Tag: CISOInsights

  • Generative AI in Cybersecurity: IBM’s 2026 Threat Reality

    Generative AI in Cybersecurity: IBM’s 2026 Threat Reality

    Generative AI in Cybersecurity 2026: The Weapon Defending and Attacking You at the Same Time
    NeuralWired  |  AI & Technology Intelligence for Security Leaders
    Cybersecurity Intelligence  /  Deep Analysis

    Generative AI in Cybersecurity: The Weapon Defending and Attacking You at the Same Time

    Generative AI has fractured cybersecurity into two simultaneous realities. It is the most powerful defensive tool deployed at enterprise scale, and the cheapest offensive weapon ever handed to criminals. Here is the honest picture, with numbers.

    By NeuralWired Research Desk  •  Published: May 31, 2026  •  Last Updated: May 31, 2026  •  14 min read

    $12.87B GenAI Cybersecurity Market 2025
    5 min To craft an AI phishing email (was 16 hrs)
    80 days Shorter breach lifecycle with AI defense
    94% Of security leaders say AI is #1 change driver

    The Core Paradox of 2026

    A financial services firm in Frankfurt tightened its breach lifecycle by 80 days last year. Its AI-powered security operations center caught a credential-stuffing campaign at 2 a.m. with no human analyst in the loop. The same quarter, one of its treasury executives received a video call from what appeared to be the CFO, instructing a wire transfer. The voice was real. The face was real. Neither was human.

    This is the defining tension of generative AI in cybersecurity right now. The same technology compressing your incident response timeline is compressing an attacker’s phishing production pipeline. The World Economic Forum Global Cybersecurity Outlook 2026, drawing on 804 respondents across 92 countries including 316 CISOs, found that 94% of security leaders identify AI as the most significant driver of change in their field. The same report found that 87% flagged AI vulnerabilities as the fastest-growing cyber risk throughout 2025.

    Both numbers refer to the same technology. That is not a contradiction. That is the story.

    Our Read
    This signals something the vendor community is reluctant to say plainly: investing in AI for defense does not reduce your exposure to AI as an attack vector. It changes the nature of the fight. Organizations that grasp this distinction will build genuinely resilient security postures. Those chasing “AI-powered security” as a procurement category will be left exposed in ways their tools cannot detect.


    How Generative AI Is Used in Cybersecurity

    Generative AI in cybersecurity refers to the application of large language models and generative systems to automate threat detection, accelerate incident response, generate synthetic attack scenarios for red teaming, analyze vulnerabilities, and craft adaptive security policies. It powers security operations centers (SOCs) by triaging alerts, reducing analyst workload, and identifying anomalous behavior in real time. (Sources: IBM, Fortinet, WEF GCO 2026)

    On Defense: What the Numbers Actually Show

    The IBM Cost of a Data Breach Report 2025, now in its 20th year and covering 600 organizations across 17 industries and 16 countries, produced the most credible measurement of AI’s defensive ROI to date. Organizations using AI extensively in their security operations cut their breach lifecycle by 80 days and saved nearly $1.9 million on average per breach, compared to organizations that did not.

    The global average breach cost fell 9% to $4.44 million in 2025, the first decline in five years. That is the headline. The subtext is more important: the U.S. average breach cost rose to a record $10.22 million, up from $9.36 million in 2024. The organizations pulling the average down are those investing in AI-augmented detection and response. The ones pulling it up are those that are not.

    Specific Use Cases That Are Working Now

    Across platforms from IBM Security QRadar to CrowdStrike and Palo Alto Networks (named by MarketsandMarkets as the dominant players in this market), the applications generating real operational value in 2026 include the following.

    Use Case What It Does Maturity Level
    AI-assisted alert triage Filters noise, prioritizes high-fidelity incidents, reduces analyst fatigue Production-ready now
    GenAI phishing detection Identifies AI-crafted emails via behavioral and linguistic pattern analysis Production-ready now
    Synthetic red teaming Generates adversarial attack scenarios at scale for penetration testing Production-ready now
    Vulnerability auto-remediation Identifies and patches insecure code in development pipelines Scaling fast (Gartner: 40% of dev teams by end of 2026)
    Autonomous SOC response Full end-to-end incident containment without human input Aspirational. 3 to 5 years from reliable deployment.
    Gartner projects that by the end of 2026, 40% of development teams will routinely use AI-based auto-remediation for insecure code. That figure was under 5% in 2023. The acceleration is real. So is the risk it carries.


    AI Cybersecurity Threats 2026: How Attackers Are Using It

    One statistic from IBM’s 2025 breach report has become the most visceral data point in enterprise security conversations this year. Generative AI has reduced the time required to craft a convincing phishing email from 16 hours to 5 minutes. That is not an incremental efficiency gain. It is a structural change to the economics of social engineering at scale.

    According to IBM’s findings, 1 in 6 breaches in 2025 involved attackers using AI. Phishing was the primary method at 37% of AI-assisted attacks, followed by deepfake impersonation at 35%. These are the first statistics of their kind at scale, and they represent a floor, not a ceiling.

    “Defenders will likely see threat actors use agentic AI in an automated fashion as part of intrusion activities, continue AI-driven phishing campaigns, and continued development of advanced AI-enabled malware. They’ll use agentic AI to implement hacking agents that support their campaigns through autonomous work.”

    Alex Cox, TIME Director and AI Working Group Lead, LastPass (TechNewsWorld, January 2026)

    The Speed Problem Is Now Structural

    FortiGuard Labs’ 2025 cyberthreat data shows that newly discovered vulnerabilities are now being weaponized in an average of 4.76 days, a 43% increase in speed compared to prior periods. The window between a CVE being published and an attacker having a working exploit is now smaller than most organizations’ patch cycles by a significant margin.

    This is where generative AI’s role in offense is most concrete and most dangerous. It is not creating fundamentally new classes of malware (the Picus 2025 Red Report found no notable uptick in AI-driven malware innovation in 2024). It is compressing the timeline of every phase of an attack, from reconnaissance to exploitation to lateral movement.

    Critical Risk Flag
    Deepfake executive impersonation is now technically feasible at enterprise scale according to Palo Alto Networks’ 2026 cybersecurity predictions. Real-time AI video and voice replicas of your C-suite require organizations to retire any multi-factor authentication method tied to voice or video verification immediately. This is not a 2027 concern.


    Shadow AI: The $670,000 Threat Nobody Is Governing

    Shadow AI refers to the unauthorized use of AI tools such as ChatGPT, Claude, or Gemini by employees without IT approval or oversight. It creates security risk because sensitive data may be uploaded to external platforms without data loss prevention controls in place. IBM’s 2025 breach data found that shadow AI adds an average of $670,000 to breach costs per incident, placing it among the top three costliest breach factors, displacing skills shortages from that position for the first time.

    13% of organizations in IBM’s study experienced AI-specific breaches. Of those, 97% lacked basic security controls for their AI systems at the time of breach. Role-based access governance, data classification, and output monitoring were absent in nearly every case.

    Shadow AI is no longer an HR policy issue. It is a board-level financial governance issue. If that framing hasn’t reached your leadership team yet, the IBM numbers are the vehicle.

    You can read more about AI system integrity risks and the specific failure modes of autonomous AI systems in NeuralWired’s analysis of AI agent document corruption, which details exactly how unsanctioned agentic systems corrupt enterprise data flows in ways that are difficult to detect and expensive to remediate.

    What the WEF Data Shows
    64% of organizations are now assessing the security of AI tools before deployment, up from 37% in 2025 according to the WEF Global Cybersecurity Outlook 2026. Governance is accelerating. But 36% of organizations are still deploying AI tools with no formal security assessment. In a market where shadow AI already costs an average of $670,000 per breach, that gap represents enormous, quantifiable financial risk.


    Agentic AI and the Next Escalation

    Agentic AI in cybersecurity refers to AI systems that autonomously execute multi-step tasks including scanning for vulnerabilities, crafting exploits, or orchestrating attack campaigns without constant human direction. In 2026, both defenders and attackers are integrating agentic AI: defenders for autonomous SOC response and threat hunters, threat actors for fully automated intrusion operations. (Sources: OWASP, WEF 2026, Darktrace)

    Darktrace’s State of AI Cybersecurity 2026 report, drawing on more than 1,500 security leaders, captures the shift in a single sentence: 2025 was the year enterprise AI went mainstream; 2026 is when it became a full-scale attack surface.

    The deployment of Anthropic’s Project Glasswing, a restricted frontier model with autonomous zero-day research capability deployed with a small set of trusted infrastructure organizations before any public release, represents a strategic threshold. AI can now autonomously discover zero-day vulnerabilities. The question for every CTO in critical infrastructure is: when adversaries gain access to comparable models, what is your baseline threat assumption?

    A concrete illustration of the speed at which AI-powered vulnerability discovery operates: as detailed in NeuralWired’s coverage of CVE-2026-31431, AI found a 9-year-old Linux kernel vulnerability in under one hour. Nine years of human security review missed it. That is not a niche benchmark. That is a preview of what autonomous AI exploit research means at scale for every organization running Linux infrastructure.

    “I expect the sophistication and intensity of cyber threats will continue to increase, as they have year over year. The ever-expanding tech landscape and rise of Adversarial AI means cybersecurity is not just about protecting business value anymore. It’s now a fundamental driver.”

    Adnan Amjad, US Cyber Leader and Partner, Deloitte & Touche LLP

    The Case Against the Hype

    If you’ve sat through a vendor briefing in the past 12 months, you’ve heard the “AI versus AI cyberwar” framing. It is compelling. It also contains a significant amount of motivated reasoning.

    Cybercriminals Are Not Adopting AI as Fast as the Headlines Suggest

    Sophos X-Ops research published in January 2025, based on direct investigation of multiple underground criminal forums, found that criminals are still largely skeptical of generative AI. Most criminal AI use is limited to bulk email generation and data analysis. Novel attack classes powered by AI remain rare. The Picus 2025 Red Report, cited by Ivanti, found no notable uptick in AI-driven malware techniques in 2024, stating directly that “AI enhances productivity but doesn’t yet redefine malware.”

    The practical implication: vendors are financially incentivized to overstate offensive AI capability to justify defensive AI spending. At least half of the AI-versus-AI cyberwar narrative in circulation right now is marketing material dressed as threat intelligence.

    AI Security Tools Create Blind Spots the Industry Isn’t Discussing

    VikingCloud’s October 2025 analysis details a specific and underreported risk. Adversarial machine learning can be used to attack AI security tools themselves through crafted inputs designed to deceive AI classifiers, allowing malware to pass through undetected. Data poisoning attacks can corrupt the training datasets those AI tools depend on, creating systemic blind spots that are invisible to the defenders relying on the system.

    AI hallucinations in security contexts add another dimension. Based on Artificial Analysis’s AA-Omniscience benchmark covering 40 AI models, all but four were more likely to provide a confident, incorrect answer than a correct one on difficult questions. In a SIEM or incident response workflow, a confidently wrong AI verdict doesn’t just delay response. It actively misdirects it. The Hacker News covered this emerging risk in May 2026, noting it is almost entirely absent from vendor marketing materials.

    “As with many other things in life, the mantra should be ‘trust but verify’ regarding generative AI tools. We have not actually taught the machines to think; we have simply provided them the context to speed up the processing of large quantities of data. The potential of these tools to accelerate security workloads is amazing, but it still requires the context and comprehension of their human overseers for this benefit to be realized.”

    Chester Wisniewski, Director and Global Field CTO, Sophos

    Nearly Half of AI-Generated Code Is Already Shipping Vulnerabilities

    This may be the most underappreciated structural risk in enterprise security today. According to Krishna Vishnubhotla, VP of Product Strategy at Zimperium, writing in TechInformed in December 2025: “Nearly half of AI-generated code contains security flaws. We will see more vulnerabilities pushed into production, not fewer.”

    If your engineering teams are using GitHub Copilot, Cursor, or any AI coding assistant at scale (and they are), the velocity gains from those tools may be offset or exceeded by downstream remediation costs from the vulnerabilities they ship. This is detailed further in NeuralWired’s analysis of why AI agents fail in production, which covers the specific failure modes that create enterprise security exposure.

    “Many people have a huge incentive to keep building the infrastructure, but the vibe has changed. Loans will get more expensive, stock prices are coming down, and profits (except for Nvidia) are few and far between.”

    Gary Marcus, NYU Professor Emeritus and AI Critic, co-founder of Robust.AI (Dark Reading, December 2025)
    Marcus is making a broader economic argument: the AI cybersecurity vendor landscape is being propped up by a capital environment that may not persist. Arkose Labs’ 2025 AI Maturity in Cybersecurity Report found that only about half of enterprises had realized measurable benefits from AI security investments despite widespread adoption. The governance gap widens faster than deployment in too many organizations.


    What Security Engineers Must Do Now

    The attack surface now includes the AI stack itself. Every LLM, API integration, plug-in connection, and training pipeline your organization runs is a software layer that must be audited, tested, and governed like any other. If you’re building or maintaining security infrastructure, here is what requires action before the next quarter closes.

    Priority Action: Shadow AI Audit
    Conduct a full inventory of every AI tool accessing company data across all departments. Engineering, HR, finance, and legal are the highest-risk vectors. Do not assume IT-approved tools are the only ones in use. They are not, and IBM’s 2025 data puts the average cost of getting this wrong at $670,000 per breach.

    Beyond shadow AI, there are four actions that move the needle on genuine risk reduction right now.

    First, evaluate AI-native EDR and SIEM tools with behavioral analysis rather than rule-based detection. Pattern-matching rules built for human-speed attacks are structurally insufficient for AI-generated phishing arriving at machine speed. Behavioral analytics and AI-versus-AI detection architectures are the operative requirement, not a future consideration.

    Second, implement the OWASP LLM Top 10 framework for every internal AI tool and every customer-facing AI product. The OWASP GenAI Security Project is the de facto technical standard for GenAI application security risks and is referenced by enterprise security teams globally. If your AI products are not being assessed against this framework, they are not being adequately assessed.

    Third, treat all AI-generated code as high-risk code. Enforce static analysis and adversarial testing pipelines before any AI-generated code reaches production. The Zimperium data on nearly half of AI-generated code containing security flaws is not a prediction. It is a current operational reality for every engineering team using a code copilot.

    Fourth, establish role-based access governance for every AI component in your security stack. IBM’s 2025 data shows 97% of AI-specific breaches lacked basic access controls. This is the single most actionable gap with the clearest remediation path.


    What CTOs Must Understand Now

    The generative AI cybersecurity market sits between $8.65 billion and $12.87 billion in 2025, depending on the methodology used, according to MarketsandMarkets and ResearchAndMarkets respectively. The broader AI in cybersecurity market, which includes all AI categories, reached $34.09 billion in 2025 according to Fortune Business Insights, with North America holding 34.90% of that market. Growth rates across credible forecasters are consistently pegged between 22% and 29% annually through 2031.

    The vendor landscape is consolidating fast. CrowdStrike, Palo Alto Networks, and Fortinet hold the largest product footprints. Decision windows for multi-year platform contracts are narrowing as consolidation removes competitive alternatives. If you are still in evaluation mode on your AI security platform strategy, that window is not staying open.

    The Post-Quantum Threat Has a Shorter Timeline Than You Were Told

    The “harvest now, decrypt later” threat model, where adversaries collect encrypted data today to decrypt when quantum computing matures, is operating on a compressed timeline. AI-accelerated cryptanalysis research is advancing faster than public quantum computing milestones suggest. NIST finalized its first post-quantum cryptography standards in 2024. Organizations have limited runway for cryptographic inventory and migration planning. Begin that inventory now.

    Timeline Realism for AI Security Claims

    The autonomous SOC is 3 to 5 years from reliable deployment at scale. AI-generated malware redefining attack classes is not in evidence yet. Post-quantum cryptography urgency is a realistic and genuine concern. Calibrate your board communications and investment timelines accordingly.

    The G7 Cyber Expert Group issued a formal joint statement in 2025 acknowledging that GenAI, agentic AI, and advanced AI systems present emerging and evolving cybersecurity risks requiring proactive cross-jurisdictional response. That regulatory signal, combined with the EU AI Act’s risk classification requirements now forcing formal security assessments of AI systems in regulated industries, means the compliance architecture around AI security is hardening fast. Organizations that treat AI governance as optional are building technical debt with regulatory interest attached.

    How We Got Here: The Four-Year Arc

    • Pre-2022 AI in cybersecurity meant machine learning for anomaly detection. Pattern matching, SIEM correlation, endpoint behavior analysis. Useful. Narrow. Human-speed attacks, human-speed defense.
    • 2022 to 2023 ChatGPT launches. Natural language AI reaches non-technical threat actors overnight. Phishing, social engineering, and script generation become democratized. The attack surface calculus changes permanently.
    • 2024 First major wave of GenAI-native security products hit enterprise procurement. CrowdStrike, Palo Alto Networks, and Microsoft release AI copilots. OWASP LLM Top 10 is formalized. NIST finalizes first post-quantum cryptography standards. Gartner places AI-powered security operations at the Peak of Inflated Expectations.
    • 2025 IBM documents AI as both defensive asset and attack vector at scale for the first time. Shadow AI becomes a top-3 breach cost factor. G7 issues formal AI cybersecurity statement. Exploit weaponization drops to 4.76 days average.
    • 2026 Agentic AI creates autonomous attack campaigns. Project Glasswing marks the first institutional AI capable of autonomous zero-day research. EU AI Act forces formal security assessments. Cyber-enabled fraud overtakes ransomware as the top CEO concern.

    Key Takeaways

    • Organizations using AI extensively in security operations cut breach lifecycles by 80 days and save an average of $1.9 million per breach (IBM 2025).
    • 1 in 6 breaches in 2025 involved attackers using AI. Phishing leads at 37%, deepfake impersonation at 35%.
    • Shadow AI adds $670,000 to average breach costs. 97% of AI-specific breaches lacked basic access controls.
    • Exploits are being weaponized in 4.76 days on average, a 43% increase in speed. AI-speed defense is not optional.
    • Nearly half of AI-generated code contains security flaws (Zimperium). Engineering velocity gains may be offset by downstream remediation costs.
    • The autonomous SOC is 3 to 5 years from reliable deployment. Human oversight is the operative model in 2026.
    • Post-quantum cryptography migration timelines are being compressed by AI-accelerated cryptanalysis. Begin inventory now.

    FAQ: Generative AI in Cybersecurity

    How is generative AI used in cybersecurity?

    Generative AI is used in cybersecurity to automate threat detection, accelerate incident response, generate synthetic attack scenarios for red teaming, analyze vulnerabilities, and craft adaptive security policies. It also powers security operations centers (SOCs) by triaging alerts, reducing analyst workload, and identifying anomalous behavior in real time. (Sources: IBM, Fortinet, WEF GCO 2026)

    What are the cybersecurity risks of generative AI?

    Generative AI introduces several cybersecurity risks: it enables attackers to generate convincing phishing emails in minutes rather than hours, create deepfake impersonations, and automate malware. For defenders, risks include shadow AI data exposure, AI model poisoning, adversarial inputs bypassing detection, AI hallucinations causing false security verdicts, and governance gaps in unsanctioned AI tool use. (Sources: IBM 2025, WEF 2026, Sophos)

    Can generative AI replace human cybersecurity analysts?

    No. Generative AI augments but does not replace human cybersecurity analysts in 2026. While AI effectively handles Tier 1 alert triage and enrichment, complex incident response, threat hunting, and strategic decisions still require human judgment. IBM’s 2025 data shows AI-human collaboration reduces breach lifecycles by 80 days. Autonomous SOC response at scale remains 3 to 5 years from reliable deployment.

    How are hackers using generative AI to attack organizations?

    Hackers use generative AI primarily to craft convincing phishing emails at scale, a process that once took 16 hours and now takes 5 minutes. They also use AI for deepfake voice and video impersonations of executives, to debug and customize malware, and to automate victim profiling for more targeted social engineering campaigns. (Sources: IBM 2025, Sophos X-Ops)

    What is shadow AI in cybersecurity?

    Shadow AI refers to the unauthorized use of AI tools such as ChatGPT, Claude, or Gemini by employees without IT approval or oversight. It creates security risk because sensitive data may be uploaded to external platforms without data loss prevention controls. IBM’s 2025 report found shadow AI adds an average of $670,000 to breach costs, making it a top-three costliest breach factor.

    What is the market size of generative AI in cybersecurity?

    The generative AI cybersecurity market was valued at approximately $8.65 billion to $12.87 billion in 2025 depending on methodology, with projections ranging from $35 billion to $45 billion by 2030 to 2031. The broader AI in cybersecurity market reached $34.09 billion in 2025. Growth rates are consistently estimated between 22% and 29% CAGR. (Sources: MarketsandMarkets, ResearchAndMarkets, Fortune Business Insights)

    What is agentic AI in cybersecurity?

    Agentic AI in cybersecurity refers to AI systems that autonomously execute multi-step tasks such as scanning for vulnerabilities, crafting exploits, or orchestrating attack campaigns without constant human direction. In 2026, both defenders and attackers are integrating agentic AI: defenders for autonomous SOC response, and threat actors for fully automated intrusion operations. (Sources: OWASP, WEF 2026, Darktrace)


    Where This Leads in the Next 12 to 18 Months

    What you now understand that most of your peers do not yet: generative AI in cybersecurity is not a product category to buy your way into. It is a structural shift in the economics and speed of both attack and defense simultaneously. The organizations winning this transition are not the ones deploying the most AI tools. They are the ones governing the AI they already have.

    Three things to watch in the next 12 to 18 months. First, agentic AI moving from experimental deployment to production-scale SOC integration at the largest financial and critical infrastructure organizations. When it works, it will compress defender response times dramatically. When it fails under novel adversarial conditions (which adversarial ML is specifically engineered to trigger), organizations that have reduced their human analyst capacity will face an unguarded gap. Second, the post-quantum migration timeline shortening faster than the public discourse reflects, driven by AI-accelerated cryptanalysis. Third, regulatory requirements under the EU AI Act and successor G7 frameworks creating mandatory security assessment requirements for AI systems in regulated industries, transforming what is currently a governance best practice into a legal obligation.

    The mantra for 2026 is the one Chester Wisniewski offered at the start of the year: trust but verify. Not just for your AI tools. For the threat intelligence you’re using to justify buying them.

    Get weekly intelligence on AI and cybersecurity delivered to your inbox. No noise. No vendor marketing. Just the analysis that matters.

    Subscribe to The Neural Loop

  • What Is Zero Trust Security? The NIST Guide (2026)

    What Is Zero Trust Security? The NIST Guide (2026)

    Zero Trust Security: Why “Never Trust, Always Verify” Is Winning the Cybersecurity War
    Cybersecurity

    Zero Trust Security: Why “Never Trust, Always Verify” Is Winning the Cybersecurity War

    $40B+ Global ZT market size in 2025
    30% Organizations that have actually implemented ZT
    $1.76M Average breach cost saved with mature ZT (IBM 2024)
    In 2020, hackers slipped into SolarWinds’ build pipeline and pushed poisoned software updates to 18,000 organizations, including the U.S. Treasury, Homeland Security, and the Pentagon. They moved through networks undetected for months. The perimeter had held. The castle walls were intact. The attackers were already inside, trusted by every system they touched.

    That’s the problem zero trust security was designed to solve. And after two decades of being dismissed as too complex, too expensive, or too theoretical, it has become the dominant cybersecurity framework for enterprises, governments, and anyone who can’t afford to assume the person inside the network is actually who they say they are.

    The zero trust security market hit $40.01 billion in 2025. It’s projected to reach $182.59 billion by 2035. Every major federal agency in the United States is under a legal mandate to adopt it. Yet only 30% of organizations have actually done it. That gap, between the promise and the practice, is the real story.


    What Zero Trust Security Actually Means

    Zero trust is not a product. It’s not software you buy. It’s a philosophy, and that distinction matters enormously, because hundreds of vendors are selling “zero trust solutions” while the framework’s own creator is calling them out on it.

    “Zero Trust is first and foremost a strategy. It’s something that you do, not something you buy.” — John Kindervag, Chief Evangelist, Illumio; Creator of the Zero Trust model; speaking at RSAC 2025. Source
    Kindervag created zero trust around 2009–2010 while a VP and Principal Analyst at Forrester Research. His foundational paper proposed a framework in which companies abandon the assumption that any device or user, inside or outside the corporate network, can be trusted by default. The phrase he coined: never trust, always verify.

    The authoritative technical definition comes from NIST (Special Publication 800-207, published August 2020): zero trust “provides a collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions in information systems and services in the face of a network viewed as compromised.”

    In plain English: assume the network is already breached. Verify every user, every device, every access request, every time. Grant only the minimum access required for that specific task. And continuously monitor, because a device that was clean at 9 a.m. might be compromised by 11 a.m.

    The Core Shift
    Traditional security asks: Are you inside the network? If yes, you’re trusted. Zero trust asks: Who are you, what device are you on, what do you need, and does this request make sense right now?, every single time.


    How It Works: The Five Pillars

    CISA’s Zero Trust Maturity Model organizes the architecture across five pillars. If you’re building or assessing a zero trust program, this is your map.

    Pillar What It Covers Why It Matters
    Identity Multi-factor authentication, privileged access, identity governance The highest-ROI starting point. Most breaches begin with compromised credentials.
    Devices Endpoint detection, device health validation, mobile device management A user with valid credentials on a compromised device is still a threat.
    Networks Micro-segmentation, encrypted traffic inspection, DNS security Limits lateral movement — what attackers do after they’re in.
    Applications & Workloads App-layer access control, secure APIs, cloud workload protection The average enterprise uses 130 SaaS apps. Each is a potential attack vector.
    Data Data classification, DLP, encryption at rest and in transit Ultimately, data is what attackers want. This pillar protects the final target.
    Each pillar progresses through maturity stages, Traditional, Initial, Advanced, and Optimal. Cross-cutting capabilities including visibility, analytics, automation, and orchestration apply across all five. The point isn’t to buy a tool for each pillar. It’s to map your existing security investments to this framework and identify what’s genuinely missing.

    The VPN vs. ZTNA Distinction

    The most misunderstood comparison in enterprise security: a VPN and Zero Trust Network Access (ZTNA) are not the same thing. A VPN grants broad network access once a user authenticates, you’re in, and you can reach most of what’s on the network. ZTNA grants access only to specific resources, verified continuously for every session. It’s the difference between handing someone a master key and escorting them directly to the one room they need. Gartner predicted that by 2025, 60% of companies would replace VPNs with ZTNA solutions, and that transition is still very much underway.


    Why Zero Trust Is Winning Now

    Three forces converged to make zero trust urgent rather than optional.

    The Perimeter Collapsed

    The traditional “castle and moat” security model assumed that everything inside the corporate network could be trusted. That assumption died slowly, then all at once. SolarWinds (2020), Colonial Pipeline (2021), and the MOVEit breach (2023) each involved extensive lateral movement that perimeter defenses couldn’t detect. The attackers weren’t breaking through the walls, they were walking through the gate with stolen credentials.

    Remote Work Killed the Network Edge

    When 2020 sent millions of employees home overnight, it didn’t just complicate security, it obliterated the physical boundary the perimeter model depended on. Workers logging in from home networks, personal devices, coffee shops, and foreign countries made the “inside vs. outside” distinction meaningless. Zero trust, which had been growing steadily, became unavoidable.

    The U.S. Government Made It Mandatory

    In May 2021, President Biden’s Executive Order 14028 formally required federal civilian agencies to develop plans for Zero Trust Architecture. The OMB memorandum M-22-09 (January 2022) went further, requiring all federal agencies to meet specific ZT objectives by the end of FY 2024. When the U.S. government mandates a cybersecurity framework across every civilian agency, the private sector follows, not because it has to, but because the vendor ecosystem, talent pool, and enterprise procurement processes all orient toward it.

    A CISA progress report published January 2025 assessed federal agency implementation through FY 2024. It was candid about failures and outlined next steps, which is itself a signal that the mandate has teeth, even if delivery is uneven.


    The Implementation Gap: 72% Planning, 30% Doing

    Here’s the single most important number in zero trust right now: according to Forrester, 72% of security decision-makers at large organizations plan to pursue zero trust or are already doing so. According to CyberRisk Alliance’s 2024 survey, only 30% of organizations have actually implemented zero trust practices.

    That’s a 42-point execution gap. And it has a name: the implementation problem.

    “Anything that helps me get visibility and reduces risk is a win, but Zero Trust has to start with a mindset and a strategy aligned to business outcomes.” — Jared Nussbaum, CISO, Ares Management; speaking at RSAC 2025. Source
    What’s stopping organizations? The data from a StrongDM survey of 600 U.S.-based cybersecurity workers is blunt: 48% cite cost and resource constraints as their primary barrier. Another 22% report internal resistance. The obstacles aren’t technical, they’re organizational and financial.

    Gartner’s estimate cuts even deeper: by the end of 2026, only 10% of large enterprises will have a mature and measurable zero trust program, up from less than 1% in 2023. Even among organizations that have started, most are mid-journey. Approximately 52% of organizations have completed full ZTNA deployment; 38% remain in partial implementation phases.

    The ROI Case CISOs Should Be Making to Their Boards
    The IBM Cost of a Data Breach Report 2024 found that the average breach costs $4.88 million, a record high, up 10% from 2023. Organizations with mature zero trust deployments save an average of $1.76 million per breach compared to those without. A mid-market zero trust program can pay for itself from a single avoided breach.

    For CISOs navigating this, the practical guidance is consistent: don’t buy new platforms before mapping existing investments. If you have MFA, EDR, and IAM tools already deployed, map them to the five pillars first. Identity is almost always where the highest-ROI work begins, because it’s where most breaches start.


    The Hard Truth: What Zero Trust Can’t Do

    No serious coverage of zero trust is complete without this part. Three categories of criticism deserve attention from anyone making real decisions about it.

    The Vendor Exploitation Problem

    The 2023 Okta breach is the cautionary tale. A threat actor accessed a stolen credential from the identity and access management firm, a company whose entire value proposition is verifying identity, and used it to access customer systems across Okta’s client base. As Jason Steer, CISO of Recorded Future, noted in the aftermath:

    “A lot of organizations are now all in on companies like Okta, who offer zero trust, and that means threat actors understand that as well.” — Jason Steer, CISO, Recorded Future. Infosecurity Magazine, March 2026
    Steer’s point is precise: zero trust can consolidate organizational risk into single-vendor dependencies. The identity pillar, when it relies on one provider, becomes a single point of failure with a much larger blast radius than the perimeter it replaced.

    Kindervag himself has addressed the product misconception directly: “Any business or vendor that claims to have a zero trust product is either lying or doesn’t understand the concept at all.”

    MFA Is Not Impenetrable

    Identity is zero trust’s highest-ROI pillar and its most exploited weakness simultaneously. Attackers have developed reliable techniques to circumvent MFA: man-in-the-middle attacks that intercept one-time codes, SIM swapping to take over a user’s phone number, and push notification fatigue attacks that bombard users with authentication requests until they approve one out of frustration. Zero trust doesn’t prevent these. It raises the cost of exploitation, it doesn’t eliminate it.

    The Academic Challenge: Is True Zero Trust Even Achievable?

    This one is uncomfortable, and it mostly hasn’t penetrated vendor marketing materials or government mandates. Professor Virgil D. Gligor of Carnegie Mellon University, a 2019 inductee into the National Cyber Security Hall of Fame and recipient of NIST’s National Information Systems Security Award, published a formal technical challenge to zero trust’s theoretical foundations.

    His argument: enterprise networks rely on “black box” devices whose security properties cannot be proven unconditionally. Because of this, the name “zero trust” is technically incoherent. What practitioners are building is trust minimization, which is valuable, but different. As Gligor concluded in his CMU CyLab Technical Report (22-002): “Zero trust is impossible in any enterprise network and has meaning only as an unreachable limit of trust establishment.”

    What This Means Practically
    Gligor’s argument isn’t that zero trust programs are worthless, it’s that teams which believe they have achieved complete trust elimination may operate with false confidence that itself becomes a vulnerability. The goal should be trust minimization, not trust elimination. If your security culture assumes zero trust means zero risk, that’s the threat.

    The Friction-Shadow IT Paradox

    Ironically, aggressive zero trust implementation can recreate the exact vulnerabilities it’s designed to prevent. When continuous verification creates too much friction, too many authentication prompts, too many blocked workflows, users find workarounds. Shadow IT proliferates. Unmonitored channels open. Organizations attempting comprehensive overnight transitions typically face implementation failures and user resistance that undermine the program entirely. Incremental deployment by pillar, starting with identity, consistently outperforms big-bang rollouts.


    What’s Changing in 2025–2026

    Two developments define the frontier of zero trust right now.

    AI Integration

    The integration of AI and machine learning within zero trust architectures is producing real capability improvements, particularly in behavioral analytics and anomaly detection. The canonical early example: in August 2025, Cloudflare launched new capabilities within its Cloudflare One platform designed to help organizations monitor AI usage and protect against Shadow AI, which it describes as the unsanctioned use of generative AI tools that bypass corporate security controls. Our read: this signals that zero trust is evolving to treat AI models themselves as entities that require access verification, not just the humans using them.

    Post-Quantum Cryptography

    In March 2025, Cloudflare announced end-to-end support for post-quantum cryptography within its ZTNA solution, enabling quantum-safe connectivity from web browsers to corporate applications without requiring organizations to individually upgrade each system. This matters because the encryption underpinning zero trust’s secure communications, the channel through which continuous verification happens, needs to be quantum-resistant before quantum computing makes current encryption breakable. The organizations that don’t start this transition now will face a retroactive security crisis when the threat matures.

    NIST released the final version of SP 1800-35 (Implementing a Zero Trust Architecture) in June 2025, documenting end-to-end implementations built with 24 commercial vendors in a government lab environment. It’s the most comprehensive practical build guide available for organizations starting from scratch.


    Frequently Asked Questions

    What is zero trust security in simple terms?

    Zero trust security is a cybersecurity approach that eliminates automatic trust for any user, device, or network connection, including those already inside a corporate network. Instead of trusting based on location, every access request is verified continuously. The core principle: “never trust, always verify.” NIST defined the framework in SP 800-207 in 2020.

    What are the five pillars of zero trust?

    The CISA Zero Trust Maturity Model defines five pillars: Identity, Devices, Networks, Applications & Workloads, and Data. Each pillar progresses through maturity stages, Traditional, Initial, Advanced, and Optimal. Cross-cutting capabilities including visibility, analytics, automation, and orchestration apply across all five pillars.

    Is zero trust the same as a VPN?

    No. A VPN grants broad network access once a user authenticates. ZTNA (Zero Trust Network Access) grants access only to specific resources, verified continuously for every session. It’s the direct VPN replacement technology. Gartner predicted that by 2025, 60% of companies would replace VPNs with ZTNA solutions, a transition still underway for most organizations.

    Who created zero trust security?

    Zero trust was created by John Kindervag while a VP and Principal Analyst at Forrester Research around 2009–2010. He published the foundational paper introducing the model and the phrase “never trust, always verify.” Kindervag is now Chief Evangelist at cybersecurity company Illumio and served as a primary author of the NSTAC report to the President on zero trust.

    Does zero trust prevent ransomware?

    Zero trust significantly reduces ransomware risk by limiting lateral movement, the ability of attackers to spread through a network after initial compromise. Micro-segmentation, a core zero trust control, contains breaches to smaller network zones. However, zero trust doesn’t prevent the initial point of entry, and identity controls remain vulnerable to MFA bypass techniques.

    How much does it cost to implement zero trust?

    Costs vary widely by organization size, existing infrastructure, and vendor choices. The financial case rests on IBM’s 2024 data: the average breach costs $4.88 million, while organizations with mature zero trust programs save an average of $1.76 million per breach. Most practitioners recommend starting with existing MFA and IAM tools mapped to the five pillars before purchasing new platforms.


    What You Now Know That Most Organizations Don’t Act On

    Zero trust security isn’t a product, a perimeter replacement, or a checkbox. It’s a strategic reorientation, from “trust by location” to “verify always, grant least privilege, monitor continuously.” The concept is 15 years old. The mandate, the market, and the threat landscape have finally caught up.

    The implementation gap, 72% intent, 30% execution, is the central story of cybersecurity in 2025. The organizations closing that gap are not the ones that bought a “zero trust platform.” They’re the ones that mapped identity as pillar one, built maturity incrementally, and didn’t mistake a vendor’s marketing claim for a security guarantee.

    Watch three things over the next 12–18 months:

    • AI as a zero trust entity: As enterprises adopt generative AI tools, the frameworks for verifying AI model access, not just human access, will become a new frontier of zero trust architecture.
    • Post-quantum cryptography adoption: Organizations that don’t begin transitioning the cryptographic layer of their zero trust implementations will face a retroactive security crisis when quantum computing matures.
    • Regulatory enforcement sharpens: GDPR, NIS2, and U.S. federal compliance requirements are tightening. A breach without a documented zero trust program is increasingly being treated as negligence by regulators and cyber liability insurers alike.
    If you’re building this, start with identity. Resist the “zero trust in a box” pitch. And read Gligor’s paper, not because he’s right that zero trust is theoretically impossible, but because the organizations that understand its limits are the ones that won’t be surprised when it doesn’t live up to its name.