Would You Know?

They didn’t break in.
They were already there.
Volt Typhoon, a Chinese state-sponsored APT campaign, spent years pre-positioned inside U.S. critical infrastructure: energy grids, water systems, transportation networks, communications pipelines. CISA, NSA, and FBI issued a joint advisory confirming it. No malware footprint. No unusual tools. No alerts fired.
They used your system utilities. Your trusted credentials. Your network and all because your network trusted them.
Your SIEM never fired. Your XDR never flagged it. Because there was nothing anomalous to detect. They looked exactly like authorized users. Because inside a flat, perimeter-trusting network, they effectively were.
This is the architectural failure John Kindervag warned about in 2010: hard and crunchy on the outside, soft and chewy in the center. Once past the shell, the attacker moves freely because the network was designed around the fiction that internal traffic is trusted traffic.
At TechNet Cyber, Assistant Secretary Sutton named it directly: living-off-the-land techniques by state actors make Zero Trust “an urgent warfighting necessity.”
So here’s the hard question every critical infrastructure owner needs to answer: If an adversary is using your own tools against you, how would you know?
Not your SOC. Not your SIEM. Your architecture.
“Assume breach” is not a response posture. It’s an architectural design principle. It means your network is built so that a threat actor who gains entry still cannot maneuver because there’s nothing to move laterally into. Microsegmented protect surfaces. Least-privilege access. Continuous verification. No implicit trust.
That’s Zero Trust. Not a compliance document. Not a product. An architectural reality.
Here’s the gap in nearly every organization today: leadership says they’ve adopted Zero Trust. Program managers have roadmaps. Vendors have sold ZT-labeled tools. But nobody has objectively measured whether the architecture actually behaves like Zero Trust under adversary conditions.
That’s what ZT ROAM does.
ZT ROAM maps your posture against the MITRE ATT&CK framework (including the living-off-the-land TTPs Volt Typhoon used). It scores lateral movement controls, microsegmentation, privilege access, and continuous verification against the DoW’s 152 Target and Advanced Zero Trust activities. The OT Extension covers the exact sectors Volt Typhoon targeted: energy, water, transportation, and communications.
Volt Typhoon wasn’t a failure of detection.
It was a failure of architecture.
The time to find out if your architecture would have stopped them is before they’re already inside and not while you’re briefing Congress about the breach.
Start your Zero Trust compliance journey today. 🔗
https://lnkd.in/eTM5tXQe
📧 ZTROAM@tensleyconsulting.com | 📞 240-636-5468
#zerotrust #leftofbreach #leftofboom #ZTROAM
Tensley Consulting Inc.
Authors: Ryan Rosencranz and Bennett Bodner