MultiHub Forum

Full Version: Phased Zero Trust rollout: prioritizing workloads and identity for legacy apps
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
I'm a network security architect at a mid-sized company, and we're beginning a major project to transition from our traditional perimeter-based security model to a Zero Trust Architecture, driven by our shift to hybrid work and cloud services. While I understand the core principles, I'm grappling with the practical phased implementation, especially around identity management and segmenting our legacy on-premise applications. For teams who have undertaken this journey, what were your biggest technical and cultural hurdles in the first year, and how did you prioritize which workloads or user groups to migrate first to demonstrate value and build internal buy-in without causing major disruption to business operations?