Where Zero Trust Falls Short
And What You Can Do About It
Overview: Exposing the Zero Trust Gap
According to research by Gartner, the majority (63%) of organisations worldwide state they have implemented a Zero Trust strategy. But when you dig into the details, you quickly find that these strategies only extend to half (or less!) of their overall environment.
Said another way: there’s still a lot to be done when it comes to protecting our modern environment and layering the principles of Zero Trust throughout.
If your organization is part of this majority, you deserve a lot of credit. The dominance of cloud-based applications and the new norm of remote and hybrid work knocked down the castle walls.
Zero Trust is an answer to this shift, but it asks you to fundamentally change how (or even if) you trust someone is who they say they are.
The research shows that you acted swiftly, got some early wins, and focused on protecting the “crowned jewels.” But then, over time, progress lost steam. Priorities shifted, the processes became harder to manage, and new systems were introduced that fell outside the original scope.
And before long, your Zero Trust initiative became a static project instead of an on-going security framework.
This isn’t due to a lack of effort… It’s a lack of clarity.
Clarity around what full Zero Trust adoption actually looks like. How far your organisation needs to take it. How to control the complexity rather than being stymied by it.
Because in the end, no matter what strategy you employ, the weakest link is the only one that matters. If you haven’t rolled out a Zero Trust strategy across your entire environment, or feel you cannot, you may be unsure what’s missing in your current approach, what to prioritize next, or how to scale it without disruption.
This eBook will help you understand why Zero Trust is a critical initiative and give you the direction you need to expand and strengthen your program.
Tool Sprawl & Shadow IT
When Zero Trust controls are fragmented across disconnected tools, enforcing policies consistently becomes difficult. Gaps widen, risks go undetected, and teams lose visibility and control.
Today’s Security Reality: What You’re Up Against
Due to its perceived complexity and impact on productivity, Zero Trust often focuses on a few critical systems or user groups, while the broader environment still operates under outdated trust assumptions.
Meanwhile, the threat landscape is evolving just as quickly.
This is where most Zero Trust efforts fall short. You have a clear mandate to secure high-risk areas, but struggle to scale with the organization. Without broad, consistent enforcement, Zero
Trust becomes more of a label than a framework.
According to the 2025 Verizon Data Breach and Incident Report (VDBIR), credential abuse is still the top access vector for attacks. Its analysis of info-stealer malware credential logs reveals that 46% of compromised systems with corporate logins were non-managed devices, often hosting both personal and business credentials.
Deepfake-based social engineering, AI-written phishing emails, and impersonation attacks bypass filters and mimic internal communication with alarming accuracy.
At the same time, the attack surface keeps expanding. Cloud sprawl, shadow IT, shadow AI, and hybrid work have blurred the boundaries of what needs protection.
This is why Zero Trust is so essential. Identity is at the center of everything.
You’re being asked to protect a constantly expanding environment, often with the same or fewer resources. This must change.
Here’s what the VDBIR says about MFA:
“Having MFA enabled continues to be the gold standard to help protect against authentication
abuse, but having it enabled should not make your detection and monitoring processes complacent.”
Prompt-bombing is a new element of social engineering whereby end users are bombarded with MFA prompts. They give in and accept it just to turn off the noise. It isn’t the only method attacker use to bypass MFA, but it is the most prevalent. It’s a good reminder that MFA, while a powerful deterrent, is not immune to abuse.
The VDBIR is an essential annual report that dives deep into the security landscape. It’s always
worth a read, and you can find it here.
Zero Trust is “a collection of concepts and ideas designed to minimize uncertainty in enforcing least-privilege, per request access decisions, on the assumption that the network is already compromised” and represents a shift from location-centric to identity-centric security.
In the past, organizations trusted anything inside their network. But with hybrid work, cloud-first infrastructure, and increasingly sophisticated threats, that trust model no longer holds up. Today, assuming anything is safe by default creates risk. Zero Trust replaces implicit trust with continuous verification.
Zero Trust is essential for organizations of all sizes as:
● It limits the damage of breaches. If an attacker gets in, Zero Trust limits what they can
access and how far they can move.
● It protects beyond the perimeter. With cloud apps and remote work, traditional network
boundaries don’t apply.
● It responds to real-world threats. AI-driven phishing and identity-based attacks are harder
to detect. Zero Trust makes them harder to succeed.
The cost of inaction is growing, with the global average cost of a data breach reaching $4.88
million in 2024, and 12,195 confirmed breaches reported in 2025 – the highest number on
record.
Never trust, always verify, and continuously validate context (user, device, posture, workload) before granting the narrowest access possible.
Why Organizations Struggle with Full Zero Trust Adoption
Early rollouts (like MFA and removing admin accounts) focus on just a small part of the environment or one-off projects, without a plan to scale over time. MFA tools, in particular, can be expensive, hard to integrate, and time consuming to manage. These challenges drain resources and slow progress.
Here’s what’s standing in the way of full adoption:
Lack of Direction and Competing Priorities
Without a clear roadmap or long-term plan, teams struggle to define what Zero Trust looks like. Daily responsibilities take over, and security loses focus.
Legacy Systems
Outdated infrastructure often fails to support modern controls. Teams rely on
workarounds that create risk and reduce consistency.
Internal Resistance
Over 20% of organizations report pushback
from internal teams. When Zero Trust feels
disruptive or adds friction, buy-in drops and
momentum fades.
Resource and Budget Constraints
Many IT teams run lean. Complex rollouts
demand more time, tools, and people than
most teams can spare.
Privileged Access Management (PAM) is
Too Complex
While PAM is essential to Zero Trust, many
tools are difficult to set up and maintain –
keeping a critical layer of protection out of
reach.
Zero Trust: What It Means and Why It Matters
Even with partial Zero Trust controls in place, you remain exposed if enforcement isn’t consistent across users, devices, apps, and privileged access. Here’s what’s at stake if your Zero Trust efforts don’t go far enough:
Lateral Movement:
If internal systems aren’t segmented and verified continuously,
attackers can move between them undetected. A single compromised account or
endpoint can become a gateway to everything else.
Unmanaged Privileged Access:
Admin credentials that aren’t closely monitored or
worse, never expire can remain active for weeks or months. This increases the risk of
insider threats, data leaks, and ransomware escalation.
Compliance Failures:
Without full visibility and consistent enforcement, policy gaps go
unnoticed until audits surface them. That can lead to failed certifications, penalties, and damage to your brand.
Tool Sprawl & Shadow IT:
When Zero Trust controls are fragmented across
disconnected tools, enforcing policies consistently becomes difficult. Gaps widen, risks go undetected, and teams lose visibility and control.
UX and IT Strain from Incomplete Rollouts
Security gaps are only part of the problem. Incomplete Zero Trust rollouts also create ongoing
operational headaches and poor experiences for both users and IT. Here’s how:
Password Fatigue:
Without centralised access or password-less solutions and SSO, users are forced to manage too many logins. The average employee juggles around 191 passwords, which leads to unsafe storage, password reuse, and increased support tickets.
Excessive Login Prompts:
In environments without conditional access or smart session management, users are prompted to log in repeatedly. This slows productivity and damages trust in the system.
Higher IT Workload:
IT teams are left managing inconsistent policies, manual provisioning, and endless reset requests. Instead of focusing on strategic improvements, they’re buried in daily maintenance.
Resistance to Future Changes:
When users see Zero Trust as frustrating or inconsistent, it becomes harder to roll out new controls. Security feels like a blocker, not an enabler, and adoption stalls.
Zero Trust should improve the experience for both users and IT. That only happens when controls are designed to scale and supported by the right tools.
Friction Between Internal Teams
Partial Zero Trust rollouts often lead to misalignment, wasted effort, and growing tension between IT and security teams – stalling progress when teams need to be working together.
Internal friction slows progress, increases exposure, and makes it harder to respond to new threats with speed and consistency.
Misaligned IT-Security Priorities:
Security teams push for broader enforcement (like stricter access policies), while IT teams face user complaints, resource constraints, and the fallout of poorly integrated tools.
Policy Gaps And Finger-Pointing:
Without full enforcement, gaps go unnoticed until something breaks, leading to reactive blame rather than proactive improvement.
Inconsistent Enforcement:
Users may experience different rules across systems, which frustrates IT and undermines security’s goals.
Audit and Compliance Gaps:
Security may assume policies are in place, while IT lacks the controls to actually implement or monitor them, creating accountability breakdowns.
The Five Must-Haves of a Zero Trust Program
To move beyond surface-level adoption, a Zero Trust program needs to cover five essential areas. These are the structural elements that protect your organization at every layer where implicit trust typically hides. If any one of these areas is lacking, your environment stays vulnerable, even if the rest is strong.
-
Identity and Access Management (IAM):
Every access request must be verified. This means multi-factor authentication and conditional access policies wherever possible.
-
Privilege Access Management (PAM):
Elevated privileges are granted only when needed, and revoked after use. This is applicable everywhere, not just in critical pockets of your network.
-
Device Trust:
Knowing who is logging in is only part of the equation. You need to verify the health of the device they’re using and tie access requests to that.
-
Network and Application Access:
Without broad, perimeter-based access controls, users should only connect to the specific apps and services they need, under specific conditions.
-
Visibility and Monitoring:
You can’t secure what you can’t see. Centralised logging and monitoring helps detect unusual activity, enforce accountability, and simplify audits.
Zero Trust Security In Action
An employee tries to access a customer database. Instead of relying on a static password, the system prompts for multi-factor authentication (MFA) and only grants access if the user’s identity is confirmed and they are on their managed device.
A remote user connects from a public Wi-Fi network. Instead of full network access via VPN, they’re only granted access to their productivity suite, with all other services segmented and blocked.
A DevOps engineer needs root access to a server for maintenance. PAM issues just-in-time access that automatically expires after the task is completed, leaving no lingering permissions.
Making Zero Trust Work: A 3-Phase Plan
The key to sustainable Zero Trust adoption is breaking it into manageable phases. That way,
you can make progress without overloading your team or disrupting daily operations.
Phase 1
Start with the Basics
Focus on the foundational, high-impact actions that deliver immediate risk reduction. Enforce multi-factor authentication (MFA) across the board.
Vault shared and privileged credentials. Remove default admin accounts. Apply least privilege access policies by default.
Phase 2
Expand Coverage
Once the basics are in place, start extending Zero Trust protections across more of your environment. Apply device trust policies. Create conditional access rules based on location, device posture, or user behaviour. Replace broad VPN access with app-level and network segmentation.
Phase 3
Optimize & Scale
With controls in place, focus on automation, visibility, and continuous improvement. Log all access activity and set alerts for unusual behavior. Automate onboarding and offboarding, including privilege revocation. Centralize reporting to support audits and compliance reviews.
Zero Trust Security Is Simplified with JumpCloud
Managing identities in one system, devices in another, access policies somewhere else… it just creates silos that hamper your ability to protect your organization effectively. It slows down enforcement, creates blind spots, and adds unnecessary friction for IT and security teams alike.
That’s where platform simplicity matters. Rather than juggling multiple tools to manage device posture, app-level access, credential vaulting, and so on, teams can simplify operations through a unified platform.
JumpCloud and VaultOne bring the essential elements of Zero Trust together in a single platform – identity, device trust, access control, PAM, and visibility – so teams can build a comprehensive Zero Trust framework without relying on fragmented, hard-to-integrate solutions.
This kind of consolidation enables stronger and more sustainable outcomes:
More consistent policy enforcement.
Faster rollout of new security controls.
Simpler audits and compliance reporting.
Less operational overhead for IT and security teams.
JumpCloud and VaultOne make it easier for organizations to fully adopt, enforce, and scale Zero Trust.
Control The Complexity of Zero Trust
The challenges of implementing Zero Trust are many, but every good challenge has a solution (or two) with the right perspective and guidance. Download The Ultimate Guide to Implementing Zero Trust in an Imperfect World to learn how to navigate through technical complexity, get executive buy-in, and prioritise your rollout.
Learn more!
