Zero trust does not remove network controls
Checking every request does not mean you stop caring about network design.
Segmentation, firewalls and monitoring all still limit how far something can travel and how much you can see. Zero trust removes the assumption that network position proves anything; it does not remove the value of making an attacker's movement harder and noisier. Vendors selling one as a replacement for the other are describing a product strategy rather than an architecture.
More on Zero trust
- Zero trust removes implicit trust in network position, not confidence in colleaguesIt was never about the people
- Continuous evaluation means decisions can changeYes is not for ever
- Policy enforcement depends on reliable identity signalsRight rule, smudged label
- Service-to-service traffic needs identity tooMachines need names too
- Device trust should match what is actually measuredOnly what the probe touched
- Policy engines create critical dependenciesOne box, every door
