
Marc Lueck at Zscaler argues that 2024 will bring a war of requirements for zero trust
As organisations continue to grapple with the pace of technological evolution – the ever-changing cyber-threat landscape, new ways of working, and the importance of frictionless user experiences – zero trust solutions remain a guiding light.
However, as growing zero trust recognition gives way to a flood of new offerings and an increasingly saturated market, a war of requirements is rapidly emerging.
While market competition often helps to drive faster evolution, resulting in greater choice and depth for the customer, business leaders need to be able to differentiate between point solutions and highly integrated cloud-based platform offerings that support further consolidation efforts in order to select the solution that will best benefit their organisation.
Unless these leaders approach zero trust through a lens that encompasses a broader view of the ways the solution can help to achieve overall growth, this war of requirements has the potential to divide the market, teams, and business as a whole.
As a first step organisations have to define who is in charge of driving a zero trust initiative. This is an important consideration in the war of requirements, and something that plays a key role in unlocking its organisation-wide value.
If a networking team is looking to deploy zero trust, their view of it and what they deploy is likely to lean heavily towards network-based zero trust; a point solution that offers them just what they need to support the business’s networking needs at that time.
Similarly, if a CISO implements zero trust, their focus is usually on logical access, the principal of least privilege and limiting access to secure assets. And if a CIO wants to deploy it, they will be looking for a solution that can assuage the business and simplify transaction flow.
As a concept, zero trust is not a regulated term. The closest thing we currently have to an official definition is from Gartner, who defines zero trust as “products and services that create an identity and context-based, logical-access boundary that encompasses an enterprise user and an internally hosted application or set of applications.” However, this is a very limited definition.
Based on NIST, I believe that zero trust can be viewed a seven-step cycle: Establish an identity (a person, machine, or device), establish the context about that identity (time of day, role, and responsibility of the identity), confirm the destination, assess the risk, prevent compromise, prevent data loss, and enforce the policy on a cyclical basis.
Once this process is viewed as a philosophy of access rather than something more limited, zero trust’s true potential can be unlocked, allowing it to meet business needs that extend beyond immediate, siloed goals.
Despite zero trust being a largely unregulated term, when it is done right, the solution enforces a fundamental change to the way security and access is delivered. Importantly, zero trust can be narrowly approached in any one of the previously mentioned ways – for network purposes, for security, or the CIO – and provide organisations with an appropriate solution, but it will not be one that sets them up for growth.
Such an approach will also create a war between vendors who are trying to sell their solutions, and customer teams trying to identify the most suitable option for them.
Instead, successful businesses will solicit opinions from a larger audience, taking into consideration the full set of business needs and goals, and ensuring the deployed solution meets these extended requirements. The zero trust winners will be those organisations that choose the broadest, most integrated capabilities – the wider the platform, the easier the future is to achieve.
Conversely, the narrower the deployed solution – typically point solutions – the harder it will be to grow and adapt its use.
Ultimately, the battlefronts for both customers and vendor wars are changing, with a particular emphasis on the vendor space. If those selling zero trust solutions recognise the many benefits of shifting from a point solution approach that can only support very specific use cases, to a platform one – both sides will win.
Fostering platform thinking over product thinking will also speed up the development of products that better serve the wider vision of zero trust.
Zero trust has already caused seismic changes in the domains of cyber-security and business transformation. In terms of who should be responsible for ensuring an organisation is deploying it in the most efficient way, one thing is certain; whoever takes on this responsibility should be matrix aligned and able to drive change by embedding zero trust in the company’s networks, security, application access, and users.
The zero trust solution should be recognised for its all-encompassing ability to meet business goals and drive overall growth, rather than fragmented needs of siloed teams. In 2024, this war of requirements is likely to rear its head, but those who recognise the true power of zero trust will come out on top.
Marc Lueck is CISO EMEA at Zscaler
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543