Security
Zero trust is a journey — but it should have a finish line
Zero trust programs fail when they are framed as endless journeys. The successful ones define measurable milestones and declare victory on each.
Few security ideas have been as widely endorsed — or as loosely defined — as zero trust. Every vendor sells it, every framework references it, and many programs drift for years without a clear sense of whether they are succeeding.
Make it measurable
The programs we see succeed break zero trust into concrete, testable milestones: every user on phishing-resistant authentication; every privileged action brokered and recorded; every critical application reachable only through an identity-aware proxy. Each milestone has a date, an owner, and a metric.
- Identity: percentage of users and service accounts on strong, phishing-resistant authentication.
- Devices: share of endpoints verified healthy before access is granted.
- Applications: number of critical apps removed from the flat network.
- Data: proportion of sensitive data classified and protected by policy.
If you cannot measure your zero-trust progress, you are not doing zero trust. You are doing a rebrand.
Sequence by blast radius
Start where a breach would hurt most — privileged identities and crown-jewel applications — rather than where implementation is easiest. Early wins on high-impact assets build the credibility and funding the rest of the program needs.