Zero Trust Is a Discipline, Not a Dashboard
Every vendor at every conference will sell you “Zero Trust” like it’s something you switch on Tuesday and forget by Friday. I’ve sat through those pitches. I’ve also spent years trying to make it real inside companies with actual budgets, actual politics, and people who just wanted to do their jobs without security getting in the way. Those are two very different jobs, and the gap between them is where most Zero Trust programs quietly die.
Strip away the marketing and Zero Trust is one decision: stop trusting the network. Not the firewall, not the VPN, not the fact that a laptop is physically sitting in your office. You verify every request as if it came from a coffee shop in a city you’ve never visited — because functionally, it did. The old model drew a wall, called everything inside it trusted, and spent all its energy on the perimeter. That model died the moment your data moved to the cloud and your people started working from their kitchens. Zero Trust is just admitting it.
Obvious when you say it out loud. Brutal to actually pull off.
The technology was never the hard part
When I took over security for a global HR software platform, “inside the network” still meant “trusted.” Identity providers, micro-segmentation, device posture checks — that machinery exists and it works. I could stand it up. What no tool could do was let me walk up to an engineer who’d held domain admin for six years and tell him he didn’t need it anymore. To him, that access wasn’t a risk on a spreadsheet. It was how he did his job, how he helped his teammates, part of his identity in the company. And I was the new person telling him to give it up for a threat he’d never personally seen materialize.
Multiply that one conversation by a few hundred people and you understand why so many Zero Trust programs quietly stall in year two. It isn’t a networking problem. It’s a human one wearing a networking costume. The vendors sell you the machinery, which is the easy 20%. The other 80% is convincing an organization to give up conveniences it has relied on for a decade, and no product ships with that.
Standing privilege is the thing you’re really fighting
If I had to name the single enemy at the center of all this, it’s standing privilege — access that just sits there, granted once and never reconsidered, waiting to be stolen. The domain admin who needs those rights twice a year but holds them every day. The service account with keys to everything because it was easier than scoping it properly. Every one of those is a loaded weapon left on a table, and the attacker’s entire game is to find one and pick it up. Zero Trust, done seriously, is a long campaign to replace “you have this access forever” with “you get this access, for this task, for as long as you need it, and then it’s gone.” That shift is technically fiddly and politically exhausting, and it’s also most of the actual risk reduction.
Start with the blast radius
The mistake I see most often is trying to boil the ocean — “we’ll Zero Trust everything by Q4.” You won’t, and you’ll burn your political capital trying. I pick the systems where a breach would actually end careers: the customer data, the payment flows, the crown-jewel intellectual property. Wrap those first. Prove it works. Let the early wins buy the room to do the rest.
When I did it that way, the payoff wasn’t only fewer incidents. It was that the next project got approved without a fight, because leadership had already watched it pay off once. That’s the quiet strategy underneath the technical one: sequence the work so each phase earns the credibility and the budget for the next. A Zero Trust program that tries to do everything at once collapses under its own political weight. One that delivers a visible win on the crown jewels first gets to keep going.
Friction is the tax you’re managing
Here’s the part the pitches skip: every verification is a small tax on someone trying to work. Push too hard and people find ways around your controls, which leaves you less secure than before and resented on top of it. The craft is putting the friction where the risk is — strong, frequent verification on the crown jewels, and a nearly invisible path for the low-risk daily stuff. Done well, Zero Trust actually feels lighter to most employees than the old VPN-and-password grind, because context does the work quietly in the background. Done badly, it’s a productivity tax with a security label, and the organization will route around it out of sheer self-defense.
It’s a posture, not a project
Here’s the part that never makes the slide: Zero Trust is never “done.” Access creeps back. People change roles and keep their old permissions. A vendor integration quietly punches a hole through your segmentation. A “temporary” exception from a launch two years ago is still live. If you’re not re-earning it every quarter — reviewing access, killing standing privilege, questioning the exceptions you signed off on last year — you don’t have Zero Trust. You have a very expensive diagram and a false sense of security, which is arguably worse than knowing you’re exposed.
Treat it like a discipline, the way a good ops team treats uptime — a standard you hold continuously, not a milestone you cross once and celebrate. That’s the version that actually holds, and it’s the version no vendor can sell you, because the product was never the point. The posture is.