Validated Containment Architectures are here. →Explore

In the latest episode of In Progress, host Doug Merritt sits down with John Kindervag, the creator of the Zero Trust model, currently chief evangelist at Illumio and advisor to the Cloud Security Alliance. They traced the path from LAN parties and firewall configurations to federal security mandates, and why most organizations still aren’t doing the basics. 

Convincing the Boss that They Needed a Network So They Could Play Online Doom 

John’s career started in broadcast engineering and television. He fell in love with computer animation after working on a Cray X MP in Los Angeles, the same machine used for the 1984 film The Last Starfighter. He wanted to keep going, but couldn’t afford a Cray of his own, so he learned to build animation computers instead.  

Then the video game Doom came out, and everyone wanted LAN parties. John convinced his boss they needed a network. He pitched it as a business need, though the real reason was multiplayer Doom after work. That’s how he learned the basics of networking.) 

Someone noticed he knew networking, offered him a job that paid better than television, and he jumped. He started with basic router and switch work. Then someone asked if he’d install firewalls and learn penetration testing and IDS. “Sure, why not?” he said. That turned out to be the right call. 

Getting Fired for Putting Outbound Rules on Firewalls 

John’s Zero Trust framework grew directly out of configuring firewalls. At the time, firewalls had a trust model tied to their interfaces. The internal network got a trust level of 100 (highest), the external network got a trust level of zero, and every other interface landed somewhere in between. 

By rule, traffic could flow freely from high trust to low trust without a policy. John saw the problem immediately: if an attacker got in, they could move data out without restriction. He started adding outbound rules to firewalls. 

His argument was simple: he was the pentester, he’d gotten in himself, and there was nothing stopping data from leaving. “All these interfaces should have the same trust level,” he said, “and that trust level should be zero.” 

The problem was that the vendor hadn’t documented it that way and the client didn’t want it. Both got mad. John got in a lot of trouble and ultimately got fired. 

That experience led him to Forrester Research, where analyst George Colony wanted people with hands-on technical skills on the security and risk team. John spent eight and a half years there, combining his years of building systems and “freezing in data centers” into what became the Zero Trust model. 

He credits Steve Mullaney, then CMO at Palo Alto Networks (and later CEO of Aviatrix), as the first person who saw the potential. “Man, this thing has legs,” Mullaney told John. He sent John on global speaking tours and helped promote the concept at a point when it could have faded into obscurity. 

“Trust Is a Vulnerability” 

Doug and John talked about how John created the Zero Trust framework. John’s core argument is that trust is a human emotion with no place on a network. “Trust is a vulnerability,” he said, “because it leads to a lot of these malicious incidents because suddenly you’re on a network and then you can go anywhere on the network.” When you trust a network segment, you allow traffic to flow unchecked. Attackers exploit that allowance. 

The Zero Trust model asks a set of specific questions: What are you trying to protect? Who should have access? Via what application? When should access be allowed? Where is the asset located? Why does this access matter? How do you verify it? 

Rather than trying to protect everything at once, John focuses on what he calls a “protect surface,” a small, well-defined set of assets that matter most. He compares it to how the Secret Service protects the president. “If those people are left alive at the end of the day, the Secret Service has done their job. They’re not there to protect everybody in the entire city.” 

Changing the Way We Incentivize Cybersecurity  

The conversation turned to incentives. John argued that CISOs rarely have the authority to drive change. “The CISO generally doesn’t have the authority to actually get stuff done. They’re just there to throw under the bus when things go bad.” Until CEOs and boards set clear objectives (what the military calls “commander’s intent”) and align incentives to match, security teams will keep optimizing for not getting fired rather than for actual defense. 

John made a direct request to Doug and every CEO: “You and all your CEO friends have to get together and say, ‘we as CEOs need to change the way we incentivize cybersecurity,’” he said. “Unless you come together and create a Manhattan project and say ‘we as CEOs are going to incentivize doing security in the right way,’ it's never going to get done, because everybody's afraid to do it." 

NCTAC Zero Trust Report: Zero Trust in Government 

Doug asked John how he got involved with the NCTAC (National Security Telecommunications Advisory Committee) Zero Trust Report of 2022. John explained how he got involved through a connection with Ross Perot and was ultimately invited to the NSTAC committee and worked on the NSTAC Report to the President on Zero Trust and Trusted Identity Management, released in February 2022. Now, by mandate, every federal agency has to have a Zero Trust program management office, Zero Trust program manager, and a Zero Trust budget.  

“Those three things are three things that commercial entities would do well to adopt,” he said. 

Final Thoughts 

The message from both Doug and John was consistent throughout: Zero Trust isn’t a product, and it’s not something you buy. It’s a strategy built on policy, applied one protect surface at a time, driven by leadership willing to change how security is measured and rewarded. The technology and frameworks exist – what’s missing is the will to act. 

Listen to the full episode. 

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
All Containment is Not Equal

All Containment is Not Equal

Sep 03, 20265 min read
Bedrock Guardrails Won-t Stop an Exfiltrating Agent, But Here's What Will

Bedrock Guardrails Won't Stop an Exfiltrating Agent, But Here's What Will

Sep 01, 20265 min read
Messages that Waited 30 Years: Preparing for Quantum Computing

Messages that Waited 30 Years: Preparing for Quantum Computing

Aug 27, 20268 min read
Frontier AI Critical Defense Program Virtual Patching Buys You Time, Not Reach

Frontier AI Critical Defense Program: Virtual Patching Buys You Time, Not Reach

Aug 26, 202610 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image