惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
F
Fortinet All Blogs
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
罗磊的独立博客
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
U
Unit 42
N
Netflix TechBlog - Medium
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
云风的 BLOG
云风的 BLOG
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Proofpoint News Feed
G
Google Developers Blog
H
Help Net Security

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Why Delaying Zero Trust Can Be Financially Irresponsible
Jaushin Lee · 2026-05-27 · via Forbes - Innovation

Dr. Jaushin Lee is founder and CEO of Zentera Systems, a leader in zero-trust security solutions for the digitally transformed enterprise.

getty

​When managing budgets, many business leaders prioritize essential expenditures and R&D, treating cybersecurity as something to invest in only when there is money left over.

​This mentality, however, relies on the assumption that security risk will remain steady until the next budget planning cycle. In reality, today’s digital environments rarely stand still. Between cloud migrations, remote work, third-party integrations and application growth, attack surfaces expand faster than legacy controls can manage.

​But the hidden cost of waiting to invest in cybersecurity is not just the expanded attack surface; it’s the compounding financial exposure that can offset any benefits gained from deferred spending.

​This is why a zero trust security posture has quietly shifted from a nice-to-have to a baseline requirement for business resilience. Once in place, I've found that this architecture can help prevent small incidents from becoming large, financially damaging events that lead to weeks of operational downtime, high recovery costs and long-term revenue loss.

The False Comfort Of The Status Quo

With firewalls in place, VLANs dividing the network and perimeter defenses monitoring network traffic, security and business leaders often believe their current controls are enough to hold attackers at bay until the next investment cycle.

​This sense of security can make improvements feel optional, rather than required. However, many of these security measures were deployed when networks were simpler and the emphasis was on keeping attackers out—not containing them once inside. ​

Risk Quietly Increases Every Quarter

While security investments may stall, an organization’s digital environment will always continue to evolve. Each change puts additional strain on existing security tools and potentially adds unmanaged endpoints, exceptions and legacy configurations that fall further behind. What was once a protected network may quietly become a mix of interconnected systems relying on implicit trust relationships not fully understood.

​The result is a growing gap between how fast a business evolves and how slowly security measures can adapt. As this gap grows and budget cycles pass, risk compounds—quietly and incrementally—until a single vulnerability could trigger a large financial loss.​

How Small Breaches Can Create Massive Financial Costs

The breaches that cause the biggest headlines rarely begin with a dramatic move. Instead, they start with a missed mitigation or an overlooked control.

​Attackers Start Where Defenses Are Weakest

Based on what I've seen in the industry, initial access is often achieved through unpatched web applications, vulnerable edge devices or unmanaged vendor connections. These vulnerabilities may seem low-priority, but each system is connected to broader enterprise assets that, once compromised, can become steppingstones to critical infrastructure.​

Lateral Movement Drives Escalation

Where poorly segmented or unchecked networks exist, attackers can move quickly from one system to another, putting data from multiple departments and locations at risk. It’s this lateral movement and escalation that drives financial exposure upward. ​

Financial modeling by Zentera and 2BSalt Financial Engineering, for example, shows that compounding cyber risk from delaying a shift to modern segmentation with zero trust can increase exposure by more than $2 million in as few as two quarters. The same analysis showed the cost of the risk climbs to over $12 million and $33 million in the next two quarters.​

Downtime Becomes The Primary Cost Driver

Although six-figure ransom demands often drive headlines, operational downtime is the biggest contributor to the $2 million figure cited above. On top of production stoppages and revenue losses, organizations must contend with remediation costs, penalties and compounding financial losses. What was once a small risk often becomes a major business event.

Why Traditional Security Approaches Can’t Keep Up

Perimeter and network security tools will still play a key role in cybersecurity, but they aren’t versatile enough to keep pace with today’s rapidly evolving digital environments. Relying on these investments alone leaves critical security risks that attackers can exploit:

Perimeter-Based Defenses Miss Internal Movement: Firewalls use predefined rules to monitor traffic entering and leaving a portion of the network. Once an attacker bypasses the firewall, internal activity often goes unmonitored, and threats can move laterally with little resistance.

Static Segmentation Can Expand The Blast Radius: VLANs and static network zones often group many systems, creating wide internal trust areas. Legacy tools that are used to manage these zones and their traffic often struggle to keep up as exceptions and new endpoints rapidly grow.

Complexity Delays Action: Traditional security system implementations and modernizations often involve long timelines, heavy coordination and high operational risk. Therefore, while environments continue to expand, security improvements generally lag behind the realities of the financial risk.

How Zero Trust Changes The Risk (And Cost) Profile

Traditional security models assume that user or system activity initiated within a network can be trusted. The zero trust model flips that assumption by requiring continuous authentication for every connection.

​In other words, every access decision should be driven by the user’s or system’s identity, context and activity, replacing implicit trust with precise connectivity strong enough to block later movement by default. Once in place, attackers are prevented from pivoting freely from segment to segment, thereby containing potential attacks, shortening mitigation timelines and lowering financial impact.

​The other strength of the modern zero trust model is its ability to be deployed incrementally—measured in days or weeks rather than months or years. For example, organizations can prioritize critical systems first and then expand protections to others over time, making the transition a bit more manageable.

Delaying Zero Trust Implementation Is A Financial Decision

​Cyber risk can no longer be calculated separately from business expansion. Every new application, business service or integration brings with it new risks that can alter the scale of potential financial damage. What can begin as a minor vulnerability or delayed investment can quickly trigger costly operational shutdowns, regulatory fines and significant financial loss.

​Therefore, leaders who delay zero trust implementation are making more than a technical choice; they are actively accepting financial risk.​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?