Skip to main content
Cybersecurity

Never Trust. Always Verify: The Origin of Zero Trust

In 2004, a group of security professionals met in London and declared that the network perimeter was already dead. It took the rest of the industry fifteen years to agree. The story of how Zero Trust went from radical heresy to US government policy.

Artiflex IT Security Practice·CISO Advisory & Compliance
··7 min read
Never Trust. Always Verify: The Origin of Zero Trust

In 2004, a small group of senior security professionals gathered in London under the banner of the Jericho Forum and declared that the network perimeter was already dead. The industry treated the statement as heresy. It would take fifteen years before the same idea, rebranded as Zero Trust, became mainstream architectural orthodoxy, and twenty years before it became codified US federal policy. The history of Zero Trust is the history of an idea that was correct on arrival and merely waiting for the rest of the world to catch up.

The Jericho Forum: The Perimeter Is Already Gone

The Jericho Forum was founded in 2004 by senior CISOs from major international corporations who were tired of pretending that the firewalled corporate network was a meaningful security boundary. They named themselves after the biblical city whose walls famously fell, and they argued that the corporate walls had already fallen in practice even if nobody was willing to say so out loud. Their thesis was simple: the perimeter as a security construct was an illusion, and the longer the industry pretended otherwise, the longer it would delay the architectures that were actually needed.

In 2007, the Forum published the Jericho Forum Commandments, eleven design principles for what they called de-perimeterisation. The commandments insisted that security must be inherent to data and transactions rather than to the network around them, that all devices must be considered untrusted by default, and that identity, authentication and authorisation must travel with the user and the data rather than being asserted by the network. The principles were largely ignored at the time. They were also, in hindsight, almost entirely correct.

The perimeter did not collapse in a single moment. It dissolved gradually through SaaS adoption, mobile devices that left the office every evening, API integrations between corporate systems and outside services, and remote contractors who needed access without ever stepping into the building. By 2010, the perimeter model was already insufficient to describe what was actually happening on most enterprise networks. The industry simply had not yet built the language or the tooling to admit it.

The Jericho Forum in 2004 said what nobody wanted to hear: the perimeter is an illusion. Six years later, Google's BeyondCorp project proved they were right. Six years after that, the US government made Zero Trust federal policy. The ideas were correct all along. They just needed a decade and a half to become undeniable.
, The slow vindication of de-perimeterisation

John Kindervag Gives a Concept Its Name, and a Framework

In 2010, John Kindervag, then a principal analyst at Forrester Research, published a paper titled "No More Chewy Centers: Introducing The Zero Trust Model Of Information Security". The paper crystallised what the Jericho Forum had argued in principle and gave it a name that would stick. Kindervag's framing was the now-famous M&M shell analogy: enterprises had built networks that were hard and crunchy on the outside, but soft and chewy on the inside, so that any attacker who breached the perimeter found themselves inside a flat, trusted environment with little resistance.

Kindervag's framework proposed three structural shifts. Micro-segmentation would replace the flat internal network with small, individually defended zones. Identity verification would happen at every boundary rather than once at the edge. Least privilege would govern every access decision rather than being granted broadly by network location. The model was clean, defensible and prescriptive enough for organisations to begin implementing in concrete steps.

Google had already been building exactly this architecture internally since 2010, prompted by the Operation Aurora breach of 2009 in which Chinese state-sponsored attackers had compromised Google's corporate network and several other large technology companies. Google's response was to abandon the corporate VPN and the trusted internal network entirely. They published the architecture in 2014 under the name BeyondCorp, and it became the first proof of concept that Zero Trust principles worked at the scale of a global enterprise with tens of thousands of employees.

Twenty Years from Heresy to Policy

2004, Jericho Forum Founded

Senior CISOs convene in London and declare the network perimeter dead. The Jericho Forum begins publishing the design principles for de-perimeterisation that the rest of the industry will spend the next two decades catching up to.

2009, Operation Aurora, Google Breached

Chinese state-sponsored attackers compromise Google's corporate network in a multi-month operation that also targets Adobe, Juniper, Rackspace and at least thirty other major technology firms. Google's response is to rethink network security from first principles rather than patch the existing model.

2010, Kindervag Coins Zero Trust

John Kindervag publishes the Forrester paper that gives the de-perimeterisation movement its name and its first concrete framework. Zero Trust, as a phrase and as an architecture, enters the industry vocabulary.

2014, Google Publishes BeyondCorp

Google releases the first of six BeyondCorp papers describing how it eliminated the corporate VPN, removed all implicit trust from the internal network, and authenticated every request based on device posture and user identity. The papers become the canonical reference for Zero Trust at scale.

2018, Vendors Adopt Zero Trust Positioning

Cisco, Microsoft, Palo Alto Networks, Zscaler, Akamai and dozens of others rebrand or reposition product lines under the Zero Trust banner. The marketing layer arrives well ahead of the engineering reality at most customers, but the centre of gravity is unmistakably shifting.

2020, NIST SP 800-207 Published

NIST publishes Special Publication 800-207, the first formal standard defining Zero Trust Architecture for federal use. The document gives architects a vendor-neutral reference model and ends a decade of arguments about what Zero Trust actually means.

2021, Biden Executive Order, Zero Trust Federal Policy

The May 2021 Executive Order on Improving the Nation's Cybersecurity directs every US federal agency to adopt Zero Trust Architecture using NIST SP 800-207 as the reference. CISA publishes the Zero Trust Maturity Model in 2022 and OMB sets agency targets for Fiscal Year 2024.

Today, Zero Trust as Default Architecture

In 2026, Zero Trust is the default architectural posture for new enterprise deployments. SASE, SSE, ZTNA, conditional access, micro-segmentation and identity-aware proxies are all expressions of the same underlying model. The argument is no longer whether to adopt Zero Trust; it is how mature the implementation is.

The pandemic did more for Zero Trust adoption in twelve months than a decade of analyst reports. When every employee became remote overnight, the VPN-based perimeter model collapsed under its own weight. Organisations that had invested in Zero Trust infrastructure sailed through. Organisations that had not spent 2020 trying to scale VPN capacity they had never anticipated needing.
, Why COVID-19 was the biggest Zero Trust adoption catalyst in history

Share this article

Need help applying any of this?

Our engineering team works with UAE businesses on the exact problems we write about. Real conversations, no sales theatre.