Implementing a mature, comprehensive and measurable zero-trust program can be a daunting journey, filled with noise and hype. Gartner Distinguished VP Andrew Lerner explained how to use the firm’s latest Hype Cycle for Zero-Trust Networking to help navigate your zero-trust and secure access service edge (SASE) journey.

Given its client interests, confusion and hype surrounding zero trust, Gartner has introduced a new Hype Cycle that categorizes what it says are 19 of the most relevant and hyped zero-trust technologies. The report explains the definition and provides specific recommendations around each of these technologies, Lerner told SDxCentral.

“Zero trust, it's similar now to a word like cloud or a word like software-defined, where so many people use it, it means everything to everyone and nothing to everyone at the same time,” he said. “One thing we see is our clients sometimes struggle to delineate things that truly exhibit zero-trust characteristics from just pure vendor marketing,”

In the report, Gartner predicts that 10% of large enterprises (i.e., have over $1 billion annual revenue and/or more than 1,000 employees) will have a comprehensive, mature and measurable zero-trust program in place, a significant rise from less than 1% in 2023.

What counts as a comprehensive, mature and measurable zero-trust program?“Comprehensive means it's broad, it's robust, it has deep roots in the organization. Mature means it's not just starting, it's well established. Measurable means you can actually point to the zero-trust program and identify specific tangible benefits,” Lerner said.

He acknowledged that measuring the maturity of a zero-trust program is challenging and involves many factors. “One way would be just how many business units within the organization have an awareness of what zero trust is and how their technology usage has an impact on it, and frankly, how long they've had the maturity is, in some cases, a function of time.”

Which zero-trust technologies orgs should adopt?

Gartner's new Hype Cycle categorized 19 zero-trust networking technologies into five stages based on the maturity level:

  1. Innovation trigger: Enterprise browsers, extranet-as-a-service, continuous access evaluation profile (CAEP), unified endpoint security, network assurance, managed secure access service edge (MSASE), universal ZTNA, service connectivity layer and hybrid mesh firewall platform.
  2. Peak of inflated expectations: security service edge (SSE), zero-trust strategy and Kubernetes networking.
  3. Trough of disillusionment: Digital experience monitoring and SASE
  4. Slope of enlightenment: zero trust network access (ZTNA), openID connect, microsegmentation, container security and remote browser isolation.
  5. Plateau of productivity: none

“The technologies on the right side of the hype cycle are more mature, they've been adopted, they're more proven … [but] that does not mean we're recommending that for your initial implementation,” Lerner said. ”The best technology you may deploy may be at the peak of the hype cycle or even to the left, depending on your specific requirements.”

When using the Hype Cycle, it's key to consider your organization's risk tolerance, he said. Early adoption of technologies on the left side of the Hype Cycle can yield substantial rewards, but at higher risk, and technologies on the right side come with less risk and fewer growing pains but might offer lower rewards as they are widely adopted.

Selecting among SSE, SASE, managed SASE

In the report, Gartner noted SSE is at peak hype, “due to a shift in the traffic flows associated with public cloud and SaaS services, and organizations’ desire to converge security tools and vendors.” It reached the adolescent maturity level with a 5% to 20% market penetration rate.

Sample vendors of SSE include Broadcom, Cisco, Cloudflare, Forcepoint, iboss, Lookout, Netskope, Palo Alto Networks, SkyHigh Security and Zscaler.

SASE is deep in the trough, “due to exaggerated marketing by many technology vendors,” the report wrote. It has the same level of maturity and market penetration rate as SSE.

Sample vendors of SASE include Cato Networks, Cisco, Cloudflare, Forcepoint, Fortinet, Juniper Networks, Netskope, Palo Alto Networks, Versa Networks and Zscaler.

Managed SASE is on the rise, which offers the full life cycle of SASE functionality as a managed service, including design, migrations, configuration, installation, operations and management. Its maturity level is emerging, penetrating 1%-5% of the target audience.

Choosing among these three technologies will depend largely on the organization's structure, size, and capabilities, Lerner noted.

Larger organizations, with multiple existing networking and security technology implementations and siloed teams, often prefer a dual-vendor SASE approach due to potential difficulties in achieving convergence. “The key is to select vendors that have strong explicit integration between” SSE and SD-WAN capabilities," he said.

Meanwhile, mid-market organizations with smaller but well-consolidated teams may lean towards a single-vendor SASE approach for unified management and simplicity.

Managed SASE becomes a preferable option for organizations lacking the expertise to design, implement and operate these systems, so they rely on vendors to do it for them. For example, “traditional organizations that have implemented managed network services or managed security services, and don't have strong or deep or scaled teams to manage the implementation,” Lerner said.