Zero Trust Turns 15 and Still Can't Get Out of Its Own Way

The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.

ThreatVectr Newsdesk· 3 min read
Zero Trust Turns 15 and Still Can't Get Out of Its Own Way
Share

John Kindervag coined zero trust at Forrester roughly fifteen years ago. The pitch was clean: ditch the crumbling perimeter model, verify everything, trust nothing by default. Simple in principle. Apparently brutal in practice.

Accenture puts the share of organizations hitting significant implementation challenges at 88%. Gartner's numbers are sharper in a different way — 35% of respondents who attempted a zero-trust initiative reported failures that hurt their organizations. Gartner's diagnosis: no strategic plan, no measurable goals, initiative dies.

So what keeps going wrong?

The product myth is still alive. Vendors sell "zero-trust" the way they'd sell a next-gen firewall — as a thing you buy and deploy. Morey Haber, chief security advisor at BeyondTrust, puts it plainly: there is no zero-trust product. Products implement discrete security controls. They don't embody a philosophy. Haber's estimate is that even the best vendor claims deliver somewhere between 10 and 15 percent of the controls a real zero-trust posture requires. The rest is marketing copy.

AmberWolf researchers demonstrated at DEF CON 33 that ZTNA products from three vendors carried exploitable vulnerabilities. The observation from researcher Richard Warren was dry and accurate: same bug classes, new stack. Buying a ZTNA product transfers trust from your perimeter to your vendor. That's not elimination of trust. It's relocation.

The technology myth is just as stubborn. George Finney, CISO at the University of Texas, is direct on this point. Micro-segmentation, policy-based identity, continuous authentication — these are tools that support zero trust. Zero trust itself is a risk framework. Its first pillar, per Kindervag's original definition, is identifying the protect surfaces that matter most: the crown jewels. Critically, Kindervag notes that IT teams don't always know what those are. Business leaders do. That's where the initiative has to start.

Mapping transaction flows across those protect surfaces is pillar two. In multi-cloud environments spanning on-prem infrastructure, containers, and microservices, that mapping exercise alone surfaces organizational dysfunction that no product can fix.

Finney's read is that the hard part is never technical. It's political. Developers shipping under deadline pressure aren't measured on security posture. Compliance teams aren't talking to networking teams. Nobody has defined what winning looks like.

The cost myth is the most fixable. Identifying protect surfaces costs nothing except time and honest conversation with business stakeholders. Building a cross-functional zero-trust working group pulls from governance, risk, and compliance functions most organizations already staff. Writing access control policies has no line item. Most organizations already run MFA, SSO, and identity management — the gap work is integration and alignment, not greenfield procurement.

None of this is glamorous. It doesn't generate a press release. It requires executives to treat zero trust as a business strategy rather than a security team project.

That framing, according to Gartner, is exactly what's missing — and what separates the initiatives that land from the ones that quietly collapse.

© 2026 Threat Vectr