categories
Zero Trust
Browse Pomerium articles in the Zero Trust category.
Topic archive
Resources Categorized: Zero Trust

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."
.png.DqqhEqND.webp)
Why Identity-Aware Access is the Missing Layer in Agentic Security
A new VentureBeat analysis from this week lands on a truth that every enterprise security team already feels in their gut: most AI agents are a credential exfiltration waiting to happen. The monolithic agent pattern — where reasoning, execution, credential storage, and tool access all share the same process — creates a threat surface that conventional security tooling wasn't designed to close.
.png.CbQUPgiG.webp)
Midmarket Security Teams Deserve Better Than Enterprise Hand-Me-Downs
New research shows 42% of midmarket security teams are stretched thin while enterprise tools don't fit. Here's why a zero trust reverse proxy, like Pomerium, changes the equation.

Complete Guide: Zero Trust for Air-Gapped Networks
Air-gapped networks are supposed to be impenetrable. No internet connection, no remote attacks. That's the theory at least. But isolation alone doesn't stop the threats that walk through the front door: compromised USB drives, malicious insiders, and supply chain attacks that arrive pre-installed on new hardware.
Turning SANS Critical AI Security Guidelines Into Enforceable Agentic Controls with Pomerium
Learn how to turn SANS Critical AI Security Guidelines into enforceable controls for access, monitoring, and governance with Pomerium.
5 Actionable Zero Trust Patterns from NIST SP 1800-35 (and How to Implement Them)
Implementing a Zero Trust Architecture (ZTA) is no longer a task that can be pushed to tomorrow—it's best practice to begin implementing it today. Understanding that moving from theory to practical implementation can be challenging, the National Institute of Standards and Technology (NIST) published Special Publication 1800-35 to provide real-world, actionable patterns to guide organizations through their Zero Trust journeys.
5 Key Takeaways about ZTA from NIST SP 1800-35
Adopting Zero Trust principles significantly reduces cybersecurity risks by ensuring only the right people, under the right circumstances, gain access to your resources.
Secure Access for Model Context Protocol (MCP)
Learn why OAuth alone can't secure the Model Context Protocol (MCP). Discover how Pomerium enforces Zero Trust for agentic AI with per-request authorization, JWT identity, and full audit logging.
How To Achieve Zero Trust In Kubernetes With Pomerium
Modern Kubernetes environments don’t have a perimeter (a single, predictable network boundary). Apps span clouds. Teams work from anywhere. Legacy security models—built on assumptions of a trusted internal network—start to fall apart.
Why Per-Request Authorization Is the Foundation of Zero Trust
Most access tools treat authentication like a one-time handshake. In these models, once a user or service is validated, they’re granted broad access for the rest of their session, regardless of what changes afterward.
How Pomerium Secures Access for Human, Service, and Agent Identities
Legacy tools were designed for single perimeters: users in offices, apps in one environment, and static roles assigned to each.
How Pomerium Enforces Real-Time, Context-Based Access
For security engineers, compliance owners, and platform teams who need smarter policies for better security posture.
Not All Zero Trust Is Created Equal: Why Enterprises Host Their Own
That’s the starting point for Zero Trust. It’s a model built on verifying every user, securing every request, and removing trust based on network location.
How Pomerium Brings Zero Trust to Legacy, Hybrid, and Cloud-Native Environments
Enterprise infrastructure doesn't live in just one place. It spans data centers, Kubernetes clusters, cloud workloads, and SaaS tools. Some of it's old. Some of it's modern. All of it needs to be secure.
Executive Order 14144: Strengthening Cybersecurity — Key Mandates & Zero Trust
The U.S. government continues to push for stronger cybersecurity standards as demonstrated by Executive Order (EO) 14144 . Signed on January 16, 2025, this order builds on previous cybersecurity directives by enhancing Zero Trust adoption, securing identity and access management, and strengthening software supply chain security.
Context-Based Access Control and Zero Trust: Key Insights from the CSA White Paper
The Cloud Security Alliance (CSA) recently released a white paper on Context-Based Access Control (CBAC) and its role in advancing Zero Trust security models. The paper underscores the necessity of shifting from static, trust-based access control to real-time, adaptive authentication that evaluates risk dynamically, and Pomerium was highlighted as a key player in the CBAC space.
Taking Back Zero Trust: Bank Policy Institute (BPI) provides a fairly reasoned take on Zero Trust
Bad actors in a Financial Institution’s network should be assumed.

12 Zero Trust Architecture Examples With Actionable Guide
At this stage, it's safe to assume you're familiar with the core principle of Zero Trust Architecture: "never trust, always verify." Zero Trust is a framework, not a single tool you can install. So, what does a real-world zero-trust architecture example look like? What tools are necessary to achieve full zero trust implementation? In this article, we have presented a zero-trust architecture example to illustrate how a fully secured organization operates and included 12 additional zero-trust examples highlighting the features and tools required for 360-degree zero-trust protection.
.png.BbM6W8pj.webp)
What is Zscaler and How Does it Work?
If you’re evaluating a shift from traditional VPNs and considering Zscaler, this article will help. Here, we have explored what is Zscaler and how it works, its offerings, cost, pros, and cons. We have also covered how ZPA works as a VPN replacement and compared it to a promising alternative—Pomerium. Let’s begin.

8 Best Open Source Zero Trust Software Solutions
Unlike traditional security, which often grants implicit trust to users solely because they are inside the network, the Zero Trust model grants no implicit trust, and therefore continuously verifies all activity, ensuring that only the right people with the right level of access are authorized to reach the resources within the network. There are many open-source zero-trust software that facilitate this approach by ensuring that no entity, whether inside or outside the network, is trusted by default. Here are eight notable open-source Zero Trust software solutions.

Cloudflare Alternatives & Competitors: CDN, Zero Trust & SASE
Cloudflare offers a wide range of services, making it difficult to find a single alternative that covers all its capabilities. In this article, we've outlined Cloudflare alternatives for 1) Zero Trust and Secure Access Service Edge (SASE) , and 2) Application and Network Services, allowing you to make an informed decision based on your specific needs. So, without further delay, let’s explore!
Achieving zero trust with Pomerium JWTs
We discuss how Pomerium JWTs enable zero trust architecture for verifying each request.

Zero Trust VPN: Meaning and Alternatives
Zero Trust VPN means a virtual private network service that works on the principle of "never trust, always verify." Although some VPN providers claim to offer Zero Trust VPN, in reality, most VPNs lack some core features and the users need to buy extra security products/services to implement the Zero Trust model.

4 Trends Shaping the Future of Access Control
Access control is no longer an afterthought of the development process – it's the cornerstone of a secure environment. The rise of remote work has fundamentally changed how we access data and resources. Organizations now face the challenge of securing access for a distributed workforce while also fending off increasingly sophisticated cyberattacks. Weak access controls leave businesses vulnerable to data breaches and unauthorized access.
Applying Zero Trust to Multi-Cloud Environments
We read the National Institute of Standards and Technology (NIST)’s SP 800-207A: A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments to summarize it so you don’t have to.

What is Zero Trust Architecture and Security?
The term "Zero Trust" has been co-opted by many marketing branches of products, but it has a defined meaning with real industry impact.

Zero Trust Maturity Rubric and Tool Matrix
Version 2 of CISA's Zero Trust Maturity Model expands on content and guidance compared to the first version, but a very specific change should be addressed:

Pomerium and CHT Security Partner for Zero Trust Network Access Solution
For the Mandarin Chinese version of this announcement, please see CHT Security's post here .
Announcing Pomerium v0.21
While we’ve been cooking up something big , we have some nice entrees to whet your appetite. Pomerium v0.21 is packed with performance improvements, bug fixes, new features, and feature updates, including:

Benefits of Zero Trust Architecture as Defined by NIST
NIST has released a draft of SP 1800-35 , Implementing a Zero Trust Architecture. The lengthy documents lay out their definition of Zero Trust Architecture (ZTA) , the benefits, why it’s important, a few examples of how an organization can implement them, expected results associated with their example builds, and a mapping of ZTA security characteristics to current cybersecurity standards and compliance.

A Close Read at NIST’s Definition of Zero Trust Architecture
This is written based on the second draft of SP 1800-35.
Announcing Pomerium v0.20
New year, new big release! We’re thrilled to announce Pomerium v0.20, including:
Analyzing the US Government’s Adoption of Zero Trust
Two years ago, we published our original Demystifying Zero Trust to discuss the following topics without marketing buzzwords:

Highlights from IBM’s Cost of a Data Breach 2022
IBM’s yearly Cost of a Data Breach 2022 report is out. The 59 page report by IBM and the Ponemon Institute contains findings based on over 3,600 interviews studying 550 organizations impacted by data breaches that occurred between March 2021 and March 2022. The breaches occurred across 17 countries and regions and in 17 different industries.
Announcing Pomerium v0.18
We are excited to announce the v0.18 release of Pomerium! This release features support for external data sources, an integral component of zero trust architecture. Without further ado, let’s get down to what it is, why it’s important, and how you can use it!

Q&A with Zero Trust Architecture Writers from NIST
We interviewed Scott Rose and Oliver Borchert from the National Institute of Standards and Technology (NIST) about their publication on Zero Trust Architecture (ZTA) discussing zero trust principles and how it affects organizations.

Insulation from Third-Party Breaches
The world’s #1 identity platform Okta has suffered a potential breach , and thousands of their corporate customers find themselves wondering if they may need to take corrective measures. Though Okta’s Chief Security Officer David Bradbury officially claims “There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers”, companies like Cloudflare have taken preventative measures to protect their internal and external accounts against hackers that may exploit Okta’s potential security breach.

The Far Reach of the White House’s Zero Trust Memo
The new White House memo on zero trust is a strong signal that the US federal government is taking an active stance regarding cybersecurity. Not only does this have far-reaching ramifications for the public and private sectors, it also serves to cut through the noise about zero trust with an impartial source. Let’s look at what the White House has to say and what this means for the cybersecurity sector going forward.

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.
Once again, we find ourselves combining the Cybersecurity & Infrastructure Security Agency's (CISA) Week 3 theme of Explore. Experience. Share. with Week 4's theme of Cybersecurity First. Ultimately, people and organizations can better prepare for an increasingly virtual world by sharing cybersecurity knowledge and making it top-of-mind.
