December 9, 2025
371 words, 2 minutes read time
John Kindervag began the concept of Zero Trust; he probably did not realize the impact it would have on the technological community.
Today, we look at the federal government and Zero Trust implementation from 40,000 feet. Kindervag will opine on topics such as browser security, the importance of data, and operational technology.
Instead of using his technical knowledge as a cudgel, Kindervag reinforces the importance of a balanced approach in which federal leaders consider both technological and behavioral aspects of implementing Zero Trust.
People with a basic understanding of Zero Trust can disregard the importance of data; he calls it the ‘protect surface’. This involves identifying and securing the smallest space within the network, as well as the entire network itself.
And so when you use that five step model and compare it to a traditional Carnegie Mellon maturity model, you know the five levels of maturity. You can put that in an orthogonal grid and determine the maturity of a protect surface. I tend to look at the maturity of the Protect surface, not the maturity of the technology, because it just seems to work better. Yeah.
One missing link in the move to Zero Trust is Operational Technology. When looking at the Department of War, it has assets deployed all over the world. They have thousands of sensors that may or may not be part of a network.
Kindervag suggests that when you have a protected surface that is a critical asset, which means it can be included in data sets.
The interview ended with comments regarding the challenges of implementing zero trust, particularly the need for strong leadership and the potential of AI to enhance cybersecurity measures, while acknowledging the complexities of data classification and the evolving threat landscape.

