πŸ’‘
If you are interested in a high-level executive summary about the pillars of Zero Trust, read this article.
Simplicity is the most difficult thing to secure in this world; it is the last limit of experience and the last effort of genius.

George Sand

Summary

What problem does Zero Trust solve?

In 2009, Google was still invested in its search engine business. They had already built custom technology to combine advertisement delivery and web searching, leading them to be the one place to go if you and your products needed attention. In economics this is defined as a moat: a long-term, sustainable competitive advantage, which protects your profits from competitors and external threats. No one else could efficiently sell attention to marketing at the time. Or had the capability (audience segregation, performance metrics) to enable "evidence-based marketing" (S. Sinnek et. al.).

At that time in 2009 a series of cyberattacks known as Aurora hit multiple businesses. Including Google. They stole core parts of that intellectual property. That moat. Something Google had invested in for years to gain an edge within the web advertisement market.

So what did Googlers do? They learned from Aurora. Within its internal initiative (BeyondCorp) Google started to rethink their security model. In 2009 Google defined the underlying concepts of Zero Trust. Far ahead of others in the industry.

BeyondCorp was a Google internal initiative to rethink security models.

The key problems BeyondCorp identified can be summed up:

  1. Implicit trust of the internal network
  2. Unrestricted lateral movement
  3. Perimeter-focused security model

Why is this a problem? – Attackers abused these conditions to exfiltrate classified information. Valuable business data. Key intellectual property assets. What gives your company an edge in the business? How do you protect this moat? If your information security sucks, your moat can be stolen, and you will face a market with rapidly evolving peers.

Aurora's attack concept (Tools, Techniques, and Procedures aka TTPs) didn't just apply to Google but to many other (affected) businesses. The resulting threats and risks were severe enough to incentivize change. Slowly.

In 2025, more companies are transforming their security models. Changes take time. In Information Security... more than they should.

Focus and strategy

So why is Zero Trust useful within the workforce? – To understand that, we need to remember the network and IT landscape 10-15 years ago, maybe in 2009 or earlier.

Bulky tower desktop PCs in the office, only a few laptops. Smartphones used to be expensive. On-premises Exchange servers used to crash. You can name many unevolved examples of that era of computing.
During that time few people used to work remotely. And if they did, it really didn't matter whether they had access to IT services or not.

Tech demand grew. Competitiveness forced companies to become more agile. Born out of that demand came the era of cloud computing. And the cloud computing macro trend brought change.

  • IT matured. Buggy Exchange servers became MS365.
  • Underperforming colocation systems got migrated to AWS or Azure.
  • Core production systems were made to scale up and down based on demand.
  • Central organizations became distributed into new digital services. Internal sales apps were merged into Salesforce, internal ticket systems got consolidated into Jira, and meetings got scheduled via WebEx or Zoom later. Just to name a few examples.

Some legacy parts remained, but for the most part, competition forced businesses to adapt. Agile. Competitive. Without time to wait. Short time-to-market cycles, iterative improvements. It all came with pros and cons.
But that 2020s velocity led to an expanding "grey area". Unknown to the rest of the workforce, a hidden problem started to grow: the end of the old network perimeter. Network? What does that have to do with competitiveness?

The idea of a perimeter is great, until it isn't. To reach into the value chain and into the revenue-generating processes, you need to ask Who and What. Evidence-based security asks the same questions as evidence-based marketing.

What Zero Trust Has to Do with the Grey Area of Perimeter Security

What drives this expanding gray area?

  1. VPNs - Virtual Private Networks. Essentially a bypass. Because we don't ask WHAT we secure. ❔
  2. DMZs and Firewalls. Essentially a set of filters. We only assume WHAT we secure is inside the corporate LAN. ❓
  3. Partners - Supply chain elements introduce additional concerns. Zero Trust strategies should focus on this. Not every enterprise architecture allows supply chain governance and effective corporate compliance. As a CxO, take note. You will be affected.

Bypasses and filters can't target core business logics / the moat / the value generating processes. Zero Trust can. If it's done with an Enterprise Architecture mindset. With an evidence-based security approach that asks Who and What. And finally: HOW?

How: Zero Trust Really Ticks

Zero Trust tech needs two touchpoints to protect what's most valueable:

  1. What: defined by domains / DNS.
    1. The name of the system, for example system_a.department
  2. Who: defined by the Identity Provider (IdP)
    1. The context of the access, for example user.name in location_1 during business hours from a company PC pc_1.

So how does it work?

In essence, you define segments based on domains. Like finance πŸ’°, procurement πŸ›οΈ, marketing, human resources, legal βš–οΈ, production, tech, management, execs and so on.
That defines What you protect: the processes and the people. In a simple scenario all lawyers use system_a.legal, system_b.legal and system_c.legal . This can be internal or external, can be the court of law, the internal legal library, or a regulator portal. Likewise, you group systems for all the other business domains. Some get shared cross-functionally, some don't. In finance you probably have accounting, controlling, M&A, business planning, etc.

Who can access system_a.finance or system_b.legal or system_c.tech depends on the individual. And the role. The context of the access: Where the access is started from. When the access is happening. How is the access started: with a company account from a company PC or from a private device from a new location? Has the user travelled 1000s of kilometers within minutes according to the geolocation check? Is the device up to date?

Zero Trust really ticks based on context. Attackers cannot assume context: they cannot get a compliant device with the same specs at the usual user location and access the same systems. They need to do something the user would never do.

Pitfalls to avoid: Zero Trust and these weird security vendors

Security vendors are weird.

You may read about SASE (Secure Access Service Edge) or ZTNA (Zero Trust Network Access). But don't bother. It's just DNS and IdP. What and Who.
-> Context. βœ…

DNS and IdP, in combination with tunneling protocols, are the bread and butter of Zero Trust. 🍞 Sadly, vendors try to hide this from you. The efforts are high, and the impact is transformational.

The key takeaway: just because you have a VPN or Tunneling with a fancy Zero Trust system, DNS isn't automatically solved. Many approaches require per-application configs. Especially if you perform TLS inspection for Data Leak Prevention or IPS purposes

For example:

  • Zscaler uses DTLS for user endpoints and IPsec for servers
  • Cloudflare WARP uses WireGuard or MASQUE (new)
  • Cisco (Umbrella) uses IKE2 or IPsec afaik
  • Pangolin uses WireGuard, and so do other open source solutions.

Why does this matter? Well, costs, costs, costs. AI can tell you the details about the differences and why that matters. What it cannot tell you is what the cost and time-to-solution impact is. Because that heavily depends on the scope of the Zero Trust project.

As a rule of thumb: avoid a vendor lock. WireGuard may not be fancy, but it is simple and probably cost-efficient. It may be too simple for many organizations, especially if they have a heavy technical footprint or demanding connectivity requirements.

Zero Trust - Here be danger!

Here is the kicker: What exactly a Zero Trust solution does (whether it's SASE, ZTNA, or something else pitched under an even more obscure acronym) is not defined. If you are looking for accurate information about these terms, you will not find them. By intention.

In translation: as a typical CxO, you will have to ensure that your organization has the right capabilities. Enabling the organization to reduce the risks by focusing Who accesses What is key.
To reduce the risks and to strengthen governance and compliance. Best practices, of course. Whether this is done with DNS and IdP shouldn't be a top concern. Sadly, it has to be.

Naive Zero Trust transformations will fail, even at mid-sized organizations. A sudden complexity explosion that can reach deeply into what generates revenue, won't sit well with stakeholders and shareholders alike.

How to avoid that: think in solutions before the vendors think for you.

Whether it's Zscaler, Cloudflare or on-premises Cisco: DNS and IdP are the core parts you need to evaluate for compatibility.

Another concerning part of the Zero Trust landscape is vendor locks. Especially, when it comes to Identity Management. Microsoft (Entra ID) and Okta dominate the market with solutions that do not have easy exit strategies. At the same time, there are impactful risks here. That's a bird-in-a-cage 🦀 problem ⛓️.

Don't outsource your brain when it's about the moat

Zero Trust doesn't deliver 100% security. That is impossible. No one has that. What some organizations have is problem-solving capability. No one else will solve your org's problems.

The question is how to approach Zero Trust strategically: outsource the brain to a system house that works closely with a vendor? Or build up in-house capability?
There is not one answer to that, but there is a general rule of thumb: if it's about your moat, your core value-generating processes, the cash cow, so to say, do it yourself. If you are a digital business exec, build it up yourself. You don't have to own the tech stack, but you have to own the problem-solving capability. No one else will solve your org's problems. Transformation always means to embrace change, and that can only come from the inside.

Summary

Mind map & summary: Simple Zero Trust
  1. Zero Trust (ZT) asks W questions and leads to evidence-based security practices that can protect the moat of the company and mitigate core risks.
  2. To be successful at Zero Trust, you must not outsource your brain. Zero Trust is a transformation project and not a tech migration. It's not about getting rid of the VPN. That is misinformation.
  3. Perimeter-focused security is still important, but it's not the one and only concern to focus on. Identity is the perimeter now, and context is what defines the acceptable security level.