The Zero Trust the enterprise has been told to adopt has been sold as the platform the enterprise has to buy, the platform that costs more than the security budget can afford, the platform the CISO has been quietly writing off as the unreachable goal. The honest framing matters here, because the Zero Trust the vendor has been promising sits as the Zero Trust the cloud platform the enterprise has been paying for has been building in by default for the last three years.
What follows runs as the working version of the field guide. The shorter version is what the CISO and the security team actually have time to read.
What the cheap Zero Trust does
Three things, in roughly that order of how much each one matters. The first runs as the identity verification, where the verification the cloud platform provides, the MFA the enterprise has been turning on by default, the conditional access the Microsoft Entra, the Okta, the Google Workspace all now offer, the verification that costs the per seat license the enterprise is already paying. The second runs as the device posture, where the posture the cloud platform checks, the posture the device management (the Intune, the Jamf, the Workspace ONE) can enforce, the posture the security team can require before the device gets the access, the posture the cloud platform provides without the additional appliance. The third runs as the application segmentation, where the segmentation the application proxy provides, the proxy that fronts the legacy application, the proxy that does not require the network access the VPN granted, the proxy the Zscaler, the Cloudflare, the Netskope all offer, the segmentation the security team can ship without the network rebuild.
What it skips
Three things, in roughly that order of how much each one matters. The first runs as the network segmentation, where the segmentation the full Zero Trust requires, the segmentation that segments the application at the network layer, the segmentation the cheap Zero Trust does not provide, the segmentation the enterprise has to build with the firewall, the VLAN, the routing the network team has been maintaining. The second runs as the identity for the service account, where the account the legacy service has been using, the service account the identity provider cannot MFA, the service account the enterprise has been treating as the special case the Zero Trust does not cover, the account the enterprise has to manage separately. The third runs as the data layer, where the layer the full Zero Trust segments, the data access the Zero Trust controls based on the user, the device, the context, the data layer the cheap Zero Trust does not see, the data layer the enterprise has to add the DLP, the data classification, the tagging the security team has been building separately.
How to land it on the budget you have
Three moves if you are the CISO that has been asked to deliver Zero Trust without the budget the vendor has been quoting. Use the cloud platform first, where the platform the enterprise has been paying for (the Microsoft 365 E5, the Google Workspace Enterprise Plus, the AWS Control Tower), the platform that has the MFA, the conditional access, the device posture, the platform the CISO can deliver the Zero Trust foundation on without the additional spend. Phased the migration, where the migration the CISO can phase (the high value application first, the legacy application last, the sequence the CISO can sell to the board), the phasing the CISO can deliver on the budget the CISO has, the phasing the CISO can show progress on without the big bang the vendor has been promising. Be honest about the gap, where the gap the CISO should be reporting to the board, the gap between the Zero Trust the CISO has delivered and the Zero Trust the full framework requires, the gap the CISO should be asking the board to fund, the gap the CISO cannot close without the additional budget. The CISO that uses the platform, phases the migration, and is honest about the gap serves as the CISO that has delivered the Zero Trust on the budget the CISO actually has.

The bottom line
Zero Trust in 2026 sits as the goal the vendor has been selling as the goal the CISO has to fund. The identity, the device posture, the application segmentation, those three are what the cheap version delivers. The network segmentation, the service account, the data layer, those three are what the cheap version skips. The cloud platform, the phased migration, the honest gap reporting, those three are the moves. The CISO that does the three delivers the Zero Trust on the budget. The CISO that waits for the full budget does not.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


