Skip to content
Field reportSC-2026-0311

Zero-Trust rollouts stall at the legacy boundary

The identity layer goes in cleanly. Then someone finds the manufacturing system that only speaks a protocol from 2004.

SeverityHigh

9 minEnterprise CyberSec

Every Zero-Trust programme we have looked at this year followed the same curve: rapid progress across cloud workloads and modern endpoints, then a long plateau. The plateau is always the same set of systems — plant controllers, an ERP instance nobody dares restart, a file share with permissions accreted over fifteen years.

These systems cannot present an identity, cannot be patched on a normal cycle, and cannot be taken offline for a migration window. The standard advice is to segment around them, which is correct and much harder than it sounds.

What the successful programmes did differently

  • Inventoried by traffic observation rather than by asking teams what they run. The two lists never match.
  • Put a policy enforcement point in front of the legacy system instead of trying to modify it.
  • Accepted a documented exception with an owner and a review date, rather than an undocumented gap.
  • Measured progress by percentage of traffic authenticated, not by percentage of projects closed.
We hit ninety per cent in eight months and spent the next two years on the last ten.
Security architect, industrial manufacturer

What to watch

Whether enforcement points become cheap enough to place in front of individual legacy hosts. That single change would convert the plateau into a slope.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined