AI has landed. Zero Trust Is No Longer Optional, But Hard to Get Right.

The Australian Signals Directorate (ASD) agrees that Zero Trust principles are part of a modern defensible architecture (MDA), that assumes no user, device, or system is trusted by default, inside or outside the network. For mid-market organisations, with limited security capability and capacity, it can enable secure, identity-led access, continuous verification, and stronger protection against evolving threats, helping meet compliance, resilience, and increasing operational security demands.

As AI is now part of most companies operating systems Zero Trust has moved from buzzword to reliable blueprint. According to Gartner, 63 per cent of organisations worldwide had begun implementing a Zero Trust strategy by 2024, and security spending in the category is projected to more than double from US$41 billion to US$102 billion by 2031. Those numbers tell one story. The reality we see everyday is that operationalising a Zero Trust framework takes support from an expert.

Like many security and technology upgrades, Zero Trust programmes often stall for the usual reasons. Scopes drift and without a specific Zero Trust capability managing implementation, deploying it demands operational maturity that mid-market organisations rarely have in-house. For IT leaders across Australia and New Zealand, the question has shifted from whether to adopt Zero Trust to how to make it work without enterprise-scale teams and budgets.

Key Challenge

Outcome with a Practical Zero Trust Approach

Growing AI usage expands the attack surface Continuous verification of users, devices, applications, and AI-driven workloads reduces risk exposure
Limited internal security resources Access to specialist Zero Trust expertise and managed services without building a large in-house team
Legacy VPNs and broad network access Secure, identity-led access with Zero Trust Network Access (ZTNA) and least-privilege controls
Increasing compliance and governance obligations Improved alignment with APRA CPS 234, CPS 230, Essential Eight, Privacy Act requirements, and broader security frameworks
Credential theft and identity-based attacks Stronger identity protection through MFA, role-based access, and identity threat detection capabilities
Complex hybrid workforces and third-party access Consistent access policies and continuous verification across employees, contractors, and external users
Fragmented security tools and visibility gaps Better visibility, centralised control, and faster threat detection and response
Difficulty operationalising Zero Trust Clear roadmap, ongoing optimisation, and measurable security outcomes that are achievable for mid-market organisations

Why Zero Trust Is So Hard to Get Right

Gartner estimates that by 2026, only 10 percent of larger enterprises globally will have a mature and measurable Zero Trust programme in place, and 35 percent have already experienced a failure significant enough to disrupt their implementation. If enterprises with dedicated security teams and resources are struggling, mid-market businesses face an even steeper path.

Forrester senior analyst, Tope Olufon, identified three areas where organisations are concentrating their Zero Trust investment:

  1. Tightening identity and access controls so users (and systems) have the right level of access, no more, no less.
  2. Replacing legacy VPNs with Zero Trust Network Access (ZTNA) for more direct and secure connectivity.
  3. Improving detection & response capability across endpoints, identity, and network layers.

Jeremy Nees, Chief Product Officer at Virtual IT Group, explains, execution is where many organisations struggle.

“Zero Trust is hard to get right because it’s not just a technology shift; it’s an operational and cultural one. Many mid-market organisations are layering it onto legacy environments without the internal capability to sustain it. The ones making real progress are taking a pragmatic, risk-led approach rather than trying to boil the ocean.”

Across ANZ, regulatory frameworks are adding urgency. For example, in the Australian financial services sector, APRA CPS 234 and CPS230 require regulated entities to maintain information security capabilities to commensurate with the threats they face. The Privacy Act sets baseline obligations for data protection, while the Essential Eight provides a maturity model that is increasingly aligned to Zero Trust principles. For CIO, CISOs, and other IT leaders, Zero Trust is no longer just a security initiative but a compliance, risk and governance priority.

At the same time, complexity is compounding. Organisations are moving toward fewer, more integrated control planes and away from disconnected point products. But overcommitting to a single vendor introduces its own risks, and no single platform delivers full Zero Trust maturity. The most effective architectures balance platform consolidation with best-of-breed tools, making interoperability essential.

And the scope of what “identity” means is expanding. As AI agents and automated systems proliferate, non-human identity governance is becoming a priority alongside traditional user-based access controls. Identity threat detection and response, guarding against credential theft, privilege abuse, and directory compromise, is adding another layer of operational demand to an already complex programme.

When it Works Well: Lessons from Estia Health

Estia Health, Australia’s second-largest residential aged care provider supports more than 10,000 residents across nearly 100 homes, and manages a workforce of over 14,000, plus a rotating ecosystem of visiting doctors and allied health professionals.

Managing that level of complexity, while safeguarding sensitive personal and health data, requires a Zero Trust approach that is both rigorous and practical.

Tharaka Perera, Estia Health’s Head of Information Security, built the programme around three pillars.

Identity comes first. Every user carries a unique identity with role-based access controls determining what they can reach. To manage a constantly shifting workforce, Estia Health standardised access profiles across similar job functions and integrated every application into a single sign-on environment through Okta. One user, one identity. Any application sitting outside that ecosystem creates a potential back door, and Estia Health doesn’t allow it.

Data required a different approach. Structured data within core systems can be controlled through role-based access, but unstructured data, such as files across shared environments, demanded more sophistication. Estia Health is building a classification-based data risk management programme, increasingly supported by AI to reduce manual effort without sacrificing rigour.

Endpoints present the hardest trade-off. Full device management across a workforce that includes visiting care professionals isn’t achievable. Instead, Estia Health enforces baseline security standards before granting access. Even visiting doctors must connect from fully patched devices. They also invest in clear communication, so staff understand not just what the controls are, but why they exist.

The end goal, as Perera describes it, is to connect all three layers into a model where access decisions are precise and context-aware, with a complete audit trail of who accessed what, and when.

It’s a sophisticated programme. It also reflects what’s possible when dedicated security leadership and deep resources are already in place.

What This Means for Mid-Market Businesses

That’s the gap; mid-market businesses across Australia and New Zealand face the same threats as larger enterprises, like ransomware, supply chain compromises and credential theft, but operate with a fraction of the security resources they need.

That’s the problem we set out to solve with Zero Trust Detection & Response (ZDR). Rather than licensing a platform and leaving an organisation to figure it out, ZDR is purpose-built for the mid-market and brings together enterprise-grade Zero Trust network and application access and our 24/7 ANZ Security Operations Centre (SOC), staffed by Zscaler Ace-certified engineers. All packaged in a model that is both commercially realistic and operationally manageable.

Where Estia Health built identity-first access controls internally, ZDR delivers that capability as a managed service; policy configuration, continuous optimisation, and threat response handled by a team with deep Zero Trust expertise. Zero Trust is not just for the big end of town. Threat actors certainly don’t think so.

See Where You Really Stand and What to Do Next

If you would like to understand where your organisation sits on the Zero Trust maturity curve, get a no obligation Zero Trust assessment and walk away with a clear, actionable roadmap to close your biggest security gaps.

Book your obligation-free assessment today.

Other recent articles

Great IT
starts here

Ready to take the next step? Talk to our
team about how we can support your
business objectives with award-winning
IT support and services.