Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Zero Trust - There is no Zero Trust in Zero Trust
Zero Trust Articles Artificial Intelligence Cloud Security Data Breach Data Loss Prevention Data Protection Identity & Access Management Regulations and Compliance Security Architecture Zero Day

There is no Zero Trust in Zero Trust

Dirk SchraderBy Dirk SchraderSeptember 2, 20266 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
There is no Zero Trust in Zero Trust
Share
Facebook Twitter LinkedIn Email Copy Link
AI Summary

A Zero Trust architecture still has to let work happen.

There is, then, no zero trust in Zero Trust.

Zero Trust's undeclared gap closes by taking a full accounting of who and what is already in the building, and deciding, deliberately, what each of them should be allowed to reach. .

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In January, the Cloud Security Alliance asked security professionals how they handle the identities on which their AI systems run. Fewer than a quarter of organizations had a documented, formally adopted policy for creating or removing one. More than 16% do not track when a new identity is created at all. Those identities hold tokens and standing access to production systems, and the people accountable for governing access have, by their own account, no record of them.

Authentication answers only half the question

This is the quiet arithmetic behind a phrase the industry has repeated for a decade: identity is the new perimeter. The phrase earned its place by moving the control point off the network and onto the identity. What it left unfinished is the harder half. It answers how something gets in, but not what it can reach once inside, who approved that access, or how far the blast radius extends if the credential is stolen.

That question is about access, and access is where the attack surface now lives: in the standing entitlement behind the login, the permissions an identity carries whether or not it uses them today. Multi-factor authentication and conditional access govern one moment, the moment of entry, while the exposure is everything an identity can reach afterward. A Zero Trust architecture still has to let work happen. Work requires access, and access is trust that has been granted and left in place. There is, then, no zero trust in Zero Trust. Some irreducible trust always remains, extended to whatever holds the entitlement and sitting quietly until something uses it. That residue is structural and undeclared.

Every framework assumes an inventory not built for agents

The frameworks meant to prevent this agree on something none of them quite says aloud: everyone is inventory-first. NIST’s Cybersecurity Framework makes asset management (ID.AM) a precondition for access control (PR.AA). Germany’s BSI IT-Grundschutz is more literal about the order of operations, opening with the Strukturanalyse, an enumeration of every asset in scope, before any protective control is chosen. France’s ANSSI builds its hygiene guidance on the cartographie du système d’information, and the UK’s Cyber Essentials scopes assets before applying user access control. Four vocabularies share one spine: know what you have, then govern it.

That spine rests on an assumption the authors of the frameworks didn’t think to record, as until recently it was always true: an identity enters through a process that registers it. A human joins, HR creates a record, a manager approves access, and an offboarding routine eventually revokes it. That discipline is imperfect, but it feeds the inventory that every framework assumes.

An AI agent arrives by a different route. It is spun up when a developer wires it into a workflow, or when a business user connects a tool that registers one on their behalf. Depending on the organization’s controls, there may be no requisition, no approving manager, no HR record, no leaver event when the project that needed it ends. From the moment it exists, it holds access and acts on it, and the perimeter model has nothing to grip: its instruments are built for an interactive subject, while an agent authenticates with a token and no human is behind the request.

The mismatch already leads to security incidents. Netwrix’s 2026 Data and Identity Security Report found a 43% breach rate among organizations where AI had significantly expanded the identities needing access, against 11% where it had not.

Monitoring needs a subject that holds still

The obvious objection is that behavioral detection closes this gap, and it deserves a fair hearing, as the capability is real and shipping. Runtime tools watch an agent’s tool calls, data accesses, and API interactions, learn its normal operation, and flag when it drifts; some can enforce access decisions automatically.

What that monitoring rests on is a stable subject and enough time to learn it, and human behavior supplies both. An agent’s actions are non-deterministic by design, so the envelope of normal grows wide enough to absorb the drift a baseline watches for. It keeps no working hours, so a call at three in the morning is an ordinary Tuesday. And one spun up for a single task can finish and disappear in minutes, whereas a baseline may need a full day of observation to converge.

Accounting comes before access

The discipline this calls for already exists, waiting to be applied to a class of uncounted identities. A security team can begin without buying anything.

Start with the rule that access should never precede accounting: no identity, human or otherwise, ought to hold standing permission it was never enrolled to hold, and one that is absent from the inventory should be treated as unauthorized by default rather than tolerated as an untracked exception. 

From there, give non-human identities the same lifecycle every human identity receives. An agent needs an owner who answers for it, a review cadence that revisits what it can reach, and a decommissioning trigger for the day its purpose ends. 

The last principle is a caution about the limits of the first two. Seeing an over-permissioned agent changes nothing about its permissions; the morning after you inventory it, it can reach what it could reach the night before. What inventory changes is the identity’s status. It moves from outside the security program, where no framework control can touch it, to inside, where the machinery an organization already runs can finally be pointed at it.  

Closing the gap from the inside

A decade on, the perimeter story turns out to have described half the problem. The industry taught itself to interrogate the knock at the door until it was reasonably sure who was there. It spent far less effort on the visitors already inside, holding keys nobody remembers issuing, to rooms nobody remembers granting. Zero Trust’s undeclared gap closes by taking a full accounting of who and what is already in the building, and deciding, deliberately, what each of them should be allowed to reach. 

Accounting is the precondition. Visibility does not reduce the risk, but it ends the blindness that kept the risk beyond reach. What an organization does once the agents are finally visible is a harder question, and the subject for another day.

Dirk Schrader
Dirk Schrader

Dirk Schrader is VP of Security Research at Netwrix. A 25-year veteran in IT security with certifications as CISSP (ISC2) and CISM (ISACA), he works to advance cyber resilience as a modern approach to tackling cyber threats. As the VP of Security Research, Dirk is working on focused research for specific industries like healthcare, energy, and finance.

  • Dirk Schrader
    https://informationsecuritybuzz.com/author/dirk-schrader/
    Balancing Identity and Data Security in 2026: Why a Two-Pillar Strategy Matters

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Zero Trust: Beyond the hype, toward reality

June 9, 20267 Mins Read

How to Implement a Zero-Trust Security Framework to Protect Patient Data

December 8, 20257 Mins Read

Securing the New Digital Workspace: Why the Browser Is Now the Core of Enterprise Security

June 18, 20257 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}