Nearly nine in ten security leaders have faced significant challenges in their efforts to implement zero trust, according to a recent Accenture. The comprehensive nature of zero trust deployments, the backlash from department heads and the extremely long time required for meaningful return on investment (ROI) are key factors causing frustration for CISOs.

“Even implementing zero trust, a fundamental security framework, is a significant challenge for 88% of organizations,” the Accenture report says. “This vulnerability extends to the physical world, with 80% unable to effectively protect their cyber-physical systems.”
A big part of the difficulty is that many companies define zero trust very differently. It was never a specification so much as a security approach, although that doesn't mean that many CISOs haven't had significant success in driving zero trust across their organizations.
See also: Security in Computer Networks: VPNs, Firewalls, IDS/IPS and Zero Trust
Furthermore, the fact that every business environment is unique requires a lack of specific implementation details for zero trust: compliance, geography, verticals, and the nature of partners and others who need access to an organization’s systems can vary significantly. At the same time, there are specificities with respect to on-prem, cloud, remote locations, IoT, and other systems.
“It’s a strategic transformation, not a tactical development, and that’s why we’re seeing such widespread difficulty across the industry,” says Prashant Deo, head of the global cybersecurity practice at Tata Consultancy Services.
Deo argues that the zero trust mindset is fundamentally antithetical to the way businesses have always approached security.
“For decades, security has been based on the assumption of implicit trust within the network perimeter. The zero trust model requires a complete reversal of that thinking,” notes Deo. “ Shifting an entire organization to a ‘never trust, always verify’ culture is a significant and difficult change.”

Rex Booth, CISO at Sailpoint, says that confusion over the definition plays a big role in the difficulty of implementing the approach: “Zero trust means different things to different people. We don’t want to narrow down what zero trust means and offer this ideal model as ‘This is the only way to do zero trust.'”
See also: Vulnerability in Azure Active Directory Exposes Credentials
Karen Andersen, identity architect at World Wide Technology, agrees with Booth about the ambiguous nature of the term: “I often think people don’t know what to do with the term. Some say it’s a product, but it means different things to different people. I often think it can be seen as a marketing buzzword, but I believe in the strategy behind it.”
In fact, Andersen is surprised that only 88% of security executives reported finding zero trust difficult to implement. “I want to meet the 12% who didn’t find it difficult,” she jokes.
Zero trust: An endless journey
A truly comprehensive zero-trust deployment could take more than a decade to execute, Andersen says — assuming it's never completed.
“When I explain zero trust [to senior management], I tell them it’s a 10- to 12-year roadmap strategy to really build that foundation,” he says. “I don’t think you ever get to the end of zero trust.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Saleh Hamdan Al-Bualy, who spent years as the director of information security for The Four Seasons hotel chain, is also concerned about the complexity of zero trust and the lack of specific incentives for its implementation.
See also: Critical Qualcomm vulnerabilities allow RCE attacks
“There’s absolutely no incentive to do it,” says Al-Bualy, who currently serves as the security lead for a secretive AI startup and defines zero trust as the opposite of Unix’s trusted host. “It has a chilling effect on the business. You can’t do zero trust unless you fully implement it. Until then, you’re not going to get any of the benefits.”
Al-Bualy emphasizes that the only way zero trust will be successful is if it is promoted from the top down, from the board or CEO to the CISO's office, similar to how Generative AI has been promoted.
“You have to convince the board and the executive team that we need to do it for XYZ reasons,” he says.
