The Legacy Infrastructure Challenge
Zero Trust is frequently discussed as if it were a greenfield architectural choice — design your network from scratch, deploy software-defined perimeters, and declare victory. In practice, nearly every enterprise with more than a decade of operational history is dealing with a fundamentally different situation: applications that cannot be re-architected, flat network segments that were designed for implicit trust, and on-premises directory services that predate cloud identity concepts by fifteen years.
The Cybersecurity and Infrastructure Security Agency (CISA) Zero Trust Maturity Model provides a useful reference architecture, but it was designed with aspirational target states in mind. The operational question facing most CISOs and enterprise architects is more immediate: how do we apply Zero Trust principles incrementally without breaking production systems or creating compliance gaps during the transition?
Zero Trust Pillars in a Legacy Context
CISA's model organizes Zero Trust across five pillars. Each presents specific challenges in legacy environments:
An Incremental Implementation Roadmap
Based on engagements with organizations in financial services, healthcare, and the public sector, Enigma recommends a phased approach that generates measurable security improvements at each stage while maintaining operational continuity.
Phase 1: Identity Foundation (Months 1–3)
Federate on-premises Active Directory with a cloud identity provider (Microsoft Entra ID, Okta, or Ping Identity). Deploy MFA for all privileged accounts and externally accessible applications. Establish a baseline Privileged Access Workstation (PAW) program for administrative functions. This phase alone eliminates the most common initial access vectors in enterprise breaches.
Phase 2: Device Trust and Endpoint Visibility (Months 3–6)
Enroll corporate devices in MDM (Microsoft Intune, Jamf). Deploy EDR agents across all endpoints and servers. Establish device compliance policies as prerequisites for Conditional Access rules. Begin inventorying unmanaged and IoT devices — these represent significant lateral movement risk in legacy environments.
Phase 3: Network Micro-Segmentation (Months 6–12)
Identify and classify high-value asset groups (ERP servers, domain controllers, sensitive data stores). Implement host-based firewall policies to restrict east-west traffic between segments. Integrate NAC for wired and wireless network access. Deploy a Software-Defined Perimeter (SDP) or ZTNA solution for remote access, replacing legacy VPN.
Phase 4: Application Access Governance (Months 9–15)
Deploy an application access proxy (e.g., Zscaler Private Access, Cloudflare Access) to front legacy applications with identity-aware access controls. Implement PAM (Privileged Access Management) for administrative access to servers and network devices. Establish continuous authorization policies that evaluate risk signals in real time.
Key Risk Factors and Mitigation Strategies
Organizations that struggle with Zero Trust implementations consistently encounter three common failure modes:
- Scope underestimation: Asset discovery consistently reveals 20–40% more endpoints and applications than organizations have in their official CMDB. Begin with a comprehensive discovery exercise.
- User experience degradation: Overly aggressive Conditional Access policies create authentication friction that drives shadow IT adoption. Tune policies using risk-based signals rather than blanket requirements.
- Treating Zero Trust as a product: No single vendor delivers a complete Zero Trust architecture. Organizations that equate purchasing a specific tool with achieving Zero Trust create a false sense of security while significant gaps remain.
About This Research
This analysis draws on Enigma's advisory engagements with 28 US enterprises undertaking Zero Trust initiatives between 2023 and 2025, aligned with the CISA Zero Trust Maturity Model v2.0 (April 2023) and NIST SP 800-207.