🚨 TIC 3 and Zero Trust: An Architectural Shift Recently, FedScoop offered me the opportunity to discuss how federal agencies are transitioning from static, legacy architectures to more modern platforms through TIC 3 and Zero Trust. At Zscaler, I help lead discussions with governments and enterprises on Zero Trust strategy and architecture. I bring to those conversations nearly 20 years of connection—pun intended—to OMB's Trusted Internet Connections Initiative, including leading CISA’s Federal Trusted Internet Connections Initiative Office as US Federal agencies transitioned to TIC 3.0. A few realities shaping this transition: 👉 Zero Trust and TIC 3.0 are not competing efforts. Under the covers, many of the same teams within CISA, our partners, and agencies across the federal enterprise helped shape the vision for both. 👉 The shift isn’t about where inspection happens or where policy enforcement points sit—though those still matter—but the evidence and justifications behind why decisions are made. 👉 Across the federal enterprise, agency architectures are moving from centralized enforcement to distributed, identity- and context-driven control. For a decade, TIC 2 was about chokepoints—and the inefficiencies they created. The infamous “TIC tax” constrained agencies’ ability to adopt cloud, mobility, SaaS, and modern digital services at the speed the missions demanded. What agencies wanted with TIC 3 was not simply a policy adjustment. They demanded fundamental architectural changes: security controls that travel with the user, the device, the session, and the application—not controls anchored to a fixed network location. That is one reason TIC 3 and Zero Trust fit together so naturally. Both recognize the same reality: trust can no longer be derived from where something is connected. That is ambient trust. That is trust by proximity. Ultimately, it is implicit trust—and something we should be working to eradicate from our enterprises. Confidence is earned through context—not simply granted by location. I’ll share the article in the comments. Thank you to FedScoop for the opportunity, and to Zscaler Public Sector for continuing to drive these conversations forward. #zerotrust #federalit #cybersecurity #innovation
Network Security Best Practices
Explore top LinkedIn content from expert professionals.
-
-
🔐 Trust is the real currency in digital asset exchanges Billions of microtransactions flow every day across exchanges. Without transparency, black-box models can create more doubt than trust. In my latest article, I explore how Kafka + explainable ML can build auditable trust networks for digital assets by: ✨ Capturing every trade and transfer in real time ✨ Applying explainable ML to flag anomalies with reasoning ✨ Creating immutable, auditable records regulators and partners can trust This is how we move from opaque AI to explainable, accountable trust layers that scale with digital finance. https://lnkd.in/gsTTp7Jb #Kafka #ML #ExplainableAI #DigitalAssets #FinTech #Trust #DataGovernance
-
Trust Architecture and Digital Identity refer to the frameworks and technologies that ensure secure and reliable digital interactions. Trust Architecture provides the foundation for safe online transactions by implementing standards, technologies, and policies to safeguard transaction integrity, including data encryption to secure communication protocols, ensuring that online interactions are protected against unauthorized access and fraud. Digital Identity represents the data that uniquely identifies an individual or entity online, and it is essential for maintaining privacy and preventing unauthorized access. Digital Identity includes usernames, passwords, biometric data, and other identifiers that authenticate a person's or entity's identity online. The Zero Trust Model, which operates on a "never trust, always verify" basis, further strengthens this security by requiring continuous verification for network access. Authentication vs. Authorization processes ensure that users are correctly identified and granted appropriate access rights to resources and services. Privacy and Data Protection are critical aspects, ensuring that personal data is managed securely and complies with regulations. Blockchain and Self-Sovereign Identity (SSI) technologies empower users to control their digital identities, enhancing privacy and security without relying on intermediaries. These concepts work hand in hand to protect our online presence and enable safe, private access to digital services. #DataProtection #CyberSecurity #Blockchain #Privacy
-
The fintechs that win in emerging markets are not really software companies. They are physical trust networks with an app on top, and the app is the part that gets underwritten. The visible company is digital: transaction volume, active users, merchant growth, platform expansion. The company that holds the moat is physical. It lives in agents, merchants, cash-in and cash-out points, field teams and repayment behaviour, the everyday places where people already move money. Here is why it matters. In markets where banks spent decades earning distrust, a number on a screen does not become real because the interface is good. It becomes real because a person hands over cash, a shopkeeper vouches for the product, a field officer fixes the failed transaction. That is the trust layer, and it is what makes a digital balance believable. Take M-PESA. Last year it moved KShs 38 trillion, around $300 billion, across 37 billion transactions, close to the entire payment behaviour of a country. The wallet gets the credit. The network of agents and tills that taught tens of millions of people to trust money on a phone is the actual company. So when you read one of these businesses, the test is simple. Find where cash enters and exits. Find who fixes the broken transaction. Work out whether trust sits with the brand or with a local agent the company does not control. Then ask what breaks if the agent network weakens by a fifth. If the answer is "not much," it is a software business. If the answer is "the company," then the trust layer is the company, and the spreadsheet is mispricing it. Emerging markets make this visible. They do not own it. Any market where institutions have not earned trust rewards the company that builds it in the real world. The hidden question is the one the funding announcement never prints: who does the customer trust when the money moves. Full breakdown, with the data and the companies, in the comments.
-
𝐌𝐨𝐬𝐭 𝐨𝐫𝐠𝐚𝐧𝐢𝐳𝐚𝐭𝐢𝐨𝐧𝐬 𝐬𝐭𝐢𝐥𝐥 𝐚𝐩𝐩𝐫𝐨𝐚𝐜𝐡 𝐜𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐰𝐢𝐭𝐡 𝐚 𝐩𝐞𝐫𝐢𝐦𝐞𝐭𝐞𝐫 𝐦𝐢𝐧𝐝𝐬𝐞𝐭. That model is collapsing. AI, cloud, remote work, APIs, and third-party ecosystems have permanently changed the attack surface. Trust can no longer be assumed. It must be continuously validated. That is why Zero Trust is becoming a leadership-level operating principle - not just a security framework. 𝐓𝐡𝐞 𝐬𝐭𝐫𝐨𝐧𝐠𝐞𝐬𝐭 𝐨𝐫𝐠𝐚𝐧𝐢𝐳𝐚𝐭𝐢𝐨𝐧𝐬 𝐚𝐫𝐞 𝐛𝐮𝐢𝐥𝐝𝐢𝐧𝐠 𝐚𝐫𝐨𝐮𝐧𝐝 𝐤𝐞𝐲 𝐙𝐞𝐫𝐨 𝐓𝐫𝐮𝐬𝐭 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐩𝐚𝐭𝐭𝐞𝐫𝐧𝐬: → Identity-First Access Identity becomes the primary security boundary Not the network perimeter → Device Validation Every device continuously evaluated for trustworthiness → Continuous Authentication Access is revalidated dynamically during active sessions → Least Privilege Access Users and systems receive only the minimum permissions required → Micro-Segmentation Restricting east-west movement across workloads and systems → Policy Engine Enforcement Access decisions enforced dynamically based on context and risk → Threat Detection Continuous behavioural monitoring across users, systems, and environments → Risk-Based Access Trust levels adjusted dynamically using contextual risk signals The leadership mistake many companies make: They treat Zero Trust as a technology deployment. It is not. It is an organizational shift in how trust, access, and risk are managed. Because modern cyber risk is no longer static. Risk changes continuously based on: → user behaviour → device posture → workload sensitivity → identity signals → threat intelligence The organizations scaling securely in 2026 are not asking: “How do we keep attackers out?” They are asking: “How do we continuously validate trust across every interaction?” That is a fundamentally different mindset. And it is becoming essential for: → AI systems → cloud-native environments → hybrid workforces → enterprise ecosystems P.S. Which Zero Trust principle do you think organizations struggle to operationalize most effectively today? Follow Drijesh P. for more insights
-
Most networks are organized, not secured. If you are relying on VLANs for isolation, you don't have a security boundary—you have a filing system. VLANs are great for grouping devices and managing broadcast domains. Over the years, they became the default way we "segment" departments, device types, or operational environments. That design creates the appearance of isolation, but in practice, those boundaries are rarely strict. The "Cardboard Door" Problem Devices inside the same VLAN can typically communicate freely. Once traffic moves between VLANs, we rely on ACLs or firewall policies to control it. But as environments grow, the "rules of engagement" fall apart: - Exceptions are added to support new apps. - "Temporary" policies become permanent. - The rule set expands until it’s impossible to audit. On a network diagram, it looks like a fortress. In operation, it behaves like an open floor plan. Reachability is the Goal From an attacker’s perspective, a VLAN is not a wall—it’s a neighborhood. Once one device is compromised, discovery tools immediately reveal every other system in that segment. Lateral movement becomes possible without ever needing to "bypass" a security control, because the network architecture allows the connection by default. Moving Beyond the Zone VLAN-based designs struggle with Zero Trust because they assume trust is inherited by location. Zero Trust assumes the opposite: every single communication must be explicitly authorized. Trust should not exist simply because two systems share the same segment. Real isolation requires granular control over how devices communicate. Without it, segmentation is just an illusion. Do your segmentation policies truly limit device-to-device communication, or do they mainly organize the network? Nile #ZeroTrust #NetworkSecurity #IoT #ShadowIT #EnterpriseNetworking #CyberSecurity
-
Zero Trust is not a product; it is a fundamental shift in architecture. The core principle is simple: Assume the network is already compromised. Identity is the new perimeter. Trust is never granted implicitly based on physical or network location, but is continuously evaluated through context-aware signals. __________________________________________________________________ Imagine an office where every single door—the breakroom, the supply closet, the server room—has a fingerprint scanner. Even if you are a manager who has worked there for 10 years, you must scan your finger at every single door, every single time. It doesn't matter if you are at your desk or working from a coffee shop; the system asks: "Who are you, and should you be in this specific room right now?" ___________________________________________________________________ The Big Misunderstanding: Zero Trust isn't about "Zero Access." It’s about "Always Verify." It’s not meant to slow you down; it’s meant to make sure a stolen password doesn't lead to a total data breach.
-
📣 WE DID IT 📣 Zero trust is a security paradigm shift that eliminates the concept of traditional perimeter-based security and requires you to "always assume breach" and "never trust but always verify." The updated edition offers more scenarios, real-world examples, and in-depth explanations of key concepts to help you fully comprehend the zero trust security architecture. 📚 Examine fundamental concepts of zero trust security model, including trust engine, policy engine, and context aware agents 📚 Understand how this model embeds security within the system's operation, with guided scenarios at the end of each chapter 📚 Migrate from a perimeter-based network to a zero trust network in production 📚 Explore case studies that provide insights into organizations' zero trust journeys 📚 Learn about the various zero trust architectures, standards, and frameworks developed by NIST, CISA, DoD, and others So happy to put this out into the world. We hope it’s helpful and brings the needed clarity to navigate these murky zero trust waters. Zero Trust Networks: Building Secure Systems in Untrusted Networks 2nd Edition, O'Reilly https://a.co/d/ekPFVdT
-
Zero Trust Architecture: Why Traditional Perimeter Security Is Officially Dead As a Senior Infrastructure Engineer, I’ll say this clearly: If your security model still trusts anything just because it’s “inside the network” — you’re already vulnerable. Zero Trust isn’t a buzzword. It’s the new foundation of modern enterprise security. Zero Trust follows one principle: Never Trust. Always Verify. Every user, device, application, and request is treated as hostile until proven otherwise. Here’s what a true Zero Trust Architecture actually looks like in practice: ✅ Identity is the new perimeter ✅ Continuous authentication & verification ✅ Least privilege access (Just Enough Access) ✅ Device compliance checks before access ✅ Micro-segmentation across network layers ✅ Real-time monitoring & behavioral analytics ✅ Conditional Access policies enforced everywhere ✅ End-to-end encryption and session control No more: ❌ Flat networks ❌ Blind internal trust ❌ One-time login security In the real world, Zero Trust means: Access is granted based on identity + device + location + risk Compromised credentials no longer equal full access Every request is validated in real-time This is how modern enterprises defend against: 🔴 Ransomware 🔴 Insider threats 🔴 Lateral movement attacks 🔴 Identity-based breaches Zero Trust is not a tool. It’s a mindset shift. And infrastructure engineers who understand this will lead the security strategy of tomorrow. Are you still relying on perimeter firewalls alone… or have you started your Zero Trust journey? 👇 Let’s discuss: Where is your organization today on the Zero Trust maturity model? #ZeroTrust #CyberSecurity #InfrastructureEngineering #CloudSecurity #MicrosoftSecurity #EnterpriseSecurity #ITLeadership #NetworkSecurity