Every security category eventually lands on Zero Trust
No matter which way you spin security - for agents, cloud, endpoints, etc - you’ll eventually end up on the zero trust.
Firewalls? ❌ Don’t trust outside resources
Microsegmentation? ❌ Don’t trust inside resources either
EDR? ❌ Don’t trust processes local processes
CNAPP? ❌ Don’t trust cloud processes either
IAM? ❌ Don’t trust your own workforce
Password managers? ❌ Don't trust your memory
Rene Descartes? ❌ Don't trust yourself
Agent security? ✔️ Nah boy you just YOLO that shit
Funnily enough, I don’t get (or like) explicit zero trust products like ZTNA, because ZT will always end up being the outcome. What you need to do instead is define smarter and more frictionless ways of reaching that zero trust sweet spot.
Here are the four natural ways I could fit in a silly graphic to reach zero trust:
Obfuscate resources
Learn production behavior
Preventative policies
Policy decision points
Obfuscate resources
These are separate Control/Data plane solutions where only explicitly allowed connections are exposed to each resource. Otherwise a resource cannot see other entities to perform lateral movement. It’s Zero Trust networks as they should have been in the first place. They mainly use VPNs like Wireguard, and the smart thing is in the control plane. It’s a pretty heavyweight solution, so expect some engineering effort to go with its deployment.
You can look the likes of NetFoundry, TailScale, and Twingate.
Learn production behavior
Assuming you’re not already compromised, you can monitor how your environment behaves today, and then define policies. This is becoming an increasingly common pattern, but I’ve seen the ones from AccuKnox, Tigera, and ARMO. In addition to writing policies based on your in-production behavior (so it doesn’t break anything), these solutions also deploy best-practice policies based on frameworks and best practices, like don’t expose your DB to the public internet.
Preventative policies
These guys looked at your cloud environment configuration to determine whether your effective policies expose you to any attacks. I’ve been working with the folks at Native and they do some really cool and forward-looking stuff with cloud security. Some other folks that market themselves in this category include Blast Security and Aryon Security.
Policy decision points
Paritcularly important for agent actions, these evaluate an action against a set of policies to allow/deny/alert/escalate. These solutions manage access and permissions across cloud and on-prem entities. You can look at folks like P0, Permit.io, Teleport, and Cerbos.



