← All writing

Cutting Through the Noise

Zero trust isn't a product

"Zero trust" turns up on a lot of quote sheets, usually next to a price. That's the first clue something's off.

The model itself is sound. Stop assuming the network is safe just because someone's already inside it. Verify every request, grant the least access that works, design as if a breach has already happened. As a way of thinking about security, it has aged well.

But it's a posture, not a purchase. You don't buy zero trust the way you buy a firewall. It's how you arrange identity, segmentation, access and monitoring across things you mostly already own. A single box labelled "zero trust solution" covers one slice of that and leaves the rest of the architecture exactly as it was.

So when it lands on a datasheet, the useful questions are about scope:

  • Which part of the model does this actually enforce?
  • What does it assume is already in place?
  • What still has to change in how we grant and check access, regardless of what we buy?

Bought as a product, it's a label on a box. Built as a posture, it's one of the better ideas security has had in years.

The badge is cheap. The redesign is the work.

Related

Written by Mandeep Singh. More at the writing index or get in touch.