Zero trust migration is dependency discovery
Most of the work in a zero trust programme is not deploying anything. It is finding out what actually talks to what.
Organisations consistently discover systems nobody remembers, connections nobody documented and integrations that only exist because of a decision made a decade ago. That inventory is uncomfortable, slow and by far the most valuable output. The technology is largely available; the reason these programmes run long is that nobody knew the shape of the estate when they started.
More on Zero trust
- Zero trust removes implicit trust in network position, not confidence in colleaguesIt was never about the people
- Continuous evaluation means decisions can changeYes is not for ever
- Policy enforcement depends on reliable identity signalsRight rule, smudged label
- Zero trust does not remove network controlsKeep the fence
- Service-to-service traffic needs identity tooMachines need names too
- Device trust should match what is actually measuredOnly what the probe touched
