top of page


Zero Trust Foundations: Running AAVI Through the Device Pillar
Devices used to mean laptops and phones. Now they mean containers, microservices, and AI agents that can act on their own. This week's Zero Trust Foundations post runs the AAVI model through the Device pillar, with real 2026 breach headlines showing what happens when device and workload trust gets skipped, whether the "device" in question has a keyboard or not.
cletetaylor67
7 days ago9 min read


Zero Trust Foundations: Running AAVI Through the Identity Pillar
Identity is where Zero Trust starts, but it cannot stand alone. In this post, we run AAVI through the Identity pillar by documenting transaction flows, writing Zero Trust policy statements, enforcing MFA, retiring legacy authentication, and showing how visibility, automation, and governance keep identity decisions honest.
cletetaylor67
Aug 118 min read


Zero Trust Foundations: Using AAVI to Build Functional Zero Trust in Existing Environments
Zero Trust does not become real by buying a tool or redrawing the network diagram. It becomes real when we assess how trust is granted today, adapt existing controls, verify that the changes work, and keep iterating. This post introduces the AAVI model for turning existing environments into functional Zero Trust one protect surface at a time.
cletetaylor67
Jul 2610 min read


Zero Trust Foundations: Cross Functions – Visibility, Automation, and Governance
The Five Pillars help make Zero Trust decisions, but the cross functions keep those decisions visible, consistent, and governed. In this post, we look at Visibility and Analytics, Automation and Orchestration, and Governance as practical operating functions for a functional Zero Trust Architecture. The goal is not a fully automated security ecosystem on day one. The goal is to prove trust decisions, implement controls consistently, reduce policy drift, and measure whether ris
cletetaylor67
Jul 1710 min read


Zero Trust Foundations: How the Five Pillars Build Better Trust Decisions
Before changing controls, we need to understand what our Zero Trust Architecture is supposed to do. This post uses the Five Pillars—Identity, Device, Network, Application, and Data—to show how legacy security assumptions can be evaluated and transformed into better trust decisions.
cletetaylor67
Jul 109 min read


Zero Trust Foundations: Start Small, Protect What Matters
Zero Trust works best when we stop trying to fix everything at once and start with one meaningful protect surface. This post explains how to choose that first surface, avoid common pitfalls, and use a practical checklist to make Zero Trust manageable with the tools and capabilities you already have.
cletetaylor67
Jul 212 min read


Zero Trust Foundations: The Trust Problem Hiding in Plain Sight
Grab a cup of coffee and pull up a chair. This post kicks off a new series for ZT Foundations where we will walk through some of the key ideas from my new book, ZT Foundations: Building Zero Trust with the Tools You Already Have. My goal for this series is simple: take the mystery out of Zero Trust, talk about it in plain language, and show how it can be built from practical decisions instead of shiny buzzwords. Over the next few weeks, we will compare traditional security st
cletetaylor67
Jun 189 min read


ZT Foundations: Zero Trust Is Not for the Faint of Heart
So pull up a chair, grab a cup of coffee, and let’s get real for a minute about Zero Trust. Not the polished conference-slide version. Not the tidy marketing version. The real version. The version where meaningful change is hard, legacy assumptions get challenged, and progress usually starts with a few uncomfortable truths. Let’s be honest: starting the Zero Trust journey can feel a little like deciding to renovate your house while you’re still living in it. You know it needs
cletetaylor67
Jun 95 min read
bottom of page