Skip to content
15 Years Of Zero Trust Why It Matters More Than Ever

15 Years Of Zero Trust Why It Matters More Than Ever

www.darkreading.com April 16, 2026

With the emergence of AI-driven attacks and quantum computing, and the explosion of hyperconnected devices, zero trust remains a core strategy for security operations.

Fifteen years ago, I introduced the zero-trust security model while working as an analyst at Forrester Research. At the time, cybersecurity was still rooted in perimeter-based thinking, built on the assumption that everything inside the network could be trusted. But real-world breaches told a different story. Attackers were moving laterally, exploiting implicit trust, and bypassing traditional defenses with ease.

Shortly after publishing my first report, Dark Reading interviewed me and wrote one of the first articles zero trust . That conversation helped bring the model beyond the analyst community and into the broader security dialogue.

What began as a challenge to a broken security model has since become the most widely adopted cybersecurity strategy in the world. From analyst reports to boardroom conversations to federal mandates, zero trust has reshaped how organizations think risk, resilience, and control.

When I first proposed zero trust, many still believed security could rely on a strong perimeter, because everything was safe inside the network. That assumption created what I called a broken trust model: the internal network was "high trust," the Internet was "low trust," and packets moved from inside to outside without inspection. That approach, however, ignored how attackers actually worked.

To address this flawed model, I introduced a strategy that was both straightforward and revolutionary: never trust, always verify. Treat every packet, connection, and system with zero trust. Segmentation, access control, and visibility were the early tools that made this possible. Alone, they weren't new ideas. But together, they laid the groundwork for a model that could prevent attackers from accessing sensitive systems and data, even after they had already breached the network.

The 2015 breach at the US Office of Personnel Management highlighted the dangers implicit in this broken trust model. Attackers stole sensitive information on more than 21 million people who had federal government clearances, including the digital representation of their fingerprints, by using stolen credentials to move laterally through the OPM's systems for months undetected. That incident showed the world that perimeter defenses alone cannot stop determined adversaries.

Congress responded with a 2016 report that recommended federal agencies adopt a zero-trust security model. Soon after, zero trust became part of boardroom conversations and national policy. By 2021, a presidential executive order mandated its adoption across the federal government.

While technology has evolved and improved our ability to create zero-trust environments, its underlying principles remain unchanged: define protected surfaces, map transaction flows, architect from the inside out, write policy, and monitor and maintain the system. Those five steps work because they focus on protecting what matters most: the sensitive data, applications, assets, and services (collectively known as DAAS Elements). The secret to the success of deploying zero trust is to focus on containing a single DAAS element inside a single protect surface and then building out your environment, one protected surface at a time.

Over the years, I've seen vendors try to market zero trust as a product or a feature. That misses the point. Technology will always change, but strategy endures. When organizations forget this and chase shortcuts, they fail. When they adhere to the strategy, they develop systems that evolve and improve over time, regardless of emerging new technologies.

When I first started talking zero trust, cyberattacks still unfolded at human speed. Today, threats move as fast as machines, which means automation is essential for defenders.

Visibility has always been a struggle, but we now have better tools. Security graphs, visualization, and learning modes give us a clear view of what's happening inside networks. Automation enforces policy without hesitation or delay.

Containment becomes critical: the ability to limit damage the moment it begins. Controlling the "blast radius" is important in critical situations. Controls must act automatically, not just alert us, and enforcement must happen at machine speed, without waiting for a human to catch up.

Only a machine can defeat another machine. AI gives attackers new capabilities, but it also gives defenders the ability to enforce zero trust at scale. Visualization helps us understand the battlefield. Enforcement ensures we win on it.

One of the most common misunderstandings zero trust is the belief that it's something you can buy. Vendors continue to package products as "zero-trust solutions," which confuses the market and distracts leaders from what truly matters: strategy. Zero trust isn't a box you install or a license you renew; it's a mindset and a way of operating.

Another misconception is that zero trust has a finish line. You can't "complete" zero trust. It's a continuous journey of adapting, refining, and reinforcing security principles. Organizations that treat it as a one-time project often stall or fail to realize its full potential.

The bigger obstacles are cultural. Many teams cling to outdated habits like perimeter defenses and awareness campaigns, resisting the deeper changes zero trust demands. Others falter because they approach it as a checklist item rather than a strategic transformation.

Leadership support is also critical. I've seen programs stall when executives don't set clear incentives or priorities. Without commitment from the top, zero-trust efforts rarely move beyond the talking stage.

The future will bring daunting challenges, including AI-driven attacks, quantum computing, and billions of hyper-connected devices. Each will test our defenses in new ways. Yet the principles of zero trust apply to all of them.

We must understand that cyberattacks are always imminent, so we must design systems that respond immediately. That means building controls that don't just alert us, but act. Containment becomes critical: the ability to limit damage the moment it begins. In today's environment, policy enforcement must happen at machine speed, not human speed. The perimeter is gone, and zero trust offers a framework for adapting to this new reality that prioritizes resilience, visibility, and control.

I often compare zero trust to military strategy. Sun Tzu, Clausewitz, and Frederick the Great all taught that ideas endure while tactics shift. As a military strategist once told me, "Most people think they are being strategic when they are being tactical. They confuse strategy and tactics." The same is true in cybersecurity. Technologies like firewalls, cloud platforms, and AI will continue to evolve, but the principle remains: Trust is a vulnerability.

That's why zero trust continues to spread across the private and public sectors. It gives leaders a clear way to think security, define enforceable policies, and treat every system and connection with the same level of scrutiny.

If you've already begun the journey, stay on course. If you haven't, now is the time to start. Because in a world where trust is a vulnerability, strategy is your strongest defense.

Chief Evangelist, Illumio

John Kindervag is considered one of the world’s foremost cybersecurity experts. With more than 25 years of experience as a practitioner and industry analyst, he is best known for creating the revolutionary zero-trust model of cybersecurity. As chief evangelist at Illumio, John is responsible for accelerating awareness and adoption of zero-trust segmentation.

Most recently, John led cybersecurity strategy as a senior vice president at On2IT. He previously served as field chief technology officer (CTO) at Palo Alto Networks and, before that, spent more than eight years as a vice president and principal analyst on the security and risk team at Forrester Research.

This year, John received the Baldrige Foundation Award for Leadership Excellence in Cybersecurity for his pioneering work in Zero Trust.

CISO Survey 2026 The State of Incident Response Readiness

AI SOC for MDR: The Structural Evolution of Managed Detection and Response

How Enterprises Are Developing Secure Applications

KuppingerCole Business Application Risk Management Leadership Compass

2026 CISO AI Risk Report

Defending Against AI-Powered Attacks: The Evolution of Adversarial Machine Learning

Tips for Managing Cloud Security in a Hybrid Environment?

Zero Trust Architecture for Cloud environments: Implementation Roadmap

Security in the AI Age

Identity Maturity Under Pressure: 2026 Findings and How to Catch Up

Extracted Entities

Industries (1)