Zero Trust Turns 15 and Still Can't Get Out of Its Own Way

The 'never trust, always verify' model isn't failing because the idea is wrong. It's failing because organizations keep treating a security philosophy like a SKU.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Zero Trust Turns 15 and Still Can't Get Out of Its Own Way
Share

Key points

  • John Kindervag coined zero trust at Forrester fifteen years ago as a replacement for the perimeter model.
  • 88% of organizations report significant implementation challenges, per Accenture.
  • A Gartner survey found 35% of respondents who attempted a zero-trust initiative suffered failures that hurt their organizations.
  • AmberWolf researchers found exploitable vulnerabilities in ZTNA products from three vendors at DEF CON 33.
  • The costliest mistakes are organizational, not technical: no strategy, no cross-functional ownership, no definition of success.

The product myth

Vendors sell "zero-trust" the way they'd sell a next-gen firewall: as a thing you buy and deploy. Morey Haber, chief security officer at BeyondTrust, is blunt about it. There is no zero-trust product. Products implement discrete security controls; they don't embody a philosophy. Haber estimates that even the most credible vendor claims deliver between 10 and 15 percent of the controls a real zero-trust posture requires. The rest is marketing copy.

AmberWolf researchers demonstrated at DEF CON 33 that ZTNA (zero-trust network access) products from three vendors carried exploitable vulnerabilities. Researcher Richard Warren's observation was dry and accurate: same bug classes, new stack. Buying a ZTNA product transfers trust from your perimeter to your vendor. That's relocation, not elimination. We first covered ZTNA product risk on 16 June 2026, and the AmberWolf findings fit a pattern we've tracked since.

The technology myth

George Finney, CISO at the University of Texas, is direct. Micro-segmentation, policy-based identity, continuous authentication: these are tools that support zero trust. Zero trust itself is a risk framework. Its first pillar, per Kindervag's original definition, is identifying the protect surfaces that matter most. Kindervag notes that IT teams don't always know what those are. Business leaders do. That's where the initiative has to start.

Pillar two is mapping transaction flows across those surfaces. In multi-cloud environments spanning on-prem infrastructure and containerised microservices, that mapping exercise alone surfaces organizational dysfunction no product can fix.

Finney's read: the hard part is never technical. Developers shipping under deadline pressure aren't measured on security posture. Compliance teams aren't talking to networking teams. Nobody has defined what winning looks like. Our 29 May story on employees shipping production apps without authentication is a clean illustration of exactly this problem.

Should you worry about the cost?

Identifying protect surfaces costs nothing except time and honest conversation with business stakeholders. Building a cross-functional zero-trust working group draws on governance and risk functions most organizations already staff. Writing access control policies has no line item. The gap work is integration and alignment, not greenfield procurement.

None of this is glamorous. It requires executives to treat zero trust as a business strategy rather than a security team project. That framing, according to Gartner, is precisely what separates initiatives that land from the ones that quietly collapse.

The blunt truth after fifteen years: zero trust isn't hard to understand. It's hard to govern. And most organizations still haven't figured out that governance is the product.

© 2026 Threat Vectr