Zero trust was a security architecture model. Zero trust is now a marketing term. The original model, articulated by John Kindervag at Forrester in 2010, was a specific approach to security. The model was sound. The marketing co-opted the model. The term now appears on products that have nothing to do with the model, on services that contradict the model, on certifications that certify nothing. The phrase has been hollowed out, and the hollowing has made it harder to talk about actual zero trust architectures, which still matter.
Zero trust, in 2026, is a phrase every security vendor uses. Zero trust is also a phrase that means everything and nothing, in the same way “we use AI” means everything and nothing. The phrase has been used so much, by so many vendors, for so many products, that the original meaning has been lost. The phrase is now a marketing position, not a technical claim. The vendors are not lying. The vendors are using the phrase in a way that is technically defensible and substantively meaningless.
The original idea, however, was real. The original idea is still the right answer to a real problem. The problem is that the right answer has been buried under the marketing.
What zero trust actually is
Zero trust is a security model that assumes no implicit trust, anywhere in the network, based on network location. The model was developed in response to the failure of the perimeter based security model, the model that said “if you are inside the network, you are trusted, and if you are outside, you are not.” The perimeter model worked when the network was the office and the office was behind a firewall. The perimeter model failed when the network became the internet, the office became the home, and the firewall became irrelevant.
The zero trust model says: never trust, always verify. Every request, from every user, from every device, to every resource, is authenticated, authorised, and logged. There is no implicit trust based on network location. There is no “inside the network” that is more trusted than “outside the network.” The trust is in the identity, the device, the context, and the policy. The trust is per request. The trust is dynamic.
The model, when implemented properly, counts as the right answer to the modern security problem. The model is what every serious security architecture should be moving toward. The model is what the marketing has eaten.
The Forrester model in 2010
John Kindervag, then at Forrester, articulated the model in 2010. The model was a response to a specific problem. The perimeter based security model was failing. The breaches of the late 2000s, including the 2009 Heartland Payment Systems breach that exposed 130 million card numbers, were inside jobs and lateral movements that the perimeter model could not stop. The attackers were inside the network. The perimeter was not the answer.
Kindervag’s insight was that the trust should be removed from the network, and added to the identity, the device, and the context. The model was not “no security at the perimeter.” The model was “security at the perimeter is not enough, and the actual security needs to be at the request level.” The model required changes to authentication, to authorisation, to network segmentation, to monitoring, to policy. The model was a complete architecture, not a product.
Why the model was good
The model was good because it matched the threat. The threat of the 2010s, and of the 2020s, is not the external attacker breaking through the perimeter. The threat becomes the credential compromise, the insider, the supply chain attack, the lateral movement. The threat is inside the network. The model is built to defend against the threat.
The model was also good because it was technology agnostic. The model did not require a specific product. The model did not require a specific vendor. The model required an architecture. The architecture could be implemented with products from many vendors. The architecture could be implemented with open source tools. The architecture could be implemented with managed services. The model was a way of thinking about security, not a way of buying it.
The model was, in other words, the kind of thing that does not, in itself, generate vendor revenue. The model is a framework. The framework is, in the vendor world, an opportunity.
The marketing takeover

The marketing takeover happened because the term is a useful marketing position. Every security vendor wanted to be on the zero trust page of the analyst report. Every security vendor wanted to be in the zero trust conversation. Every security vendor wanted the zero trust RFP checkbox. The vendors that had nothing to do with zero trust architecture relabelled their products. The vendors that had products that were a small part of a zero trust architecture relabelled their products. The vendors that had products that contradicted zero trust architecture relabelled their products anyway.
The relabelling was, in most cases, technically defensible. A vendor that sells a VPN can claim zero trust because the VPN can be a part of a zero trust architecture. A vendor that sells a firewall can claim zero trust because the firewall can be a part of a zero trust architecture. A vendor that sells an identity provider can claim zero trust because identity sits as the foundation of zero trust. Every vendor can claim zero trust, because every security product can be a part of a zero trust architecture. The claim is technically defensible. The claim is also not what most buyers think the claim means.
The 2026 “zero trust” product landscape
Walk any security trade show in 2026 and count the zero trust badges. The count will be in the hundreds. Walk any security RFP and count the zero trust questions. The count will be in the dozens. The products and the questions have, in most cases, very little to do with the original architecture. The products and the questions are about the marketing position, not the technical claim.
The 2026 “zero trust” product landscape includes VPNs (which are a perimeter technology, not a zero trust technology). Includes firewalls (which are a perimeter technology, not a zero trust technology). Includes endpoint protection (which is a layer of defence, not a zero trust architecture). Includes SIEMs (which are a monitoring technology, not a zero trust technology). Includes identity providers (which are a necessary component, not the architecture itself). Includes cloud access security brokers (which are a policy enforcement point, not the architecture). Includes microsegmentation tools (which are the closest to the original architecture, but are still a component).
None of these products is zero trust. All of these products can be parts of a zero trust architecture. The gap between “is a part of” and “is” sits as the marketing gap. The gap amounts to the reason the phrase has been hollowed out.
What real zero trust looks like in 2026
Real zero trust in 2026 is an architecture, not a product. The architecture has six components. A strong identity provider, with phishing resistant authentication, conditional access, and risk based re authentication. A device trust framework, with continuous device posture, device attestation, and the ability to deny access from unknown or compromised devices. A policy engine, with the ability to evaluate every request against the user’s identity, the device’s posture, the resource’s sensitivity, the context’s risk. A microsegmentation layer, with the ability to limit lateral movement, to scope access to specific resources, to prevent the compromised credential from accessing the entire network. A comprehensive logging and monitoring layer, with the ability to detect anomalies, to investigate incidents, to provide the audit trail the SEC and the GDPR require. A continuous validation process, with the assumption that any of the above can fail, and the ability to respond.
The architecture is not a product. The architecture is a set of products, from multiple vendors, integrated, configured, monitored, and maintained. The architecture requires the security team to design it, the IT team to implement it, the operations team to maintain it, the board to fund it. The architecture is, in other words, the kind of thing that the 2010 model required and the 2026 marketing has obscured.
The honest assessment
The honest assessment of zero trust in 2026 is that the marketing has eaten the architecture. The phrase is a marketing position. The buyers think they are buying an architecture. The vendors are selling products. The gap sits as the reason the 2026 security stack looks, in many enterprises, exactly like the 2016 security stack, with a few zero trust badges on it.
The honest assessment of the underlying problem is that the original architecture is still the right answer. The threat of credential compromise, of insider threat, of lateral movement, of supply chain attack, has not gone away. The threat has gotten worse. The architecture that defends against the threat is still the architecture Kindervag articulated in 2010, with the additions of AI, of post quantum cryptography, of the device trust frameworks, of the SSE/SASE consolidations. The architecture has evolved. The marketing has not.
The work to do if you actually want zero trust
- Stop asking vendors if they are zero trust. Ask vendors how their product fits into your zero trust architecture. If the answer is “we are zero trust”, the vendor is selling the marketing position. Find a different vendor.
- Map your current architecture against the six components. Identify the gaps. Prioritise the gaps. The biggest gap, in most enterprises, stands as the microsegmentation layer. The second biggest counts as the device trust framework.
- Design the architecture as a set of integrations, not a set of products. The products change. The architecture is durable. The integration amounts to the work.
- Fund the work. The architecture requires the same investment as any other enterprise architecture. The marketing suggests the investment is a product purchase. The architecture suggests the investment is a multi year program.
- Measure the outcomes. The architecture is not a product you can buy and deploy. The architecture is a set of capabilities. The capabilities can be measured. The measures are the proof.
The bottom line
Zero trust was a sound architecture. Zero trust is now a marketing term. The marketing has made it harder to talk about the architecture, which is still the right answer to the modern threat. The companies that have done the architectural work are not getting breached. The companies that have bought the marketing position are still running perimeter architectures with a zero trust badge on the firewall.
The fix is to know the difference. The fix is to ask the right questions. The fix is to fund the work, not the badge. The fix counts as the same one it has always been: the security comes from the architecture, not from the marketing, and the companies that understand this are the companies that will not be in the post incident report.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



