Zero-Trust rollouts stall at the legacy boundary
The identity layer goes in cleanly. Then someone finds the manufacturing system that only speaks a protocol from 2004.
SeverityHigh
9 minEnterprise CyberSec
Every Zero-Trust programme we have looked at this year followed the same curve: rapid progress across cloud workloads and modern endpoints, then a long plateau. The plateau is always the same set of systems — plant controllers, an ERP instance nobody dares restart, a file share with permissions accreted over fifteen years.
These systems cannot present an identity, cannot be patched on a normal cycle, and cannot be taken offline for a migration window. The standard advice is to segment around them, which is correct and much harder than it sounds.
What the successful programmes did differently
- Inventoried by traffic observation rather than by asking teams what they run. The two lists never match.
- Put a policy enforcement point in front of the legacy system instead of trying to modify it.
- Accepted a documented exception with an owner and a review date, rather than an undocumented gap.
- Measured progress by percentage of traffic authenticated, not by percentage of projects closed.
We hit ninety per cent in eight months and spent the next two years on the last ten.
What to watch
Whether enforcement points become cheap enough to place in front of individual legacy hosts. That single change would convert the plateau into a slope.