2026 · 07Cybersecurity
Zero trust is a governance decision, not a product
Buying a zero-trust product before agreeing on identity, data classification, and decision rights just moves the problem behind a nicer login screen.
Every second cybersecurity conversation I have in Windhoek starts with a vendor slide that promises "zero trust in ninety days." It never lands, because zero trust is not a product you install — it is a set of governance decisions the organisation has to make before a single policy is written.
The three decisions that come before tooling
- Identity is the perimeter. Agree, in writing, that every access decision routes through a single identity provider. Until that is signed, every "zero trust" project is a parallel silo.
- Data has to be classified. You cannot write a least-privilege policy for data nobody has classified. Start with three tiers — public, internal, restricted — and refine later.
- Decision rights are explicit. Who approves an exception? Who owns the risk when a legacy system cannot meet the standard? Name them before procurement.
What to buy, and when
Only after those three decisions is it worth evaluating an identity provider, a policy engine, and network segmentation. In that order. Reverse the order and you get an expensive login screen bolted onto the same flat network you had last year.