Fifteen years after introducing zero trust, John Kindervag argues the framework has not lost its relevance against AI-assisted attacks. In a recent SecurityWeek piece, he says the core model still holds firm, but only when organizations get the implementation right.
Kindervag's position is that AI changes the threat landscape without invalidating zero trust's underlying principles. The emphasis falls on execution: poor deployment, not the framework's age, is what leaves organizations exposed. The article offers no competing views, presenting Kindervag's defense as the central argument.
For security teams, the takeaway is that zero trust is not a product to install but a strategy to apply deliberately. As AI tools make attacks faster and more adaptive, the discipline of verifying every request becomes more important, not less.