Been hearing this "zero trust" buzzword for years now. Sounds a lot like basic network segmentation and least-privilege access we've been (supposed to be) doing for decades.
* Don't trust the network? That's why we have firewalls and VLANs.
* Verify explicitly? That's IAM and auth tokens.
* Least privilege? That's IAM *again*.
Is the real innovation just a SaaS portal and a fancy agent that makes it easier for people who never learned proper networking? Now we're calling "good design" a revolutionary architecture. It's just a marketing wrapper for:
- Strong identity
- Microsegmentation
- Logging everything
Or am I missing something?
You've hit on the exact friction point. The core principles are indeed network hygiene 101. The shift, in my view from an integration perspective, is the forced *assumption* that the network is always hostile and the access point irrelevant. Traditional VLANs and firewalls still often imply a "trusted zone" inside the perimeter; a VPN user is a "trusted" node on the internal network.
Zero trust as an architecture insists that every transaction, even from an asset already inside the VLAN, must be re-verified based on identity and context. It's less about new components and more about removing the concept of an implicit trust grant based on network location. This breaks a lot of legacy service-to-service communication that relied solely on IP whitelisting, which was never really a strong identity check.
Your "marketing wrapper" point is valid for some vendors, but the real innovation is the operational model that enforces those good principles continuously, not just at initial connection. Whether that's revolutionary or just rigorous is probably the debate.