Implementing Zero Trust: Why Most Organizations Struggle
- By Suresh Katukam, Nile
- August 25, 2025

The concept of Zero Trust is nothing new, with the term coined in 2010 by Forrester Research analyst John Kindervag. Twenty-five years later, Zero Trust is more relevant than ever to today’s complex digital landscape. The shift to remote work, widespread cloud adoption, a growing BYOD (Bring Your Own Device) culture, and the proliferation of the Internet of Things (IoT) have massively expanded the attack surface, underscoring the need for a Zero Trust approach that moves beyond the limitations of perimeter-based security.
These traditional security models assume that threats primarily originate from outside the network perimeter. However, the perimeter’s definition is not as clear-cut as it once was. If the campus network were the sole location for user connections and application hosting, perimeter-based security could primarily focus on the attackers outside the walls. However, this is no longer true.
The Zero Trust framework addresses the limitations of traditional security models, enabling networks to protect against both external and internal threats. The essence of Zero Trust is: “Never trust, always verify.” Core principles include least-privilege access, operating under the belief that a breach is “not a matter of if but when,” continuous monitoring, and network segmentation to restrict lateral movement of adversaries.
Unfortunately, few organizations have successfully implemented Zero Trust principles across their entire environment due to several key challenges. In fact, Gartner observed in the 2024 State of Zero Trust Adoption Survey that around 63% of respondents had either attempted or partially attempted a Zero Trust initiative, with about 35% reporting failures in their initiatives that adversely affected their organization.
Zero trust challenges: The campus is now the weakest link
Organizations are facing several obstacles regarding Zero Trust, including solution complexity, resource strain, interoperability issues, and the need for a mindset shift, mainly related to user expectations. The biggest challenge, according to many, has been in defining what is needed, its advantages, and, to a degree, whether the organization's data and assets are clearly more secure. The problem often stems from organizations being led to believe that more is better.
As work-from-home initiatives became commonplace, Zero Trust efforts shifted toward securing remote access users, further complicating efforts. Vendors and analysts alike set their sights on recommending Zero Trust Network Access (ZTNA), sold as a component of Secure Services Edge (SSE) solutions, which emphasize a cloud-driven security model for devices connecting to enterprise resources. The simplification and ease with which ZTNA is presented have led many to believe that it is now what should be used for the campus as well.
The problem is further compounded by the fact that most IoT devices aren’t capable of running the agents that ZTNA solutions depend on, as IoT devices lack the ability to support agents that are often used by ZTNA solutions. Organizations must either re-engineer their existing network infrastructure to support complex dynamic segmentation requirements or move to a modern network architecture that natively supports Campus Zero Trust principles. Ideally, these modern wired and wireless networks support micro-segmentation on day one, forwarding traffic from all endpoint types to an enforcement point for inspection, providing enhanced visibility, control, and protection. An updated architecture also includes the ability to more easily work within a ZTNA framework without requiring complex integration projects.
The key advantage a new architecture provides is the ability for any size organization to implement Zero Trust for the campus and branch, and ZTNA for remote users in a way that establishes a unified policy enforcement framework both for on-premises endpoints and those connecting remotely.
Is there a role for AI automation?
Due to the sophistication and speed at which threats are emerging, limited resources, and the complexity surrounding Zero Trust initiatives, networks and security solutions will play an increasingly central role. The real-time observability and threat detection offered by AI is the only way organizations can continuously monitor users, devices, and anomalous behavior at a pace that is impossible to match.
AI automation streamlines Zero Trust security by managing complex and repetitive tasks while providing autonomous visibility and control. By incorporating AI into a modern network architecture, it eliminates the need for an increasing number of third-party solutions typically layered over a network. Ultimately, natively delivered AI-driven tools will enhance network visibility, reduce manual IT ticket engagement, and minimize the time IT teams spend monitoring systems. This enables IT staff to focus on more strategic initiatives.
Recommendations
For organizations looking to enhance Zero Trust initiatives, it is important to reassess efforts, determine current vulnerabilities, and develop a strategy that addresses core inefficiencies. Hybrid work, large-scale IoT/OT support, security training for users, and creating an upgrade plan for legacy network and security solutions must all be addressed cohesively, as each provides opportunities for adversaries to exploit.
As such, it is important to start with a network foundation that includes robust Zero Trust capabilities, eliminates the need to layer on solutions, and offers a unified approach that satisfies compliance, risk, and user expectations, regardless of where devices are connected from.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/Olivier Le Moal
Suresh Katukam, Nile
Suresh Katukam is the chief product officer and co-founder of Nile.