Skip to content
Scan a barcode
Scan
Paperback The Zero Trust Gap: What Zero Trust Really Demands, and Why So Many Programmes Fail Book

ISBN: B0HDK8H572

ISBN13: 9798190773569

The Zero Trust Gap: What Zero Trust Really Demands, and Why So Many Programmes Fail

Most Zero Trust programmes deliver less than they promised. The reasons are predictable, and almost none of them are technical.

The gap in the title is a literal one. In every incident this book examines, the organisation already had the control. It was present in the architecture and absent from one path, and that path became the incident.

The British Library's on-premise domain. Colonial Pipeline's legacy remote access. Change Healthcare's Citrix portal. A forgotten test tenant inside Microsoft. In six of the ten cases the missing control was a second factor, and in at least two the organisation had already identified that gap and formally accepted it.

This is a practitioner's guide, written by a hands-on cyber security manager with fifteen years in high-assurance and regulated environments, who leads a team spanning information assurance, architecture and engineering. It argues that Zero Trust is the right model, that most implementations of it fall short, and that the reasons are budgetary, political and operational rather than architectural.

WHAT MAKES THIS DIFFERENT

It is built on evidence, not assertion. Ten documented incidents from 2021 onwards, several taken from the affected organisation's own post-incident report or from sworn testimony to a legislature. Every claim carries a source. Where a source could not be verified, the book says so.

It prices every recommendation. Each chapter states what its advice genuinely demands, measured in people, in months of discovery work and in change appetite rather than in licence fees. You will not find prices here, because licence costs vary by an order of magnitude and would be wrong within a year. You will find the costs that actually decide whether a control survives contact with an organisation.

It argues against itself. Every chapter gives the opposing case its own section, in its strongest form. One chapter is devoted entirely to where the model fails, including a table stating incident by incident whether these controls would have prevented it. In three cases the answer is no. That chapter also sets out the four things that would change the author's mind.

WHAT IT COVERS

Identity, and the four ways multi-factor authentication is genuinely defeated. Why phishing-resistant credentials do not solve help desk impersonation. Network segmentation, and why programmes stall before enforcement. Endpoints, including what July 2024 revealed about uniform agent deployment. Applications, and the trap in fronting a legacy system with a proxy. Data, and why encryption at rest protects against the wrong thing. Sequencing, funding models, and what to tell a board. What has to be operated afterwards, and what regulators actually ask for. And what to do in the first week, month, quarter and year.

WHO IT IS FOR

Security architects, CISOs and technology leaders who have to defend a strategy to a board. The engineers who have to build it afterwards and usually discover the parts nobody costed. Risk, audit and compliance professionals who need to know what Zero Trust actually evidences, as opposed to what it implies.

It assumes you know what a firewall does. It does not assume you have implemented any of this before.

UK regulatory frame throughout, with US and EU instruments named where they apply.

Short by design. The argument is complete, and padding it would not have improved it.

Recommended

Format: Paperback

Condition: New

$19.99
Ships within 2-3 days
Save to List

Customer Reviews

0 rating
Copyright © 2026 Thriftbooks.com Terms of Use | Privacy Policy | Do Not Sell/Share My Personal Information | Cookie Policy | Cookie Preferences | Accessibility Statement
ThriftBooks ® and the ThriftBooks ® logo are registered trademarks of Thrift Books Global, LLC
GoDaddy Verified and Secured