not an IT project.
Frequently Asked Questions
Why is Zero Trust a governance decision rather than an IT project?
Boards are now legally accountable for cyber posture under NIS2, DORA, and GDPR. Gartner's 2025 research states that organisations without a Zero Trust architecture cannot meet modern cyber resilience requirements.
How much can Zero Trust reduce data breach costs?
The average data breach costs €4.5M. Organisations with a mature Zero Trust posture reduce that exposure by 50–75%.
Did a government body adopt Zero Trust as an official standard?
Yes. The US National Security Telecommunications Advisory Committee's report to the President cited “John Kindervag, ON2IT BV” three times as the primary authority. The Five-Step Process, the Maturity Model, and the Kipling Method became the official US Government implementation standard.
What questions should a board be able to answer about Zero Trust?
Among others: whether Protect Surfaces have been mapped and reviewed in the last 12 months, what a successful breach would cost financially and reputationally, and who on the board owns the Zero Trust governance mandate.
How long has Zero Trust been used in practice?
Zero Trust has more than 20 years of practical application behind it, and is now the number one US Federal Zero Trust authority's reference framework.