Category Zero Trust

[ZT 3] What Zero Trust Changes About How You Work

A strategy you cannot buy still has to show up somewhere. Here is where: the sign-in, the VPN that quietly disappears, the admin rights that expire, the office network that stops being special, and the operational loop that keeps all of it honest. The lived experience of Zero Trust, costs included.

[ZT 2] From the Perimeter to the Access Decision

The castle-and-moat model was a reasonable design for a world that stopped existing. Where Zero Trust actually came from, the 2010 report that flipped the mantra, Google's proof that it works at scale, and the destination: every access is a per-session decision, made on evidence, by a policy engine.

[ZT 1] Zero Trust Is Not a Product

Nobody sells Zero Trust, including the vendors who say they do. Microsoft says so on its own documentation, NIST needed 24 organizations and 19 distinct builds to demonstrate one, and the man who coined the term has spent a decade saying you cannot buy it. What you can do is practice it.