Zero trust

Zero Trust ends at the browser

Zero Trust - Zero Trust Network - Zero Trust Architecture - ZTA

COMMENTARY: “Never trust, always verify” is standard operating procedure at most enterprise organizations. Zero Trust was coined in 2010; it became an integral part of NIST in 2020. It includes the “assume breach” mindset and a focus on least privilege and continuous monitoring.

Strict Zero Trust identity and access governance has been widely implemented across networks, internal systems, and platforms that connect to external vendors. For organizations that have adopted zero trust, internal supply chain security is almost as secure as it can possibly be.

However, Zero Trust completely falls apart when it comes to securing the website, whether B2C or B2B. Zero Trust campaigns usually end before reaching the browser.

Many companies still have not taken any action to implement Zero Trust at the website level. As a result, tens of thousands of sites fall victim to digital supply chain attacks every day; it doesn’t make headlines because it isn’t always discovered.

Zero Trust and your website

Web architecture includes third-party analytics tools, AI-based chat, marketing automation, and payment processing: your entire digital client-side supply chain. According to Source Defense research, enterprises own only about 18% of their website code, with third-party vendors owning, hosting, and executing 82% of the site’s code.


Related reading:


Every marketing team faces turnover. The plug-in or app the previous marketing director implemented five years ago is still within the website infrastructure. The marketing team’s new web manager has added all sorts of tools to maximize GEO/AEO AI search appearances. Meanwhile, the ecommerce team is ensuring connectivity to the new payments processing platform. Sensitive payments data is left exposed through this unmanaged digital supply chain. Non-ecommerce sites are just as vulnerable, as they host sensitive business data, PII, protected health information, and session tokens.

All the while, almost no one is asking the IT or security team to review the new website apps for security issues. Your customers are still entering their credit card and personal details, expecting the website to be fully safe. That is definitely not the case.

Running unvetted, unmonitored third-party scripts gives threat actors most privileged access, in extreme contradiction to the Zero Trust core principle of least privileged access. By default, most of the third-party scripts have full Document Object Model (DOM) access, allowing them to read PII, financial data, and credentials without restrictions.

The regulators are watching

Some regulatory agencies are fully aware of these issues and have started taking more active steps to drive compliance. PCI DSS 4.0.1, Requirement 6.4.3, requires strict, continuous integrity monitoring, governance, and authorization to prevent web skimming/Magecart attacks.

Meanwhile, HIPAA and the U.S. Office for Civil Rights have issued directives restricting tracking technology that exposes patient data. In addition, data privacy issues fall under CCPA, FFIEC, and NIST mandates.

That doesn’t mean most enterprises are addressing the issue; it just means they are more open to penalties when a breach is revealed, and they are investigated for lack of action.

Website weakness and AI

Website security is going to be even further weakened, as threat actors, whether experienced or beginners, become more proficient at prompting the code necessary to drive cyberattacks. AI gives threat actors the ability to alter their attacks based on transaction frequency, transaction value, region, and even time of day.

Cybercriminals are strengthening their threat capabilities with generative malware and script obfuscation, which lets them deliver client-side attacks that bypass traditional signature detection. They’re also using AI to try to stay one step ahead, countering forensic and remediation techniques. Meanwhile, persistent attacks allow them to compromise third-party script repositories to evade the detection window. Finally, agentic AI commerce hijacks mask malicious activities within high-velocity, normal traffic.

Taking control of your website security

Logging potential attacks using the alert-response model for client-side attacks fails completely because this approach adds even more massive amounts of log data to the SOC alert “pile.” The SOC teams will miss many of these alerts simply due to the regular noise they must comb through daily.

It’s time to extend your Zero Trust approach to your website with prevention by design. Zero Trust means defining and authorizing the exact actions and permissions a script can execute, not just authorizing the script itself.

You can’t secure it if you don’t know what you have. Audit all client-side scripts, identifying and eliminating “ghost” scripts. The audits frequently uncover legacy scripts that are already end of life, which have not received patches or security updates in years. Then, you need to establish behavioral baselines for the scripts you have kept.

Taking the proactive approach, prevention by design, keeps web threats out of the SOC queue. Implement client-side management tools that enforce runtime protection, blocking unauthorized network requests or DOM reads and ensuring scripts can’t access payment or PII fields 24/7. They generally don’t affect the architecture or increase latency.

Deploying these tools within your security stack is low-hanging fruit; it can be done quickly, often overnight or in a few days, based on the tools chosen, versus the weeks or months or years that it takes to implement Zero Trust elsewhere in the enterprise.

PCI DSS has mapped its controls directly to the NIST cybersecurity framework; therefore, non-payment-focused enterprises can use the guidelines to implement Zero Trust on their web applications. The key is ensuring real-time threat protection, not just implementing periodic scans.

Making Zero Trust standard operating procedure

Implementing web security isn’t just technical. The security team is usually not aware when new scripts have been added to the website. They must take a proactive approach, ensuring the web management teams, marketing, ecommerce, and other teams with web access are fully aware of the risks. They need to put together a clear, easy-to-follow process to ensure that Zero Trust stays an integral part of the website.

Lax website security reduces client trust, erodes your brand, and leaves you open to significant fines from a full range of regulatory agencies. You don’t want your clients to find unauthorized charges on their credit cards or discover their PII has been stolen. The combination of cybercriminals and AI is going to increase the threat volume.

Client-side attacks don’t generally make headlines because we’ve failed to adopt controls to detect and prevent them — we’ve missed a major threat surface. To fully protect your enterprise, Zero Trust should become integral not only internally, but also within your digital third-party supply chain.

Hadar Blutrich

Hadar Blutrich is CTO of Source Defense and brings more than 15 years of varied executive experience, leading teams and developing multiple out of the box solutions. He has led projects with industry giants such as Bank of America, Chase, and others, working closely with their R&D and security teams.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Asymmetric Warfare

You can skip this ad in 5 seconds