You Think You Have Zero Trust. You Don't.
Most executives believe they have Zero Trust. Most executives are wrong.
They have a conditional access policy. They have MFA. They have an Intune compliance rule. And they’ve checked the box on a board slide that says “Zero Trust: Implemented.” But conditional access is one control in one layer. Zero Trust is an end-to-end architecture that spans identity, device, network, application, and data. The gap between those two things is the liability you don’t know you’re carrying.
🔒 The Five Layers of Zero Trust
Zero Trust is not a product you buy. It is an architecture you build. It requires coverage across five layers, and each layer must enforce the same principle: never trust, always verify.
Zero Trust is a chain. Each layer is a link. If any link is missing, the chain breaks. Most organizations have two links and call it a chain.
- Identity: Conditional access, MFA, identity governance, least privilege. Most organizations stop here. This is the front door.
- Device: Endpoint compliance, device health attestation, certificate-based authentication. A healthy identity on an unhealthy device is still a risk.
- Network: Microsegmentation, no implicit trust zones, encrypted traffic between all segments. The flat network is the architecture Zero Trust was designed to replace.
- Application: Per-application access, not VPN-based network access. The user should reach the app, not the network.
- Data: Classification, DLP, encryption at rest and in transit. The final layer: what you’re actually trying to protect.
Most organizations have deployed one or two layers. A few have deployed three. Almost none have deployed all five. That’s not Zero Trust. That’s a partial deployment with a confident name.
💰 The Liability Gap
Your cyber insurance carrier is beginning to ask the right questions. Not “Do you have MFA?” That’s table stakes. The questions that determine your premium: “Do you have microsegmentation?” “Do you have per-application access?” “Can you demonstrate that lateral movement is blocked across network segments?”
The insurance carrier is the authority that defines what Zero Trust means. Not the vendor. Not the consultant. The carrier. And the carrier is asking questions most organizations can’t answer.
The gap between your perception and your architecture is the liability you don’t know you’re carrying. You believe your breach blast radius is contained. Your architecture tells a different story. When the carrier asks the question during underwriting, the answer determines your premium, or your coverage.
Each missing layer is a small risk. Five small risks is not five times the liability. It is exponentially more, because the layers are interdependent. The carrier knows this. That’s why they’re asking.
✅ The Maturity Question
The question for leaders is not “Do we have Zero Trust?” The question is: “Across how many layers can we demonstrate that implicit trust has been eliminated?”
If the answer is one or two layers, you have a control deployment. You do not have an architecture. Overconfidence in incomplete Zero Trust is worse than no Zero Trust at all, because it creates the illusion of protection. The gap between those two things is where breach liability lives.