Skip to content
Cybersecurity4 min read27 May 2026Draft — awaiting Abhijit's review

Zero Trust Is a Culture, Not a Product

You cannot purchase your way to zero trust. The architecture only works when the organisation changes how it thinks about access.

By Abhijit Debnath

Somewhere along the way, 'zero trust' became something you buy. Vendors sell it in boxes, dashboards, and licence tiers. But the organisations I have seen struggle with zero trust rarely lacked tooling — they lacked agreement about what they were actually protecting, and from whom.

The architecture is the easy part

Verify explicitly. Least privilege. Assume breach. The principles are well documented and the technology to enforce them is mature. What is hard is the Tuesday morning reality: a regional manager who shares credentials because the approval workflow takes three days, a legacy application that cannot speak modern identity protocols, an executive who wants an exception.

Security without culture becomes friction. Culture without architecture becomes hope. You need both, in that order of difficulty.

Zero trust is ultimately a statement about how an organisation treats access: as something earned continuously, never assumed permanently. That is a behavioural commitment before it is a network diagram.

Start with identity, not infrastructure

If you are beginning the journey, resist the urge to redesign the network first. Start where trust actually lives — identity. Consolidate it, strengthen it, make access visible and reviewable. Every hour invested in clean identity data pays back across every later phase.

And measure culture, not just coverage: how long does access provisioning take, how often are permissions reviewed, how many standing exceptions exist? Those numbers tell you more about your zero-trust maturity than any dashboard.

CybersecurityZero TrustGovernance

Stay in the loop

Get new perspectives by email — written occasionally, never noisily. Unsubscribe anytime.

More perspectives are on the way.