ON2IT - Zero Trust Innovators

Select your region

Talk to us →
← Back to blog Zero Trust

Zero Trust Governance: 7 Questions Every Board Must Ask

September 21, 2026 · 18 minutes read · By Tim Timmermans

Zero Trust is not a technology decision. It is a trust governance decision. That distinction is not semantic, and it is the reason most Zero Trust programs stall somewhere between the purchase order and the audit.

This article is drawn from The Zero Trust Cybersecurity Handbook: Redefining Trust in a Digital Era by Tim Timmermans and Yuri Bobbert, and from the way ON2IT operationalizes it through Zero Trust as a Service, the AUXO™ Zero Trust Platform and the GSOC. It is written for the people who have to answer for cyber resilience: the board, and the CEO, CRO, CIO and CFO who report to it.

Situation, Complication, Resolution

Situation

Digital transformation has created environments organisations were never designed to operate in. Technical debt consumes roughly 42% of developer capacity (Stripe, The Developer Coefficient, 2018) and diverts 10 to 20 percent of the technology budget earmarked for new products (McKinsey, 2020). The average breach now costs $4.99M and takes 247 days to identify and contain (IBM Cost of a Data Breach, 2026). Implicit trust, wired into every legacy system, is no longer a design choice. It is a liability.

Complication

Cybersecurity is no longer an IT issue. Boards are held accountable for resilience, regulatory compliance and financial sustainability. DORA, NIS2, GDPR and the SEC disclosure rules have created a compliance treadmill organisations cannot step off. Gartner predicted in January 2023 that by 2026 only 10% of large enterprises would have a mature and measurable Zero Trust program, up from less than 1%. The gap between stated posture and actual control is where breaches occur.

Resolution

Zero Trust, operationalized as a governed discipline rather than a technology project, is the answer. The handbook provides the strategic framework, refined across hundreds of ON2IT implementations. ON2IT's Zero Trust as a Service delivers it as a managed operating model through AUXO and the GSOC, removing the implementation burden from internal teams.

Decision required

Two governance questions have to be resolved before execution. First: what is the organisation's acceptable residual risk threshold? That defines the boundary between managed risk and board liability. Second: in a major breach, does response authority remain internal, or is execution delegated? The regulatory clock starts at detection, not at decision.

Zero Trust is not just an IT strategy. It is a business imperative. Boards that invest in it today will build organisations that are secure, scalable, and trusted by regulators, customers, and investors alike.

Timmermans & Bobbert, The Zero Trust Cybersecurity Handbook

Or, put the way it lands in a boardroom: our technical debt is not a backlog problem. It is a liability on the security balance sheet, and Zero Trust is the only operating model designed to price it correctly.


Eight Forces Breaking Security Today

The handbook opens with a structural diagnosis. Organisations can no longer rely on implicit trust, perimeter thinking, or incremental improvement. Eight forces have conspired to make the previous era's security model inadequate. Each one is simultaneously a failure of the old model and a design requirement that Zero Trust was built to address.

Architectural entanglement

Enterprises operate in a dense spaghetti of cloud services, APIs and legacy components. Data flows are unclear. The architecture itself is the threat surface.

Security tool overload

Organisations accumulate dozens of isolated tools, each solving a fragment of the problem. The result is noise, redundancy and operational exhaustion, not protection. Tools without architecture are expensive decoration.

Visibility fragmentation

Fragmented architectures and tool sprawl create blind spots. Leaders lack real-time visibility across users, devices, data and workloads, which is exactly what attackers count on.

Executive misalignment

Cybersecurity has become so overloaded with jargon and technical nuance that executives cannot see the core risk. The Knowing-Doing Gap opens between boardroom awareness and operational action.

Erosion of digital trust

As breaches escalate, trust in digital operations weakens. Regulators demand more proof. Customers expect more assurance. Boards face increasing accountability with decreasing visibility.

Regulatory inflation

DORA, NIS2, GDPR and SEC rules create a compliance treadmill organisations cannot step off. Requirements intensify faster than the ability to meet them. Compliance is now a board-level business driver, not an IT project.

Legacy bias in security leadership

Many strategies remain rooted in perimeter-based thinking, protecting networks rather than protecting value. The last era's playbook fails against today's adversaries and tomorrow's regulators.

Moore's Law meets Murphy's Law

As compute power and automation grow exponentially, the speed and scale of failure grow with them. When Murphy's Law strikes in a hyperconnected system, the blast radius is no longer containable by legacy controls.

Board signal

The security strategy built for the last era is the structural risk we carry into the next one.

Why Cybersecurity Is Now Board Accountability

Several converging forces have moved cybersecurity from the IT basement to the boardroom. The handbook is explicit: cybersecurity is now a core business activity for competitive differentiation, regulatory compliance and stakeholder trust. High-profile breaches ended CEO tenures at Target, where Gregg Steinhafel stepped down in 2014, and at Equifax, where Richard Smith retired in 2017. At Yahoo the consequences landed differently but no less clearly: the General Counsel resigned, and the CEO forfeited roughly $14M in bonus and equity. Director liability is real, and it is growing.

Digital transformation expanded the attack surface. Cloud adoption, IoT and OT integration, remote work, AI and SaaS dependence mean more systems, more interconnections and more risk vectors, without a commensurate increase in control.

Regulations are now business drivers. GDPR, NIS2, DORA, HIPAA and PCI DSS require proof of protection, incident reporting and demonstrated governance. Non-compliance is a financial and reputational event, not an audit finding.

Customers and partners demand verifiable trust. Organisations that achieve strong security can safely adopt AI, cloud, automation and new business models. Zero Trust is not a brake on digital transformation. It is the precondition for it.

Board signal

Cybersecurity is no longer about keeping attackers out. It is about remaining trusted, compliant and operational while they try.

What Zero Trust Actually Is

Zero Trust is not a product. Across NIST SP 800-207, the CISA maturity model and the academic literature the working definition is consistent enough to state plainly: Zero Trust is a cybersecurity strategy that prevents data breaches and limits the impact of attacks by removing implicit trust from digital systems. It assumes breach by default, and it protects assets through continuous validation and strict access control rather than trying to reduce risk after the fact.

In practical terms, Zero Trust requires that all interactions between users, devices, applications and services are verified before access is granted; that all network traffic is inspected; that data sets are segmented to limit blast radius; and that configurations are continuously monitored. It operates on one non-negotiable principle: never trust, always verify.

Principle 01 · Redefine trust

No user, device or service is trusted by default, ever. Continuous verification replaces implicit trust at every layer.

Principle 02 · Remove implicit trust

Strip implicit trust from legacy infrastructure. Access by network position must be redesigned around verified access.

Principle 03 · Continuous verification

Access is verified on every interaction, not once at login. Posture, context and behaviour are assessed continuously.

Principle 04 · Assume breach

Design controls as if compromise has already occurred. Limit blast radius, enforce least privilege, contain lateral movement.

Board signal

Zero Trust does not ask whether attackers can get in. It asks: when they do, how little can they reach?

From Framework to Operating Model: The Five Steps

The handbook's five-step implementation model has been refined across hundreds of ON2IT deployments and aligns with NIST SP 800-207, CISA's Zero Trust Maturity Model and Forrester's ZTX framework. The starting point is always the same: identify what you are protecting, not where the perimeter is. ON2IT's Zero Trust as a Service delivers this model as a managed, outcome-based operating model through AUXO and the GSOC, removing the implementation burden from internal teams already stretched by technical debt.

1

Define the Protect Surface

Identify high-value assets, applications and services, the DAAS elements: Data, Applications, Assets, Services. A Protect Surface is the inverse of an attack surface: small, defined and defensible. Each surface is scored on confidentiality, integrity, availability, audit obligation, business criticality and fraud risk. The Relevance Score determines the required level of protection. This is how Zero Trust inverts the model: the Protect Surface is small, the attack surface is vast.

2

Map transaction flows

Document all interactions between DAAS components using App-ID, User-ID and Content-ID. Transaction flow mapping is the precondition for policy precision, and for the SOC to detect anomalies against a known baseline. Without flow mapping, no policy can be written with precision. This is where architecture becomes visible, often for the first time.

3

Build the Zero Trust architecture

Design and implement security measures based on identified Protect Surfaces and their Relevance Scores. ON2IT maintains a comprehensive repository of vendor-agnostic security measures, mapped to MITRE mitigations, ISO 27001, NIST CSF and PCI DSS, from which architects select based on context and proportionality. AUXO operationalizes this across six management disciplines: identify, protect, detect, respond, recover and govern.

4

Create Zero Trust technical policies

Access conditions are defined using Who, What, When, Where, Why and How, the Kipling 5W+1H method. Policies are narrow, specific and least-privilege by design. A policy allows only what is functionally necessary, nothing more. This is how implicit trust is eliminated at the policy layer, not just the network layer.

5

Monitor and maintain via the GSOC

Once Protect Surfaces, measures and policies are in place, the Zero Trust environment is handed to operations. ON2IT's GSOC, a Zero Trust-native managed security operations centre, provides continuous monitoring, anomaly detection and log analysis against a defined Zero Trust baseline. In a breach, the SOC directly initiates CSIRT with full chain-of-custody documentation from detection through recovery.

Board signal

Zero Trust as a Service converts a capital-intensive security transformation into a governed, outcome-based operating expenditure. Zero Trust is not a project that ends. It is a discipline that runs, and the GSOC is how we prove it at every audit.

The Maturity Gap: 90% Carrying Unpriced Liability

Gartner predicted in January 2023 that by 2026 only 10% of large enterprises would have a mature and measurable Zero Trust program, up from less than 1% at the time. Which means roughly 90% carry the liability of stated Zero Trust intent with incomplete Zero Trust execution. Most organisations have purchased Zero Trust components. Few have operationalized Zero Trust as a continuous management discipline. The gap between policy and architecture is precisely where breaches occur, and where regulators are increasingly focused.

AUXO is designed precisely for this gap. It provides the governance scaffolding that turns point solutions into a coherent control environment.

Board signal

Having Zero Trust tools is not the same as having Zero Trust posture, and auditors, insurers and regulators are beginning to know the difference.

What Each Executive Is Accountable For

The handbook maps the specific challenge, failure mode and Zero Trust outcome for each C-suite role. Cyber resilience is not a CISO problem. It is a board accountability distributed across four roles, each with a distinct job that Zero Trust is the only operating model capable of doing.

CEO · Fragile systems and unprepared boards

A single ransomware attack, data breach or supply chain compromise can halt operations, damage customer trust and erode shareholder value. Regulators and investors expect CEOs to demonstrate cyber resilience as part of corporate governance. The departures at Target and Equifax established the accountability precedent.

Zero Trust outcomeLimits blast radius, improves ESG ratings, and provides a governance framework that aligns leadership vision with operational execution.

CRO · Silent and residual risks stay unseen

Traditional risk models fail to account for dynamic digital threats. The Knowing-Doing Gap, where risk awareness does not translate into action, is where material breaches occur. Silent risks (unnoticed vulnerabilities) and residual risks (incomplete mitigations) expose the organisation to unquantified losses.

Zero Trust outcomeLowers risk exposure, enhances real-time risk visibility through SOC and CSIRT data, and reduces cyber insurance premiums through documented risk management practices.

CIO · Small incidents, high impact

Perimeter-based security fails to stop lateral movement. The average breach still takes 247 days to identify and contain. A single unpatched system or misconfigured service can provide unrestricted access to business-critical systems. Cloud expansion amplifies every gap.

Zero Trust outcomeEliminates implicit trust and prevents lateral movement, improves regulatory compliance, and demonstrates "in control" status at audits, almost in real time.

CFO · Spend is rising, ROI is unclear

Costly point-solution investments without integration. Expensive tools that remain underutilised or overlap. No financial transparency on how cyber investments translate into risk reduction. Insurance premiums rising, with insurers demanding proof of robust practices before providing coverage.

Zero Trust outcomeEliminates redundant tools, converts CapEx-heavy transformation into governed OpEx, and reduces unexpected cybersecurity expenses and insurance premiums.

Board signal

Zero Trust is not just an IT strategy. It is an organisational function that requires embedding at every layer: strategic, managerial and operational.

The Cultural Reframe: From Implicit Trust to Continuous Verification

The handbook is unambiguous: the primary failure mode in Zero Trust programs is not technical, it is organisational. Forrester's research consistently identifies change management, not technology integration, as the leading cause of Zero Trust program delays. Zero Trust requires a fundamental shift in how every user, workflow and vendor relationship is understood. The shift is visible at every level.

Previous eraZero Trust
Implicit trust as default in all systems and relationshipsContinuous verification as the non-negotiable baseline
Protect everything at the perimeterProtect Surface discipline, safeguard what matters
Security as an IT function with a compliance mandateSecurity as board accountability with a governance mandate
Tool accumulation, solving fragments of the problemCoherent architecture, vendor-agnostic measure repository
Annual compliance checkboxContinuous, measurable cyber resilience, defensible in real time
Knowing-Doing Gap, risk awareness without architectural responseStrategic, managerial and operational alignment, simultaneously
Reactive breach recovery after the clock startsProactive Protect Surface management with pre-assigned response authority

ON2IT's CSIRT and GSOC teams operate as embedded partners, not just service providers, which means the cultural transition is shared rather than delegated.

Board signal

Zero Trust fails in the org chart before it fails in the architecture.

When It Happens: CSIRT and the Six Response Phases

The governance question the board must answer before a breach is: who decides, and who executes? The CSIRT follows the cybersecurity incident response process across six defined phases, each with its own activities, outputs and board implications. The regulatory clock, under NIS2, DORA, GDPR and SEC disclosure rules, starts at detection, not at confirmation.

ScenarioON2IT roleGovernance implication
PreventionAUXO reduces blast radius through continuous microsegmentation and least-privilege enforcementInvestment tolerance versus residual risk acceptance
Active responseGSOC and CSIRT execute live containment; speed of isolation is the primary metricOperational disruption versus threat spread velocity
Major breachCSIRT leads forensic integrity; the regulatory clock starts at detectionInternal control versus delegation to ON2IT capability
1

Preparation

Hire and train for failure, not just prevention. Communication plans, response procedures and handling checklists must be periodically tested, not filed. The board must ensure preparation resources are funded and exercised. An untested response plan is an unpriced liability.

2

Identification

The regulatory clock starts here. Advanced automated detection through the SOC. 24/7 incident reporting capability. Priority, severity and impact classification begin at the moment of identification, not confirmation. Zero Trust's continuous monitoring directly compresses the 247-day industry average for identifying and containing a breach.

3

Containment

Zero Trust microsegmentation makes this phase bounded rather than organisation-wide. Protect Surface architecture limits the blast radius to the compromised segment. Evidence is secured and chain-of-custody documentation begins. Speed of isolation is the primary driver of breach cost reduction.

4

Eradication

Clean-up and removal of attack traces, infections and backdoors, bounded by the Protect Surface that contained the blast radius. Additional investigation determines whether other surfaces are affected. The Zero Trust architecture means eradication is surgical, not systemic.

5

Recovery

Business continuity, not just technical restoration, is the recovery target. Systems return to operation with a final sanity check and intensified monitoring. The key measures: how fast did operations resume, was the regulatory reporting window met, and was the board informed in the right sequence?

6

Post incident

Root cause analysis produces Security Improvement Advisories. The board receives a structured post-incident report, the governance artefact regulators will request. This is where the Knowing-Doing Gap closes, or does not. The organisation emerges with a stronger posture than it entered with.

Board signal

The governance design for a major breach must be decided in the boardroom today, not in the war room tomorrow. Pre-assigned decision authority is the difference between a managed crisis and a regulatory failure.

Seven Questions Every Effective Board Must Ask

Section 4 of the handbook provides the board's governance toolkit: seven questions structured across strategic, managerial and operational layers. These are not rhetorical. They are the questions that distinguish boards that govern cybersecurity from boards that are merely informed about it.

1. What are our most valuable digital assets, our Protect Surfaces, and how are we protecting them?

Strategic. Identifying and securing high-value assets is the foundation of cybersecurity strategy. You cannot govern what you have not defined. Protect Surface definition is the first act of Zero Trust implementation and the first governance accountability of the board.

2. How does the board actively support cybersecurity strategy, and what does the CISO need from us to be effective?

Strategic. Cybersecurity is a leadership responsibility. Boards must move beyond compliance checklists and actively shape security strategy, governance and resource authority, not just IT budget approval.

3. Do we have clear visibility into our silent and residual risks?

Strategic. The Knowing-Doing Gap begins here. Silent risks and residual risks are the attack surface regulators are now auditing specifically. Boards need proactive risk oversight, not annual summaries of last year's posture.

4. What cybersecurity KPIs are we tracking, and do they measure resilience rather than just prevention?

Managerial. Dwell time, blast radius, recovery speed and regulatory reporting compliance are resilience KPIs. "Number of tools deployed" is not. Boards must ensure that cybersecurity performance is measurable, aligned with strategic goals and continuously optimised.

5. When did we last simulate a major breach, and what did we change as a result?

Managerial. An untested incident response plan is an unexercised governance assumption. The answer to this question reveals the real state of resilience readiness, not the stated one. Lessons must be adopted, not filed and forgotten.

6. Are our existing security investments delivering measurable risk reduction, or are we paying for overlapping tools that create noise?

Operational. Organisations report using more than 45 security tools on average, with each incident requiring coordination across roughly 19 of them (IBM Security and Ponemon Institute, 2020). Tool consolidation around Zero Trust architecture, using a vendor-agnostic measure repository, is the path from noise to signal. Budgets must be optimised for real impact, not tool accumulation.

7. Does our culture allow security failures to surface, or do we have a reporting environment that buries the signal?

Operational. The organisations that surface failures learn from them. The organisations that hide them encounter them again, at greater scale. Zero Trust makes failures visible, measurable and improvable, which is what regulators, investors and customers now demand.

Board signal

Boards that ask these seven questions govern cybersecurity. Boards that do not will learn the difference the hard way.

The Numbers That Survive Boardroom Debate

$4.99M
Average breach cost

Global average, a record high and 12% up year on year. IBM Cost of a Data Breach Report, 2026.

247
Days to identify and contain

Mean breach lifecycle, the window Zero Trust directly compresses. IBM Cost of a Data Breach Report, 2026.

42%
Developer capacity lost

Share of the working week spent on maintenance, debugging and bad code. Stripe, The Developer Coefficient, 2018.

10%
Mature Zero Trust programs

Share of large enterprises expected to have one by 2026, up from under 1%. The other 90% carry unpriced liability. Gartner, January 2023.

45+
Security tools in use

Average per organisation, with roughly 19 involved in any single incident. IBM Security and Ponemon Institute, 2020.

4 · 5 · 7
The framework

Principles, implementation steps and board questions. The complete governance framework from the handbook.

The Two Decisions the Board Has to Make

Two governance questions must be resolved before execution, not during an incident. Deferral is not a neutral position. Every quarter of delay extends the window of unpriced liability and widens the distance from the resilience standard regulators and investors now require.

Decision 01

What is our acceptable residual risk threshold under a Zero Trust operating model?
This defines the boundary between what is managed through Zero Trust as a Service and what remains internal board accountability. It determines scope, SLAs, regulatory reporting obligations and the board reporting cadence. It is a governance decision, not a technical one, and it must precede implementation.
Decision owner: board, CRO and CISO.

Decision 02

In a major breach, does response authority remain internal, or is execution delegated to the CSIRT?
The regulatory reporting clock under NIS2, DORA, GDPR and SEC rules starts at detection. Pre-assigning response authority is the difference between a managed crisis and a regulatory failure. This decision has to exist before the incident, not be improvised during it.
Decision owner: board, CEO and CISO.

What Zero Trust Resolves

The handbook's epilogue returns to its opening diagnosis and shows, problem by problem, how Zero Trust addresses each one.

Architectural entanglement

Zero Trust introduces Protect Surfaces: small, defined, manageable segments that replace dense webs of interconnected systems with bounded, auditable environments.

Tool overload

Zero Trust replaces tool sprawl with architectural coherence. Measures are selected from a vendor-agnostic repository, precisely matched to each Protect Surface's Relevance Score.

Blind spots

Zero Trust mandates continuous verification, logging and flow mapping, restoring the real-time, contextual visibility that fragmented architectures had permanently obscured.

Executive complexity

Zero Trust cuts through jargon with one principle: never trust, always verify. Protect Surfaces give boards a governance vocabulary that requires no technical expertise.

Regulatory inflation

Zero Trust's continuous monitoring, documented policies and SOC governance create the audit trail that DORA, NIS2, GDPR and SEC rules demand as evidence of "in control" status.

Moore's Law meets Murphy's Law

Zero Trust's assume-breach posture and microsegmentation ensure that when failure occurs at machine speed, the blast radius is bounded rather than organisation-wide.

The organisations that treat Zero Trust as a technology project will fall into the 90% who carry unpriced liability into the next breach. The organisations that treat it as a governance discipline will build the resilience, the compliance posture and the stakeholder trust that define the next decade of digital business.

Timmermans & Bobbert, The Zero Trust Cybersecurity Handbook

Where to Start

Get in touch

Walk into your next board meeting with both answers already in hand.

The board does not need to understand microsegmentation. It needs to define what the organisation is protecting, decide how much residual risk it is willing to carry, and name who holds authority when the clock starts. Everything else follows from those three answers.

Tell us in a few lines which Protect Surfaces matter most to you and where response authority sits today. In one conversation we will show you what a governed Zero Trust operating model changes for your residual risk position and your reporting obligations under NIS2 and DORA. A short message is enough, no documents needed.

Talk to ON2IT

FAQ

What is Zero Trust governance?

Zero Trust governance is the practice of running Zero Trust as a board-level management discipline rather than a technology project. It means the board defines the Protect Surfaces, sets the acceptable residual risk threshold, pre-assigns incident response authority, and tracks resilience KPIs, while the architecture and operations deliver against those decisions.

Why is Zero Trust a board decision rather than an IT decision?

Because the two decisions that determine the outcome are governance decisions, not technical ones: how much residual risk the organisation accepts, and who holds response authority in a major breach. Both carry director liability under NIS2, DORA, GDPR and SEC disclosure rules, and neither can be delegated to an engineering team.

What questions should a board ask about cybersecurity?

Seven, across three layers. Strategic: what are our Protect Surfaces, how does the board support the strategy, and do we see our silent and residual risks? Managerial: what resilience KPIs do we track, and when did we last simulate a breach? Operational: are our investments reducing risk, and does our culture let failures surface?

What are the four principles of Zero Trust?

Redefine trust, so nothing is trusted by default. Remove implicit trust from legacy infrastructure. Verify continuously, on every interaction rather than once at login. Assume breach, and design controls to limit blast radius as if compromise has already happened.

What are the five steps of Zero Trust implementation?

Define the Protect Surface, map transaction flows, build the Zero Trust architecture, create Zero Trust technical policies using the Kipling method, and then monitor and maintain through the SOC. The order matters: you cannot write a precise policy before you have mapped the flows.

What is a Protect Surface?

A Protect Surface is the set of Data, Applications, Assets and Services that actually needs protecting. It is the inverse of an attack surface: small, defined and defensible. Each one is scored on confidentiality, integrity, availability, audit obligation, business criticality and fraud risk, and that Relevance Score sets the required level of protection.

How does Zero Trust help with NIS2 and DORA compliance?

Continuous monitoring, documented least-privilege policies and SOC governance produce the audit trail these regulations demand as evidence of "in control" status. Just as importantly, the regulatory reporting clock starts at detection, so pre-assigned response authority and a tested incident process are what make the reporting window achievable.

What is the difference between having Zero Trust tools and having Zero Trust posture?

Tools are purchased. Posture is operated. Gartner expected only 10% of large enterprises to have a mature, measurable Zero Trust program by 2026, which means most organisations own components without running the discipline that connects them. Auditors, insurers and regulators are increasingly able to tell the two apart.


Sources

  • Timmermans, T. and Bobbert, Y. The Zero Trust Cybersecurity Handbook: Redefining Trust in a Digital Era.
  • IBM. Cost of a Data Breach Report 2026. Global average cost and mean time to identify and contain.
  • Gartner. Gartner Predicts 10% of Large Enterprises Will Have a Mature and Measurable Zero-Trust Program in Place by 2026, January 2023.
  • Stripe. The Developer Coefficient, 2018. Share of the developer week spent on maintenance and bad code.
  • McKinsey. Tech debt: Reclaiming tech equity, 2020. Share of new-product technology budget diverted to technical debt.
  • IBM Security and Ponemon Institute. Cyber Resilient Organization Report, 2020. Average number of security tools in use.
  • NIST. SP 800-207, Zero Trust Architecture, 2020. US Executive Order 14028, Improving the Nation's Cybersecurity, 2021.
Zero TrustGovernanceBoardCyber ResilienceNIS2DORAZTaaS