Zero Trust Adoption Lagging Despite Rising Cyberattack Costs, TechRadar Reports
According to TechRadar, cyberattacks are causing billions in losses, yet only 35% of companies have implemented Zero Trust security, exposing a critical gap.
Artificial intelligence has given anyone with a computer, tablet, or smartphone easy access to automation, including malicious actors. This allows them to continually change their approach, scale their efforts, and exploit vulnerabilities in target software. The impact is already visible. In October, the Cyber Monitoring Centre reported that a cybersecurity incident affecting Jaguar Land Rover in August cost the UK economy an estimated £1.9 billion. In North America, WestJet's June cyberattack led to the theft of 1.2 million passengers' data, and the data of 1.5 million flyers are believed to have been compromised following September's attack on Collins Aerospace.
Public trust is also declining. Research released earlier this year showed that when consumers were asked which industry they trusted with their data, no single sector received an approval rate above 50%. Without a clear and modernized security strategy, businesses are left vulnerable to reputational damage, operational delays, and financial loss.
The Zero Trust principle, emphasizing "never trust, always verify," was popularized by John Kindervag in 2009, building on the work of the Jericho Forum, which later became part of The Open Group Security Forum. As Gartner's Neil MacDonald explained, "Zero Trust is not a technology; it's a security philosophy that rewires how we think about access." Yet implementation remains low.
Traditional approaches, such as over-reliance on VPNs, drew a single perimeter around data, allowing criminals to steal from across the organization once breached. In contrast, Zero Trust confines access to the specific section where an incident occurs. Successful implementation requires risk evaluation on a case-by-case basis, with deliberate decisions to accept, mitigate, or transfer risk.
Security infrastructure must also be dynamic. At any point, a key tech stack component can become a target, so security professionals should track attempts and techniques used and amend infrastructure accordingly.
Cybersecurity budgets are growing. IDC's Worldwide Security Spending Guide in March predicted a 12.2% spending increase in the following year, reaching $377 billion by 2028. However, organizations need to ensure this investment is not a one-off; every element and everyone's access must be continually questioned.
To drive long-term resilience and embrace Zero Trust, vendor-neutral definitions of methodology and standards will be necessary. Once widely acknowledged, a commitment should be made to continuous improvement.