The era of ‘castle-and-moat’ security is officially over. For decades, organisations operated on the assumption that if you built a strong enough perimeter – firewalls, VPNs, and gateways – everything inside the network could be trusted.
That model has collapsed.
Today, the perimeter is porous. Data lives in the cloud. Employees work from everywhere and, critically, attackers aren’t breaking down the walls – they are logging in with stolen keys.
This shift has made Zero Trust more than just an industry buzzword – it is now the non-negotiable foundation of modern cybersecurity.
The failure of implicit trust
Traditional security relied on implicit trust. Once a user passed an initial check at the perimeter, they could move laterally across the network.
Adversaries continue to exploit this outdated approach.
According to the CrowdStrike 2026 Global Threat Report, 82% of detections in 2025 involved malware-free intrusions. Attackers are increasingly using valid credentials and legitimate tools to evade legacy defences, bypassing traditional controls without relying on malicious code.
If your security strategy is still focused on detecting malware at the perimeter, you’re leaving the majority of modern attacks undetected.
The need for speed
Cybercriminal speed now exceeds human reaction times. CrowdStrike recorded an eCrime ‘breakout time’ – the time to compromise a host and move laterally – of just 27 seconds.
In less than a minute, an attacker can escalate privileges. No human team can react fast enough, necessitating a shift toward automated, policy-based responses and least-privilege access.
Defining Zero Trust
Zero Trust isn’t a single product you buy – it’s a strategic framework. As defined by CrowdStrike, it centres on the principle of ‘never trust, always verify’.
Regardless of where a connection request originates, no user or device is trusted by default. Every request must be authenticated, authorised, and encrypted.
This approach limits the ‘blast radius’ of a breach, ensuring that if credentials are compromised, the attacker cannot freely roam the network to exfiltrate high-value data.
The ransomware evolution
The urgency for Zero Trust is driven largely by the evolving tactics of ransomware groups. Veeam reports that roughly 75% of organisations experienced at least one attack in the last 12 months.
However, as ransom payments decrease due to government bans and better refusal rates, threat actors are pivoting.
We are seeing a return to ‘data encryption roots’. While data extortion (threatening to leak stolen data) has been popular, Veeam predicts attackers will return to locking down systems and diversifying how they monetise access, as double-extortion tactics yield diminishing returns.
Resilience through backup
Veeam highlights that successful attacks often exploit flat networks and unprotected backups. To counter this, they recommend Zero Trust-style measures for data resilience:
- Immutable storage: Backups that cannot be altered or deleted.
- Role-based access: Limiting who can touch backup infrastructure.
- Isolated recovery environments: Ensuring data restoration without reinfecting the network.
The identity battleground
With the perimeter dead, identity is the new battleground.
The Australian Signals Directorate (ASD) Annual Cyber Threat Report 2024–25 emphasises identity controls to combat business email compromise and supply-chain attacks.
But implementing robust identity controls creates tension. Employees often view security measures like MFA as a personal inconvenience. When security creates friction, users find workarounds, opening new vulnerabilities
A successful Zero Trust strategy must balance verification with user experience. This means using context-aware access policies that only increase authentication requirements when risk indicators are high, rather than bombarding users for every interaction.
BYOD and the AI challenge
The challenge extends to the devices employees use and the tools they access. The rise of Bring Your Own Device (BYOD) policies and Generative AI adds layers of complexity.
Enterprise browsers now provide Data Loss Protection (DLP) controls regarding external Large Language Models (LLMs). This allows organisations to restrict or monitor data transfers, preventing sensitive company IP from being fed into unauthorised AI platforms.
This is Zero Trust in action: allowing the use of modern tools while enforcing strict boundaries on data movement.
Moving from theory to practice
Transitioning to a Zero Trust architecture is not an overnight process. It requires a shift in mindset from defending the perimeter to protecting the data.
It starts with visibility – knowing exactly what devices and users are on your network. From there, it involves implementing strong identity controls, segmenting your network to prevent lateral movement, and ensuring your backup and recovery systems are resilient enough to withstand a breach.
In a landscape where attackers move in seconds, and valid credentials are the weapon of choice, implicit trust is a luxury no business can afford. Zero Trust is the only way to ensure that when an intruder gets in, their access leads nowhere.




