* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* The SolarWinds Hack: Why We Need Zero Trust More Than Ever

# The SolarWinds Hack: Why We Need Zero Trust More Than Ever

![The SolarWinds Hack: Why We Need Zero Trust More Than Ever](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2021/02/the-solarwinds-hack-why-we-need-zero-trust-more-than-ever.png)  
**By [George Finney](https://www.paloaltonetworks.com/perspectives/author/george-finney/ "Posts by George Finney")** | **5 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The SolarWinds Hack: Why We Need Zero Trust More Than Ever\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fthe-solarwinds-hack-why-we-need-zero-trust-more-than-ever%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/the-solarwinds-hack-why-we-need-zero-trust-more-than-ever/?pdf=download&lg=en&_wpnonce=032c300878 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/panw_master-twitter-profile-pic-400x400-1.png)  
  George Finney is the Chief Security Officer for Southern Methodist University....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/george-finney/)

## IN THIS ARTICLE

A broad swath of U.S. government agencies and corporations was compromised in what is now considered one of the most sophisticated cyberattacks in history. The exploit, known as Sunburst, was exposed in December 2020 when cybersecurity experts realized that the IT management software company, SolarWinds, had been hacked.

Unlike other hacks where customer data had been lost, cybercriminals used their access to inject malware into SolarWinds software, which was sent to potentially thousands of customers via a software update.

This was a really big deal because SolarWinds' Orion software lies at the heart of the network infrastructure of many organizations. The software is used to monitor and in some cases control network switches, routers, firewalls, and servers. This makes the administrators of the Orion software some of the most privileged users in an organization and it appears that any admin who used this server would have had his or her passwords compromised.

Many IT departments have been trying to dig out of this breach, and many business leaders are asking how this could have happened and whether it could have been prevented.

The volume and scope of the incident---and particularly the exposure of high-profile targets that were known for having great security---seemingly send a message that nothing could have been done to prevent it from being successful.

I would argue that there is more that could have been done. While there isn't a technology by itself that can stop these kinds of attacks, what we need is more adoption of Zero Trust when it comes to technology.

## The Three Tenets of Zero Trust

Could Zero Trust in and of itself prevented the attack from succeeding? Probably not. However, I am firmly convinced that broader deployment of Zero Trust could have mitigated the impact of the attack by potentially calling attention to it sooner and by limiting its spread.

The basic precept of Zero Trust is "never trust, always verify." In practice that comes down to three main tenets:

1. **Secure Access,** i.e., nothing and no one gets access to the network unless and until it is authenticated, authorized and verified.
2. **Least Privilege,** i.e., granting least-privileged access based on who is requesting access, the context of the request and the risk of the access environment.
3. **Log Everything**, i.e., all traffic must be logged and inspected at various inspection points that identify and permit traffic based on established rules. This maintains least-privileged access.

The first tenet of Zero Trust is where most of the concern around Sunburst centers. For any software you use, you expect that the software company will have gone through code reviews before putting into production. Your organization may have even done its own testing of the software before deploying it. But in the case of Sunburst, the malware waited two full weeks before executing, making it very difficult to detect.

One of the first things that happened after the malicious software was downloaded was that the malware would call out to their command-and-control servers. A command-and-control server is how the bad guys learn that their hack was successful and allows them to tell their malware what to do.

The fact that this attack method took place and was widely successful from the attackers' perspective, highlights several areas where a Zero Trust architecture could have mitigated risk and why it must be part of every organization's cybersecurity strategy going forward. Zero Trust isn't any one technology. It's more like a philosophy.

The first question a Zero Trust practitioner would have asked is whether your SolarWinds server needed any access to the internet. Indeed, many of a company's critical applications don't need direct internet access.

This is the second tenet of Zero Trust -- least privilege -- in action. Organizations should look at least privilege for job roles and functions as well as in their networks.

Sunburst also allowed cybercriminals to steal the passwords of administrators that used the server--- because those passwords would have been stored on the server. In some cases, a Windows domain administrator account may have been used to access the server, and if this was the case, the entire Windows domain could have been compromised. Domain admin accounts should be strictly limited. But, if an organization uses multi-factor authentication in a Zero Trust architecture, just stealing the passwords would not have been a significant issue.

If your company does use SolarWinds software, the first questions you would have asked were whether you had been infected and how extensive the breach might have been.

This is where the third tenet of Zero Trust---log everything---comes into play.

To answer questions related to the cause and extent of potential damage---whether your internal team did an investigation or if you brought in forensic consultants to assist---the investigators would have needed logs to make a clear and accurate determination.

The cybercriminals began sending the malware in March of 2020 and weren't discovered until December 2020. This means you would have needed network, DNS, account logins, and server logs for at least the prior year. With a Zero Trust architecture, all of that information would have been readily available.

## A Game Changer?

Some people have asked, is the SolarWinds breach a game changer? It certainly was the most significant breach in history, because of the sheer breadth and scope. But the techniques the attackers used were fairly commonplace. The defenses that an organization needed to defend itself already exist and should now be considered table stakes. If Sunburst is a game changer, it will be because it meant that 2021 was the year that we all adopted Zero Trust.

*** ** * ** ***

*George Finney is the Chief Security Officer for Southern Methodist University.*

* [Geopolitical Impact](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=geopolitical-impact)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/05/nation-states-are-reshaping-threat-landscape.jpg) BLOG

### Addressing Regulatory Issues

**Is There a Cyber Cold War? How Nation-States Are Reshaping the Threat Landscape**

Why today's geopolitical risks are every CIO's security problem....

[Wendi Whitmore](https://www.paloaltonetworks.com/perspectives/author/wendi-whitmore/ "Posts by Wendi Whitmore")
[](https://www.paloaltonetworks.com/perspectives/is-there-a-cyber-cold-war-how-nation-states-are-reshaping-the-threat-landscape/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/05/supply-chain-chaos-in-2025.jpg) BLOG

### Geopolitical Impact

**Supply Chain Chaos in 2025: How Geopolitics Are Rewriting the Rules**

Cyber resilience is the new supply chain imperative....

[Helmut Reisinger](https://www.paloaltonetworks.com/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com/perspectives/supply-chain-chaos-in-2025-how-geopolitics-are-rewriting-the-rules/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/navigating-the-geopolitical-cybersecurity-landscape-in-2025-1920.jpg) BLOG

### Geopolitical Impact

**Navigating the Geopolitical Cybersecurity Landscape in 2025**

Geopolitical cyber risks are evolving---learn how to stay ahead in 2025....

[Anand Oswal](https://www.paloaltonetworks.com/perspectives/author/anand-oswal/ "Posts by Anand Oswal")
[](https://www.paloaltonetworks.com/perspectives/navigating-the-geopolitical-cybersecurity-landscape-in-2025/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
