The Zero Trust Blind Spot

Zero Trust is a journey, but without a clear baseline, it’s impossible to know how far you’ve come or what still needs attention. In this edition of The Modern Security Mindset, discover why measurement is the foundation of every successful Zero Trust strategy and how organizations can use objective assessments to identify gaps, prioritize investments, and validate progress with confidence.

Share On Your Socials

Facebook
Twitter

You Can’t Improve What You Can’t Measure

Most organizations say they’re on a Zero Trust journey. Very few can tell you where they are on it.

That’s not a criticism. Zero Trust is genuinely complex, it is comprised of 152 target and advanced activities across seven pillars, mapped across your users, devices, applications, data, network, automation, and visibility layers. Knowing where you stand requires more than intent. It requires measurement.

John Kindervag, the architect who coined Zero Trust, laid out a 5-step implementation path that still holds up 15 years later. The image above maps it exactly. Here’s what each step actually means in practice:

Step 1 — Define your protect surface. Not your attack surface but your protect surface. What data, applications, assets, and services matter most to your mission? You can’t secure everything equally. Start with what you can’t afford to lose.

Step 2 — Map the flows. How does data move to and from that protect surface? Who touches it, what touches it, and how? You cannot build policy around transactions you haven’t mapped.

Step 3 — Build the Zero Trust Architecture. With your protect surface defined and flows understood, you can design the architecture that wraps controls around what matters and not around the perimeter of everything.

Step 4 — Create policy. Using the Kipling Method (who, what, when, where, why, and how) write context-based policy that governs access to the protect surface. No more implicit trust. Every access decision earns it.

Step 5 — Monitor and maintain. Zero Trust is not a project you complete. It’s an iterative process. Inspect traffic, analyze telemetry, tighten policy, and close the gaps the data reveals.

Here’s where most organizations go wrong: they jump straight to Step 3 or 4 (buying tools, writing policy) without ever establishing a baseline at Step 1. They don’t know what they’re protecting, so they can’t measure whether their controls are actually working.

You can’t improve what you can’t measure.

That’s why ZT ROAM belongs at both ends of this path and not just at Step 5. Before you spend a dollar on ZT implementation, deploy ROAM to establish your baseline. Know your gaps. Make informed decisions about where to invest. Then validate continuously as you build.

ZT ROAM deploys in minutes as a Docker container, a Kubernetes workload, or an OVA image. It maps automated adversary tests to your DoW ZT Strategy milestones, scores your posture in real time, and tells you exactly where you are on the journey.

Zero Trust is a journey. ZT ROAM is your guide.

Start today with Tensley Consulting Inc. 🔗 https://lnkd.in/eTM5tXQe 📧 ZTROAM@tensleyconsulting.com | 📞 240-636-5468

#zerotrust #ZTROAM #securebydesign #leftofbreach #cybersecurity

Authors: Ryan Rosencranz and Bennett Bodner

Articles

Tensley Showcases ZT ROAM v2.0 at TechNet Cyber 2026

Tensley Consulting made a strong impact at TechNet Cyber 2026 with the debut of ZT ROAM v2.0, engaging industry leaders and demonstrating the latest advancements in Zero Trust assessments. The event also featured a presentation from William Johnson on securing legacy operational technology environments, reinforcing Tensley’s leadership in driving innovative cybersecurity solutions across government, defense, commercial, and research sectors.

Tensley at the 16th Annual Billington Cybersecurity Summit

Tensley Consulting is proud to join the 16th Annual Billington Cybersecurity Summit in Washington, D.C., where we’ll highlight our zero trust platform, ZT ROAM, and share insights on strengthening cybersecurity culture in an era of evolving human-targeted threats.