top of page


Zero Trust Foundations: Running AAVI Through the Device Pillar
Devices used to mean laptops and phones. Now they mean containers, microservices, and AI agents that can act on their own. This week's Zero Trust Foundations post runs the AAVI model through the Device pillar, with real 2026 breach headlines showing what happens when device and workload trust gets skipped, whether the "device" in question has a keyboard or not.
cletetaylor67
7 days ago9 min read


Zero Trust Foundations: Running AAVI Through the Identity Pillar
Identity is where Zero Trust starts, but it cannot stand alone. In this post, we run AAVI through the Identity pillar by documenting transaction flows, writing Zero Trust policy statements, enforcing MFA, retiring legacy authentication, and showing how visibility, automation, and governance keep identity decisions honest.
cletetaylor67
Aug 118 min read


Zero Trust Foundations: Using AAVI to Build Functional Zero Trust in Existing Environments
Zero Trust does not become real by buying a tool or redrawing the network diagram. It becomes real when we assess how trust is granted today, adapt existing controls, verify that the changes work, and keep iterating. This post introduces the AAVI model for turning existing environments into functional Zero Trust one protect surface at a time.
cletetaylor67
Jul 2610 min read


Zero Trust Foundations: Cross Functions – Visibility, Automation, and Governance
The Five Pillars help make Zero Trust decisions, but the cross functions keep those decisions visible, consistent, and governed. In this post, we look at Visibility and Analytics, Automation and Orchestration, and Governance as practical operating functions for a functional Zero Trust Architecture. The goal is not a fully automated security ecosystem on day one. The goal is to prove trust decisions, implement controls consistently, reduce policy drift, and measure whether ris
cletetaylor67
Jul 1710 min read


Zero Trust Foundations: Start Small, Protect What Matters
Zero Trust works best when we stop trying to fix everything at once and start with one meaningful protect surface. This post explains how to choose that first surface, avoid common pitfalls, and use a practical checklist to make Zero Trust manageable with the tools and capabilities you already have.
cletetaylor67
Jul 212 min read


ZT Foundations: How Zero Trust Changes IT Work and Legacy Security Practices
Zero Trust is more than a security buzzword. Learn how Zero Trust changes IT work, why legacy authentication and flat networks must evolve, and how practical security decisions reduce risk in today’s threat landscape.
cletetaylor67
Jun 2612 min read


Zero Trust Foundations: The Trust Problem Hiding in Plain Sight
Grab a cup of coffee and pull up a chair. This post kicks off a new series for ZT Foundations where we will walk through some of the key ideas from my new book, ZT Foundations: Building Zero Trust with the Tools You Already Have. My goal for this series is simple: take the mystery out of Zero Trust, talk about it in plain language, and show how it can be built from practical decisions instead of shiny buzzwords. Over the next few weeks, we will compare traditional security st
cletetaylor67
Jun 189 min read


ZT Foundations: Zero Trust Is Not for the Faint of Heart
So pull up a chair, grab a cup of coffee, and let’s get real for a minute about Zero Trust. Not the polished conference-slide version. Not the tidy marketing version. The real version. The version where meaningful change is hard, legacy assumptions get challenged, and progress usually starts with a few uncomfortable truths. Let’s be honest: starting the Zero Trust journey can feel a little like deciding to renovate your house while you’re still living in it. You know it needs
cletetaylor67
Jun 95 min read


Most Zero Trust Conversations Start with the Wrong Question
Most zero trust conversations start in the wrong place. We ask what to buy before we ask what needs to change. And until that changes, the journey does not really begin. “Zero trust is not something you buy and turn on. It is a choice to design for the world as it really is.” The Zero Trust Shift That Changes Everything I cannot tell you how many times I have been in a zero trust conversation where the first question on the table was, “Which platform should we buy?” And hones
cletetaylor67
May 267 min read


A Personal Note About Why I’m Making Secure by Habit Free
So I want to make this promise clearly and publicly: ebook versions of Secure by Habit will always be available free of charge at cletustaylor.com, including the current versions, all future editions, and any translations we are able to publish over time.
cletetaylor67
May 193 min read


AI Over Coffee: What the xAI Shake-Up Says About SpaceX, Grok, and the New Physics of AI
xAI’s move into SpaceX is not just another Musk-world plot twist. It is a sign that AI is leaving its pure software era and entering something more physical, more political, and much harder to ignore. The real story is no longer just about models. It is about power, water, regulation, and who gets to build the infrastructure behind intelligence.
cletetaylor67
May 129 min read


Standards Don’t Keep You Safe. Decisions Do.
Zero Trust is one of the clearest signals that we’re moving past the expectation that standards will provide the roadmap for implementation. In a Zero Trust world, ‘minimum requirements’ are not a destination. They are a baseline. They tell you where the floor is, not where the ceiling should be. And no longer can we rely on what we defined on Monday being adequate for what may happen on Friday
cletetaylor67
May 58 min read


Legacy Protocols: The Quiet Escape Hatch We Need to Close, Starting Now
Modern auth + MFA everywhere. Short-lived tokens. No more “easy paths.” Grab a cup of coffee with me for a minute, because this is one of those security conversations that feels “technical”… right up until it becomes the headline nobody wanted. One of the fastest ways Zero Trust fails is through legacy authentication protocols that are still quietly enabled “for compatibility.” They were designed for a different era, static credentials, limited context, minimal verification,
cletetaylor67
Apr 2814 min read


Speaking Security So the Business Can Actually Decide
Or: How I Stopped Saying Smart Things and Started Getting Decisions Let me start with a confession.Early in my career, I thought if I explained a security issue clearly enough, the business would obviously do the right thing. Reader, that is adorable. What actually happened was this: I would explain the risk, sprinkle in some impressive terminology, everyone would nod, someone would say “Good call,” and then absolutely nothing would happen. No funding, no priority, no decisio
cletetaylor67
Apr 216 min read


AI Is Red-Teaming Faster Than We Can Patch: Vulnerability Response Has to Go Real-Time
Coffee talk on how AI-driven discovery is compressing the clock, and what we should measure and automate next.
cletetaylor67
Apr 148 min read


A Security Pro’s Take on Mythos
People who know me well have a running theory that I never sleep. After spending my “free time” working through Anthropic’s Claude Mythos system card (all 200+ pages), I’m not sure I have strong evidence to refute that hypothesis. Occasionally something lands in the AI world that makes even seasoned security folks sit up a little straighter. Anthropic’s Claude Mythos Preview is one of those moments. Below is a grounded, security-minded take on what the model is, what it isn’
cletetaylor67
Apr 84 min read


From “Staying Compliant” to “Eliminating Implicit Trust”: GRC’s New Role in a Zero Trust World
Most GRC programs know how to prove they’re compliant. Zero Trust raises the bar by asking a harder question: how quickly can you eliminate implicit trust—and prove it with real signals, not just audit evidence?
cletetaylor67
Apr 711 min read


Stop Letting Vendors Write Your Zero Trust Security Strategy
Zero Trust is an architecture and a set of outcomes, not a shopping list. Decide what “good” looks like for you , then pick tools that earn a place in that design. We say we want a “security strategy,” but a lot of the time what we really have is a pile of product decisions made in the moment; because an alert was scary, a headline was loud, or a demo was chef’s kiss . And honestly? Historically we’ve treated cybersecurity tooling like drunk teenagers dating the next pretty t
cletetaylor67
Apr 26 min read
bottom of page