top of page


Zero Trust Foundations: Running AAVI Through the Device Pillar
Devices used to mean laptops and phones. Now they mean containers, microservices, and AI agents that can act on their own. This week's Zero Trust Foundations post runs the AAVI model through the Device pillar, with real 2026 breach headlines showing what happens when device and workload trust gets skipped, whether the "device" in question has a keyboard or not.
cletetaylor67
7 days ago9 min read


Zero Trust Foundations: Using AAVI to Build Functional Zero Trust in Existing Environments
Zero Trust does not become real by buying a tool or redrawing the network diagram. It becomes real when we assess how trust is granted today, adapt existing controls, verify that the changes work, and keep iterating. This post introduces the AAVI model for turning existing environments into functional Zero Trust one protect surface at a time.
cletetaylor67
Jul 2610 min read


Zero Trust Foundations: Cross Functions – Visibility, Automation, and Governance
The Five Pillars help make Zero Trust decisions, but the cross functions keep those decisions visible, consistent, and governed. In this post, we look at Visibility and Analytics, Automation and Orchestration, and Governance as practical operating functions for a functional Zero Trust Architecture. The goal is not a fully automated security ecosystem on day one. The goal is to prove trust decisions, implement controls consistently, reduce policy drift, and measure whether ris
cletetaylor67
Jul 1710 min read


Zero Trust Foundations: The Trust Problem Hiding in Plain Sight
Grab a cup of coffee and pull up a chair. This post kicks off a new series for ZT Foundations where we will walk through some of the key ideas from my new book, ZT Foundations: Building Zero Trust with the Tools You Already Have. My goal for this series is simple: take the mystery out of Zero Trust, talk about it in plain language, and show how it can be built from practical decisions instead of shiny buzzwords. Over the next few weeks, we will compare traditional security st
cletetaylor67
Jun 189 min read


Standards Don’t Keep You Safe. Decisions Do.
Zero Trust is one of the clearest signals that we’re moving past the expectation that standards will provide the roadmap for implementation. In a Zero Trust world, ‘minimum requirements’ are not a destination. They are a baseline. They tell you where the floor is, not where the ceiling should be. And no longer can we rely on what we defined on Monday being adequate for what may happen on Friday
cletetaylor67
May 58 min read


From “Staying Compliant” to “Eliminating Implicit Trust”: GRC’s New Role in a Zero Trust World
Most GRC programs know how to prove they’re compliant. Zero Trust raises the bar by asking a harder question: how quickly can you eliminate implicit trust—and prove it with real signals, not just audit evidence?
cletetaylor67
Apr 711 min read


Stop Letting Vendors Write Your Zero Trust Security Strategy
Zero Trust is an architecture and a set of outcomes, not a shopping list. Decide what “good” looks like for you , then pick tools that earn a place in that design. We say we want a “security strategy,” but a lot of the time what we really have is a pile of product decisions made in the moment; because an alert was scary, a headline was loud, or a demo was chef’s kiss . And honestly? Historically we’ve treated cybersecurity tooling like drunk teenagers dating the next pretty t
cletetaylor67
Apr 26 min read
bottom of page