You Can’t Improve What You Can’t Measure

Most organizations say they’re on a Zero Trust journey. Very few can tell you where they are on it.
That’s not a criticism. Zero Trust is genuinely complex, it is comprised of 152 target and advanced activities across seven pillars, mapped across your users, devices, applications, data, network, automation, and visibility layers. Knowing where you stand requires more than intent. It requires measurement.
John Kindervag, the architect who coined Zero Trust, laid out a 5-step implementation path that still holds up 15 years later. The image above maps it exactly. Here’s what each step actually means in practice:
Step 1 — Define your protect surface. Not your attack surface but your protect surface. What data, applications, assets, and services matter most to your mission? You can’t secure everything equally. Start with what you can’t afford to lose.
Step 2 — Map the flows. How does data move to and from that protect surface? Who touches it, what touches it, and how? You cannot build policy around transactions you haven’t mapped.
Step 3 — Build the Zero Trust Architecture. With your protect surface defined and flows understood, you can design the architecture that wraps controls around what matters and not around the perimeter of everything.
Step 4 — Create policy. Using the Kipling Method (who, what, when, where, why, and how) write context-based policy that governs access to the protect surface. No more implicit trust. Every access decision earns it.
Step 5 — Monitor and maintain. Zero Trust is not a project you complete. It’s an iterative process. Inspect traffic, analyze telemetry, tighten policy, and close the gaps the data reveals.
Here’s where most organizations go wrong: they jump straight to Step 3 or 4 (buying tools, writing policy) without ever establishing a baseline at Step 1. They don’t know what they’re protecting, so they can’t measure whether their controls are actually working.
You can’t improve what you can’t measure.
That’s why ZT ROAM belongs at both ends of this path and not just at Step 5. Before you spend a dollar on ZT implementation, deploy ROAM to establish your baseline. Know your gaps. Make informed decisions about where to invest. Then validate continuously as you build.
ZT ROAM deploys in minutes as a Docker container, a Kubernetes workload, or an OVA image. It maps automated adversary tests to your DoW ZT Strategy milestones, scores your posture in real time, and tells you exactly where you are on the journey.
Zero Trust is a journey. ZT ROAM is your guide.
Start today with Tensley Consulting Inc. 🔗 https://lnkd.in/eTM5tXQe 📧 ZTROAM@tensleyconsulting.com | 📞 240-636-5468
#zerotrust #ZTROAM #securebydesign #leftofbreach #cybersecurity
Authors: Ryan Rosencranz and Bennett Bodner