A compliance auditor asked one question last month that stopped the room.
The setting was a healthcare estate three months into a segmentation rollout. Group-based policy was landing cleanly. Identity was mapped. East-west traffic was inspected and locked down. Audit trails were flowing where the compliance team wanted them. The board deck was ready to be walked through, and the risk register was smaller than it had been in years.
Then the auditor, from the client's parent group, asked how the crypto in transit would hold up in five years, once harvest-now-decrypt-later became a real timeline for regulated data. His point was that the segmentation, however clean, sat on top of a layer nobody in the room had worked on with the same discipline. That layer was the one exposed to the five-year horizon.
Nobody in the room had a good answer, because the architecture didn't contain one.
The shift I keep bumping into now, across pharma, healthcare, and regulated ITES estates: Zero Trust segmentation isn't the frontier anymore, it's the floor. What isn't settled is the layer above. That layer is the data protection sequencing, the crypto estate ahead of PQC, and how fast AI is going to change what an attacker can do at machine speed for almost nothing. That's the ground I'm moving toward.
So I'm widening the lens. Same first-person register, same field-first bias, broader ground. AI security and post-quantum readiness. Cisco portfolio field notes from the pre-sales seat, including where the platform I sell is the right answer and where it isn't. Security architecture patterns that carry across vendors. And the resilience stack that sits alongside Zero Trust: data protection sequencing, threat modelling for enterprise, PQC migration. The newsletter is coming too. It's now called The Security Practitioner. Fortnightly. Next issue on the 27th of August.
If you're running a Zero Trust or SSE rollout in a regulated environment right now, or you're a pre-sales SE at a competing platform who reasons differently about where the enforcement point should sit, or a CISO who has already crossed the layer above segmentation and figured out what mattered on the other side, or a threat modeller who thinks I've got the sequence wrong on which layer above segmentation matters first, I'd particularly like to hear from you.
For folks 3-7 years into security architecture: what widened your lens most, and what pattern do you wish you'd started tracking a year earlier?
Softened for confidentiality. Views my own.
#Cybersecurity #ZeroTrust #AISecurity #CiscoIndia