ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Zero Trust · Is our organisation secure? Here's how to know.
Zero Trust is a governance decision,
not an IT project.
The boards that treat cybersecurity as a technology problem keep funding the wrong thing. Zero Trust reframes security as a trust governance mandate — one that protects what matters, provably, at scale. This is the research that makes the case.
For Boards · CEOs · CFOs · CISOs · Investors
The Resilience Mandate
Gartner 2025: organisations without a Zero Trust architecture cannot meet modern cyber resilience requirements. Resilience and Zero Trust are no longer separate tracks.
The Governance Mandate
Boards are now legally accountable for cyber posture under NIS2, DORA, and GDPR. Trust governance belongs in the boardroom — not delegated down to IT.
The Financial Mandate
The average data breach costs €4.5M. Organisations with mature Zero Trust postures reduce that exposure by 50–75%. The CFO conversation has changed.
Board Briefs
Authority Research for Executive Leadership
Governance intelligence for boards, CISOs, CFOs, and the C-suite
4 briefs · 6–15 min each
From the Governance Brief · Seven Questions
What every board should be able to answer
01Do we know exactly what data and systems are most critical to protect?
02Have we mapped our Protect Surfaces — and reviewed them in the last 12 months?
03What would a successful breach cost us — financially and reputationally?
04Are we compliant with NIS2, DORA, or GDPR requirements for cyber governance?
05Does our security programme have an architecture, or just a set of products?
06Can we demonstrate Zero Trust progress to regulators and insurers?
07Who on the board owns the Zero Trust governance mandate?
Not able to confidently answer these questions? Talk to a Zero Trust expert →

Frequently Asked Questions

Why is Zero Trust a governance decision rather than an IT project?

Boards are now legally accountable for cyber posture under NIS2, DORA, and GDPR. Gartner's 2025 research states that organisations without a Zero Trust architecture cannot meet modern cyber resilience requirements.

How much can Zero Trust reduce data breach costs?

The average data breach costs €4.5M. Organisations with a mature Zero Trust posture reduce that exposure by 50–75%.

Did a government body adopt Zero Trust as an official standard?

Yes. The US National Security Telecommunications Advisory Committee's report to the President cited “John Kindervag, ON2IT BV” three times as the primary authority. The Five-Step Process, the Maturity Model, and the Kipling Method became the official US Government implementation standard.

What questions should a board be able to answer about Zero Trust?

Among others: whether Protect Surfaces have been mapped and reviewed in the last 12 months, what a successful breach would cost financially and reputationally, and who on the board owns the Zero Trust governance mandate.

How long has Zero Trust been used in practice?

Zero Trust has more than 20 years of practical application behind it, and is now the number one US Federal Zero Trust authority's reference framework.