Zero Trust fails most often as an unsequenced technology programme. Tools are purchased, principles are asserted, and access behaviour stays exactly as it was. The budget is spent and the risk position is unchanged.
The baseline you do not have
The reason is usually that the programme starts without a baseline. Nobody can state, across identity, devices, networks, applications, workloads, and data, where the organisation actually stands. Without that, the roadmap and the purchase decisions rest on assumption.
A discovery phase establishes the baseline against a recognised maturity model, so the position is defensible to auditors, regulators, and new leadership, well beyond the team that commissioned it.
Zero Trust fails most often as an unsequenced technology programme. Tools are purchased, principles are asserted, and access behaviour stays exactly as it was.
Most capability is already owned
Discovery routinely finds that an organisation owns more relevant capability than it uses. Identity, network, and monitoring investments already in place often improve maturity more than a new purchase would, once they are configured and governed to the target state.
Establish where you stand, decide which use cases justify investment, and only then make procurement decisions. Delivery follows a roadmap tied to business risk, with the design decisions governed independently of any vendor's revenue.
