Every security vendor now sells a "zero trust solution." Buy the product, flip it on, tick the box. That framing is convenient for sales cycles and almost useless for actually reducing risk.
Zero trust was never a product category. It's a working assumption: nothing inside your network gets trusted by default just because it's inside your network. That assumption has to be re-earned constantly, by people and processes, not switched on once by a piece of software.
Where the product framing breaks down
A tool can enforce identity checks, segment a network, or flag anomalous access. What it can't do is decide what "least privilege" means for your finance team's quarterly close process, or notice that an engineer still has admin access from a project that ended eight months ago. Those are habits — reviewing access regularly, questioning default permissions, treating every request as something to verify rather than assume — not settings.
What the habit actually looks like
- Access reviews on a calendar, not a trigger. Waiting for an audit to check who has access to what means you're always finding problems after they've been sitting there for months.
- Verifying explicitly, even internally. "They're on the VPN" is not the same as "they should have access to this system."
- Assuming breach, not just preventing it. The useful question isn't only "how do we stop this," it's "if this account is compromised right now, how much damage can it actually do?"
- Treating access removal as routine, not exceptional. Offboarding — from a role, a project, or the company — should be as practiced as onboarding.
Why this is a training problem, not just a tooling one
We get called in most often after the tooling is already in place — a client has bought the platform, configured the policies, and adoption still hasn't happened, because the people operating it were never trained on the judgment calls it requires. A zero trust policy engine is only as good as the person deciding what "least privilege" means for a specific role.
That's a different skill than reading a vendor's admin console documentation. It's closer to a security mindset than a software feature, and it has to be built deliberately across a team, not assumed to arrive with a new license.
Buying the product is the easy part. The habit is what actually reduces risk — and habits don't come installed.
