CISO Tribune

Analysis

Zero trust is an org-change problem wearing a technology costume

Why zero trust programs stall: the architecture is documented, the tooling is bought — and the organizational change is unbudgeted. A leadership view.

By CISO Tribune Editorial · Published July 7, 2026 · 2 min read

TL;DR: Zero trust fails as a project and succeeds as a program. The architecture is well documented (NIST 800-207) and the tools are mature; what stalls it is everything the purchase order didn't cover — identity debt, application archaeology, and thousands of humans whose login experience you're about to change. Lead it as organizational change with a technical component, not the reverse.

What is zero trust actually asking the organization to do?

Strip the vendor language and the model asks four hard things. Know every identity — human and machine — and make identity the perimeter, which first means confronting years of identity debt: orphaned accounts, shared credentials, over-privileged service accounts. Know every application and how it authenticates — including the twenty-year-old one that runs payroll and predates the concepts involved. Enforce least privilege continuously — which means taking access away from people who have it, the single most politically expensive act in enterprise IT. Verify continuously — device posture, context, session — which changes the daily experience of every employee. Only the last one is mostly technology.

Why do the programs stall?

A recognizable sequence. Year one: strategy deck, tool purchases, a successful pilot on a friendly application. Year two: the pilot meets the application catalog — half the estate can't speak modern authentication; the identity data is dirtier than assumed; the first access-restriction wave generates executive escalations; the program quietly narrows to "deploy the new VPN replacement." The lesson isn't that zero trust is wrong — it's that the constraint was never the platform. It was identity hygiene, application readiness, and the organization's appetite for friction, none of which appeared in the business case.

How do successful programs sequence it?

Three patterns recur. Identity first, visibly: a year of unglamorous work — MFA everywhere, privileged access management, killing shared accounts, joiner-mover-leaver automation — pays for every later phase and reduces real risk immediately even if the program never advances. Risk-ranked expansion: protect the crown-jewel applications and the highest-risk populations (admins, finance, executives) before chasing coverage percentages; a big-bang enterprise rollout is how programs die. Friction budgeting: treat user friction as a spendable budget — every new prompt or blocked flow draws it down — and buy it back with visible wins like killing the legacy VPN or enabling clean BYOD. Programs that only add friction get cancelled by acclamation.

What is the CISO's actual job in this?

Not architecture — the frameworks are written. The job is executive translation and expectation-setting: framing zero trust as a multi-year operating-model change with quarterly risk deliverables, not a product deployment with an end date; getting business-unit leaders to co-own the access decisions for their applications; and reporting progress in risk terms ("privileged access to the payment system now requires verified device and step-up auth") rather than coverage theater ("62% of apps onboarded"). The programs that survive leadership changes are the ones whose value showed up before the vision finished — which is, conveniently, exactly what sequencing identity first delivers.

Frequently asked questions

What is zero trust in simple terms?
A security model that stops treating the internal network as trusted: every access request is verified based on identity, device, and context, with least privilege enforced continuously — 'never trust, always verify.' NIST SP 800-207 is the reference architecture.
Why do zero trust programs fail?
Rarely for technical reasons. They fail because the work is mostly organizational: cleaning up identity, cataloguing applications, changing how every employee logs in, and getting business units to accept access friction — change management that the tooling budget never included.
How long does zero trust implementation take?
Multi-year, honestly. Mature programs sequence it: identity foundation first, then highest-risk applications and populations, expanding gradually — rather than a big-bang rollout, which is where most stalled programs died.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.