Zero Trust Didn’t Fail — The Industry Failed at Zero Trust
Zero trust hasn’t failed — the industry sold it as a product and stopped at identity. In this Techstrong TV interview, Portnox Field CISO Garrett Gross joins Mike Vizard to push back on the narrative that zero trust is broken and lay out what continuous enforcement actually looks like. Garrett and Mike dig into why a valid identity on a compromised device is still a risk, how the AI agent explosion is multiplying access paths faster than most security teams can govern them, why attackers are getting more patient with stolen credentials, and how complexity creates the exceptions and blind spots that adversaries are counting on. A grounded, practical take on getting back to the fundamentals of identity, device posture, and continuous verification — without slowing the business down.
Transcript
Hey guys, thanks for the throw. We're here with Garrett Gross, who's the Field CISO for Portnox, and we're having a little chat about zero trust. And there's a lot of people talking about it, but maybe not a whole lot of action.
Garrett, welcome to the show. Hey, thanks, Mike. Happy to be here.
We've been talking about zero trust and identity for several years now, and some of us even longer than that. But for all our discussions, it seems like we're not actually getting much done. So from your perspective, what's holding this up?
It seems, on paper at least, a relatively simple idea. Yeah. I think the notion is out there that zero trust is failing, but it's not.
Zero trust principles have been validated for years. I think that the industry has failed us. I think that we've been oversold this promise of zero trust via a product, but then folks stop there, and they don't realize that it's a process.
It's something you have to continuously assess and go back to and do the hard work. So we just see zero trust stopping at identity a lot. Earlier on in the earlier years, we saw it fail starting at identity.
If that's the case, what's to be done about this? " So I would say that the industry failed by turning zero trust into something that organizations thought they could just buy, rather than something that you have to continuously enforce. Because organizations were sold a strategy, but they were never given the operational capabilities needed to execute it.
So, I'd say that zero trust doesn't fail because organizations lack identity. It's because they stop verifying trust after identity. So to your point about that, I also feel like the process is maybe still fundamentally broken, and I say that because the business side seems to decide who needs to access what, and they have a tendency to maybe be over-permissive about that.
And then the security people are supposed to clean that up and maintain that whole workflow, but that's really hard to do as people move around and jobs change. So, can we even do this, or do we need to rethink how identity is first assigned? That's a really great point.
At a core, I try to remind folks that security's responsibility is to keep the business moving. Now, from a secure standpoint, of course, but I think that businesses are going to business. If they're sold a bill of goods, they're going to take it and they're going to run with it, and they're going to stop there.
Because most organizations were sold this concept that identity would solve all these access problems. But then what we started to see is attackers continue to be successful because identity is just one part of that whole equation. A valid identity on a compromised device is still a risk.
A contractor, an unmanaged device, those are still a risk. So, we're now realizing that zero trust requires continuous enforcement, not only based on identity, but device posture, risk score, network contacts, behavioral signals, not more dashboards and reports. So the missing piece is enforcement.
It's the hard work. It's really the thing that we all know it is. It's just I don't think we're honest with ourselves that we have to continuously reassess this process that we thought we got right at the onset.
Do the business folks understand that, and will they support that? Because I think a lot of times when we try to reassess the workflows around identity, they resist because they feel like that's an intrusion. So is there a way to do this that doesn't create as much friction?
Yeah, that's a great question. It's hard to say, "Hey, I know I just bought that security thing a year ago. " And maybe that might've been all you need at the time.
Unfortunately, hindsight is 20/20, and a lot of the proof points that we have are breaches. That doesn't really help organizations pre-breach, but again, that's the story that we see time and time again, under-investment in security or doing the bare minimum until there's a forcing function like a breach, like a compliance violation or some sort of fine that are levied against the organizations. Of course, we're seeing these new animals in the zoo.
They're called AI agents, and I'm not quite sure whether or not they are non-human identities or an extension of our human identities or something entirely new and different. What's your take on this? I embrace AI, both from a user but also from an operator on the security side.
I think AI is very rapidly changing the world, but we have to be careful to not let it overconsume security fundamentals or adherence to that, because AI doesn't change how we do security. Every AI agent, every automation platform, every machine identity, it just creates another access path that we have to govern. So Mike, I'd say the challenge isn't AI itself, it's the explosion of identities and access paths that AI introduces, and we see a parallel in application security.
All the folks that are out there vibe coding software, that's a great thing, but it produces a lot of probably extremely vulnerable pieces of software that are out there that, again, pose a challenge to security just because of the sheer volume that's out there that we have to deal with. I also think that these things don't behave in ways that are easy to anticipate. I think if I have a machine identity or a human identity, I can, with some confidence, have some understanding of what they're trying to access and maybe make a plan accordingly.
But it seems like these AI agents are inclined to do things in ways that we wouldn't anticipate. I couldn't agree with you more, but again, it goes back to the point of zero trust, not being the buzzword, but being the concept of just because I gave you access to this or just because I gave you access a week ago, doesn't mean that you inherently get that just because you're this AI agent machine identity. You have to constantly reassess, should this agent be able to do this?
In the cases of agents going rogue and wiping out production infrastructure, that agent probably shouldn't have been given the capability to do that from the onset. What's your advice to the security people who are caught in the middle of all this, because they can see that there's an issue, but the business wants to drive hard on productivity, and nobody wants to be the person at the party telling everybody to back off the punchbowl. Yes.
The plight of the CISO. It's our job to communicate risk, Mike. The business is going to do what the business is going to do, and I'm not the CEO for a reason.
I'm the security guy. So I think more quantification of what this risk presents is probably going to help. Of course, as we go on, more proof points of what AI is able to do and what AI is not able to do, and just staying aware.
Mike, you've been doing this for a while, just like me. It's cyclical. We see the same lessons being learned with cloud compute, with containerization, with all these different control planes, but the risk remains the same.
You can't have an overly permissive identity set, and then you have to couple that with constantly assessing, does that device pass muster? Does that identity and device pair pass muster? So again, I just think the message is we have to continue to communicate risk, we have to be able to quantify it, and we have to pay attention.
And we also have to not be afraid to say, "Hey, you know what? I got that wrong. " Do you think that there's an opportunity to be proactive here, or are we just waiting for a couple of well-known disasters before everybody wakes up and says, "We need to do something about identity"?
No, I would definitely not sign my name next to that one. Again, if you approach things with this concept of zero trust, and again, not being sold a product of zero trust, but you approach this from always assessing, does this identity match who this person is? Does this identity have the authority to do the things that it's supposed to do?
And can I actually track what this identity is doing? As long as you approach that, you're in the best position you could be. And again, just not accepting this inherent trust that just because this identity was able to do something a week ago doesn't mean it's still able to do that today.
So that's really what we can do from a proactive standpoint is, much like the bouncer at a club door or the front of a club, we have to make sure that we're validating that that person even belongs in there in the first place, rather than some of the other post-access approaches, which is constantly validating activity and containment and things like that. We would like to stop the problem before it even presents itself. " And as I look at it, I just can't help but wonder, is there even a perimeter anymore, and is that just an obsolete concept?
I don't think there's a perimeter anymore. I think the concept of a perimeter works against us in that it gives us a place to stop. Zero trust fails when you approach this from a perimeter standpoint.
Well, actually, when you approach it from any singular piece of the puzzle. So no, I think that a network is just another control plane that we have to identify, we have to quantify risk, and we have to constantly assess for changes. What's your assessment of what's going on with the bad guys out there?
" That's actually the point that I like to drive home with folks is yes, Methos presents an unparalleled threat to cybersecurity, but let's not keep reliving the lessons we've lived over the years. It's always the simple stuff. It's never this highly coordinated, bleeding-edge threat that's being exploited.
Sometimes it is, but most likely, it's a third-party contractor that you didn't verify their access to, or it's you let John do his work on his personal laptop rather than enforcing that it has to be on a corporate-owned machine. So, I don't think that we need to ignore the threat that this AI-led vulnerability exploitation presents, but I also think that it's not a cue for us to focus completely on that, which is unfortunately what I am seeing in the industry is we're really focusing on that. But as a long time nerd and hacker, it's the same thing that we see all the time.
You don't see many stories about wireless access exploits, but guess what? That's still a very viable attack vector. Social engineering is still a very viable attack vector.
And to your point, that's what most criminal organizations are still counting on exploiting, is that you-trust this user to do this one thing a week ago, and things have changed, and now you still trust that user. And so they're able to exploit that. They're waiting for that perfect storm to exist where you let your guard down.
But to land the plane and answer the question that you're asking, I don't think that we're going to see a ton of widespread activity coming from something like Mythos. I think that's going to distract a lot of us in focusing on that, and that's going to probably cause some organizations to leave other areas unintended to. " And then they strike.
So is the nature of the attacks changing? That's a good question. I don't know that I could say that overall the nature of attacks are changing.
I think that attackers are learning that they can be more patient and reap a lot more of the rewards if, like you said, they lay the groundwork and create a network of identities that they've compromised. 10, 20 years ago, I think the proclivity was, as soon as I got that compromised identity, I'm going to go and use it. But now, yeah, attackers are starting to see that they can build this network of compromise and then just use that to really get what they're after.
So at the end of the day, is this really something where we're saying to folks, "We need to just focus on the fundamentals," and there's a lot of things that can be the new bright, shiny objects, but maybe where at the end of the day, the issue is us because we're just not focused on the fundamentals enough? I think that we need to not, again to my earlier point, not get distracted by whatever the new hype threat is. Not completely ignore it.
I'm not saying that at all. But again, to your point, we need to remember that zero trust starts at visibility. It fails when you stop at any singular point.
And much like any master of anything will tell you, it's mastery of the basics. It's not mastery of advanced techniques. It's this always validating, always verifying.
So not making concessions for things. Because, not to get off on a tangent, but I think one of the problems that faces organizations today with what you're talking about is complexity. I think that they bring in something like a new identity assessment tool or a new exploitation framework or something, and they start using that but realize that it's not a fit for the organization.
This was designed for an organization with much greater capabilities or something like that. And so because it's so complex, they start making exceptions, and exceptions become concessions, and then those concessions lead to blind spots. And then that's exactly what attackers are waiting for, is for you to let your guard down because you don't have the capability to enforce something, or you don't have the capability to manage something.
And that's what we're seeing with a lot of organizations that just don't, to your earlier point, they didn't make that giant investment in security, but they're faced with the same problems that organizations much larger than them face. All right. Well, folks, you heard it here.
Identity and zero trust, it's a continuous process. It's not an event. And if you've got more exceptions than rules, you're in trouble.
Hey, Garrett, thanks for being on the show. Awesome. Thanks so much.
All right. Back to you guys in the studio.