_url]

Duration: 18:36
In this episode of CGE Radio, J. Richard Jones and guest host deputy editor Lori Turnball chat with Dave McCann, Managing Partner and Canadian Leader, IBM Consulting, and Director, LGS Group about the Client Innovation C…
Zero Trust with Zero Nonsense [not-audio_url] [/not-audio_url]

Duration: 16:03
Digital transformation is accelerating with key shifts such as the expanding Hybrid Workforce and the continued migration of applications and data to the cloud. As we make this transformation, Information Security teams…
Canadian financial inclusion in digital payments [not-audio_url] [/not-audio_url]

Duration: 26:19
In this episode of CGE Radio, hear about digitizing government payments. Robert Hyde, CEO at Payment Source and Jennifer Tramontana, Executive Director at CPPO talk about financial inclusion and payment methods and trend…
Work-integrated learning: Empowering the future of Canada's workforce [not-audio_url] [/not-audio_url]

Duration: 35:26
In this episode, we will get into work integrated learning. We will talk about what works and what doesn't and delve into Riipen, North America's largest marketplace for work-integrated learning. We will see how Riipen i…
How VidCruiter is Modernizing Government Organizations' Recruitment [not-audio_url] [/not-audio_url]

Duration: 27:16
In this episode of CGE Radio, we will look at how government organizations can use technology to automate their hiring process. Joining J. Richard Jones to discuss this topic is Sean Fahey, CEO of VidCruiter. Sean is an…
Data-driven government implementation [not-audio_url] [/not-audio_url]

Duration: 14:12
Full data-driven government implementation has been an ongoing goal for many years. But human obstacles, the unwillingness to collaborate, cybersecurity issues, and trust are hampering the full roll out of this. Hear fro…
Deploying critical assets to the cloud [not-audio_url] [/not-audio_url]

Duration: 33:33
In this episode, J. Richard Jones talks with two experts from FireEye about cloud. FireEye is the intelligence-led security company. Working as a seamless, scalable extension of customer security operations, FireEye offe…