The Imperative & The Important - Zero Trust Edition
This edition takes the lane the industry thought it had figured out — zero trust — and reads a week that proved otherwise. The product carrying the label got exploited, the intelligence community said the model is being turned “on its head,” and the standards bodies quietly finished the homework. The durable lesson underneath: zero trust was scoped for people, and the population on your network just changed.
The Imperative
The zero trust front door took a hit. Cisco confirmed active exploitation of CVE-2026-20349, a high-severity flaw in its ASA and FTD firewalls that lets an unauthenticated attacker reload the appliance with a single crafted HTTP request — no workarounds, hot fixes only (Help Net Security). Read the affected-features list closely: IKEv2 remote access VPN, SSL VPN — and Zero Trust Network Access itself. CISA put it on the Known Exploited Vulnerabilities catalog and gave federal agencies until August 14 to fix it. The business translation: the box you bought to replace the VPN sits in the same exploited path the VPN did. Zero trust is an architecture, not an appliance — and “assume breach” applies to the access layer you paid for.
The intelligence community said agentic AI is turning zero trust “on its head.” Autonomous agents need broad access to data, tools, and systems to be useful — exactly what zero trust was built to deny by default. The emerging requirement, per the IC’s chief information office: a “digital birth certificate” not just for people and devices but for AI agents, with an enterprise identity service heading into operational pilots this fall (Breaking Defense). The quote that matters: “Zero Trust for us has been redefined as identity and policy enforcement of fine-grain attributes.” When the most surveilled network on earth says identity is the whole game, that is the roadmap.
The market started selling zero trust for machines. Microsoft extended its zero trust program to AI agents — a new AI-focused assessment, a DevSecOps pillar with 91 enumerated tasks, and guidance that treats an agent’s memory as a governed security boundary (Microsoft Security). Two weeks later and an ocean away, SK Shieldus announced it will classify AI agents as “Non-Human Identities” and manage their access the way it manages people’s, aligned to NIST’s AI Risk Management Framework and ISO/IEC 42001 (Seoul Economic Daily). Two vendors, two continents, fifteen days apart, same product category. When the market converges that fast, it is pricing a liability customers already have.
The standards scaffolding quietly finished. It is Friday, so note what the policy shelf now holds. NSA’s Zero Trust Implementation Guidelines Phase One and Phase Two enumerate 77 activities that move an organization from discovery to target-level maturity (NSA). CISA and the Pentagon published joint guidance adapting zero trust to operational technology, citing Volt Typhoon’s persistence inside OT environments as the reason (Inside Cybersecurity). NIST’s SP 1800-35 shows 19 worked example implementations (NIST). The business translation: zero trust is no longer a slogan you can gesture at. It is an auditable maturity model with numbered activities — which means “where are you on it” is now a fair question from a regulator, an insurer, or a board.
The Important: The Population Just Changed
Every one of this week’s stories is the same story. For fifteen years, zero trust meant verifying people, then devices. The fastest-growing population on your network now is neither — it is software that acts: agents that request credentials, hold them, and use them at machine speed. The Cisco exploit says your access layer can fail; the IC says the identity model must expand; the market says someone will sell you the fix; the standards say you will be measured on it.
The durable shift is that trust is becoming a census question. You cannot verify an identity you have not enumerated, and most organizations have never counted theirs — human accounts, service accounts, API keys, and now agents, many provisioned by a pilot project nobody reviewed.
For the leadership team, the playbook is the discipline we teach in every lane, applied to identity:
Discovery is an identity census. Every entity that can act in your environment — person, device, service, agent — enumerated with an owner. You cannot apply least privilege to a population you have not counted. (Regular readers will recognize this as the CBOM argument from our post-quantum lane. Same discipline, different asset.)
Agility is revocation speed. Least privilege is only real if you can take access back faster than it can be abused. A credential you cannot revoke in minutes is an unhedged position — and an agent holding one is an unhedged position that never sleeps.
Governance is ownership of a number. Someone must own the count of identities holding more access than their task requires, the way someone owns days sales outstanding. If no one owns the number, it grows.
The Imperative changes weekly. The Important is your homework either way: the organizations that count their identities before an attacker, auditor, or regulator does it for them set the price of the fix. Everyone else takes the market’s price.
Three Questions for Your Next Leadership Meeting
How many identities can act in our environment right now — human, service, and AI — and who owns that census? If the answer is a shrug, the census has already been taken by someone else.
If our remote-access layer failed this morning — outage or compromise — what is the fallback, and does it quietly bypass the controls we bought? The Cisco advisory had no workaround. Yours should.
Which of our AI pilots already hold credentials, and would any of them pass the access review we require for a new hire? If an agent has more access on day one than an employee gets in year one, the policy is the vulnerability.
The Imperative & The Important is the daily briefing from Carl’s Corner — timely developments and the durable ideas underneath them, across post-quantum cryptography, IoT and OT security, cybersecurity, and enterprise AI. Friday editions read the week through the lens of policy and standards.
Sources
Help Net Security — Cisco fixes actively exploited firewall flaw (CVE-2026-20349): https://www.helpnetsecurity.com/2026/08/13/cve-2026-20349-cisco-firewalls-dos/
Breaking Defense — Agentic AI turning Zero Trust cybersecurity “on its head”: https://breakingdefense.com/2026/08/agentic-ai-turning-zero-trust-cybersecurity-on-its-head/
Microsoft Security Blog — Advance Zero Trust for AI: new tools and guidance: https://www.microsoft.com/en-us/security/blog/2026/08/04/advance-zero-trust-for-ai-new-tools-and-guidance-to-secure-ai-agents-and-devsecops/
Seoul Economic Daily — SK Shieldus expands zero-trust security to cover AI agents: https://en.sedaily.com/technology/2026/08/19/sk-shieldus-expands-zero-trust-security-to-cover-ai-agents
NSA — Phase One and Phase Two of the Zero Trust Implementation Guidelines: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4393480/nsa-releases-phase-one-and-phase-two-of-the-zero-trust-implementation-guidelines/
Inside Cybersecurity — CISA, Pentagon release zero trust guidance for operational technology: https://insidecybersecurity.com/daily-news/cisa-pentagon-release-zero-trust-guidance-operational-technology-systems
NIST — SP 1800-35, Implementing a Zero Trust Architecture: https://csrc.nist.gov/pubs/sp/1800/35/final