SPECIFICITY OF BUILDING A ZERO TRUST ARCHITECTURE IN HYBRID INFRASTRUCTURES
Roman Syrotynskyi, Ivan Tyshyk · Cybersecurity Education Science Technique · 2025
The popularity of hybrid infrastructures is growing rapidly, as they allow you to combine the advantages of local computing resources - control, cost-effectiveness, compliance with regulatory requirements - with the scalability, flexibility and high availability of cloud technologies. In such conditions, there is a need to provide a unified approach to information security that can cover both types of environments. Zero Trust Architecture (ZTA) is considered a modern and effective model that allows you to achieve a high level of access control, minimize the risks of security breaches and ensure the protection of critical resources regardless of their location. However, building ZTA in hybrid environments is accompanied by a number of challenges due to the heterogeneity of technologies, the lack of unified management tools, varying degrees of control over infrastructure components and the complexity of implementing unified authentication, authorization and monitoring policies. The article examines the key differences between traditional (local) and hybrid infrastructures, in particular from the point of view of building a zero-trust architecture. The specifics of integrating elements of local and cloud environments, which often have different mechanisms for user identification, session management, event logging, and access policy enforcement, are analyzed. A number of important architectural components and technologies are proposed that form the stack of components necessary for implementing ZTA in a hybrid environment. An analysis of the challenges of implementing a zero-trust architecture in a hybrid network infrastructure is also described, in particular the complexity of hybrid network topologies, the complexity of microsegmentation, visibility unification, centralized access management (IAM), and others. Taking into account the identified features, a phased plan for migrating hybrid infrastructures to a zero-trust architecture has been formed, which involves assessment and planning, architecture development, decision selection, and other important steps.