Friday, July 31, 2026
HomeArticleFrom Identity to Intent: A Leader’s Journey Through the Evolution of Zero...

From Identity to Intent: A Leader’s Journey Through the Evolution of Zero Trust

Mithilesh Kumar, Head of Zero Trust Strategy at Netskope, on the shift from identity to intent, navigating the Zero Trust maturity journey, and why the next pillar of security belongs to AI.

Zero Trust has evolved from a security concept to a business imperative. How do you see organizations moving from strategy to successful implementation in today’s hybrid and cloud-first environment?

Mithilesh Kumar: Think about how we used to secure an office. One security desk in the lobby, you badge in once, and after that you could roam the whole building freely. That worked when everyone and everything lived inside those walls. But today your people are working from home, from cafes, from airports, and your applications have moved to the cloud — so that lobby desk is now guarding an empty building.

That’s why security leaders can no longer depend on a perimeter-based trust boundary. The rule has to flip to verify before you trust, every user, every request, every time. The good news is you don’t have to guess your way there. CISA has developed a Zero Trust Maturity Model that lets you implement and measure your progress across four maturity levels. Every organization adopting it is at a different rung on that ladder, and that’s completely normal, the point is knowing where you stand and taking the next step.

As cyber threats become increasingly sophisticated, what are the biggest challenges enterprises face when adopting a Zero Trust architecture, and how can they overcome them?

Mithilesh Kumar: The first mistake is treating Zero Trust like a fire extinguisher, one box you mount on the wall and you’re done. It isn’t a product. It’s an architecture framework, and you achieve it across multiple security pillars: identity, device, network, application, and data plus three cross-cutting capabilities running through all of them. It’s much more like getting fit: no single pill does it, you build it up over time.

So the how is to implement in phases and let maturity grow gradually, in a way that doesn’t disrupt the business experience. The organizations that struggle are the ones trying to jump several maturity levels in one go. When you switch on security at every layer at once, suddenly every login asks three more questions, and you get real pushback from end users and from business application owners alike because continuous validation takes time for people to adapt to. Go stage by stage, and adoption follows.

Identity has become the new security perimeter. How do you view the role of Identity and Access Management (IAM) in strengthening an organization’s Zero Trust framework?

Mithilesh Kumar: For years we relied on the castle-and-moat model, once you were inside the walls, you were trusted. In a world where applications and users sit outside the organization’s network entirely, that wall is simply gone. Identity has become the new perimeter.

Now the checkpoint travels with you. Whether it’s a human or a non-human identity, you’re only allowed to reach an application or service once you present your identity and the right access permissions. And even then, we no longer hand you the keys to the whole building. It’s like a hotel keycard that opens your room and the gym, but not every door on every floor you get specific applications with specific permissions till you need it, and nothing beyond that.

With AI transforming both cybersecurity defenses and cyberattacks, how do you see AI reshaping Zero Trust strategies over the next few years?

Mithilesh Kumar: For a long time IAM was really about people logging in, and it worked very well for human users. AI changes the cast of characters. As we adopt AI on both the attack and the defense side, the scope of non-human identities (NHI) , essentially autonomous software agents, is growing tremendously.

Picture a warehouse that used to have a handful of workers and now runs on thousands of robots, all handing things to one another. You can no longer just check who is at the door, you have to check intent, what this agent is actually trying to do. And the traffic isn’t only user-to-application anymore. It’s agent talking to agent, moving side to side, so organizations will increasingly have to adopt intent-based protection and secure both north-south and east-west AI traffic. That agent-to-agent lane is where a lot of the action is heading.

Many organizations struggle to balance security, compliance, and user experience. What best practices would you recommend for achieving this balance while implementing Zero Trust principles?

Mithilesh Kumar: A lot of teams chase compliance the way a student crams only for the exam. I’d flip that around: as I always say, compliance is a byproduct of good security practices. Get the security genuinely right and the compliance largely takes care of itself.
The way to keep that balance with user experience is to walk the ladder rather than leap it. Adopt the CISA Zero Trust Maturity Model and build maturity in phases — traditional, initial, advanced, optimal. There will be some overlap between the stages, but moving gradually means your users adapt as you go, instead of everyone hitting a wall of new prompts on the same morning. That’s what keeps security and experience rising together.

Looking ahead, what emerging trends or technologies do you believe will have the greatest impact on enterprise cybersecurity and Zero Trust adoption by 2030?

Mithilesh Kumar: We’ve spent this decade establishing that identity is the perimeter. My strategic vision for the next era is simple: as AI becomes the primary actor, intent becomes the new perimeter. We aren’t moving away from Identity; we are wrapping it in a higher layer of context where the ‘who’ is verified by Identity, but the ‘what’ is validated by Intent-based authorization. The question shifts from who are you to what are you actually trying to do and should you be doing it for both human and non-human entities.

Having led large-scale cybersecurity and digital transformation initiatives, what advice would you give to technology leaders seeking to build resilient, future-ready security organizations?

Mithilesh Kumar: Security is a journey, not a destination, and the Zero Trust Maturity Model is your odometer. It provides the essential visibility required to progress because you simply cannot improve what you cannot measure.

However, leaders today face an additional imperative: we cannot simply wait for legacy frameworks to catch up to the AI era. While we leverage the existing five pillars, we are actively defining a “6th Pillar” of Zero Trust, an extension specifically designed for AI and Autonomous Systems. This is about more than compliance; it is about managing the “Scope of Authority” for our new digital workforce. We are moving beyond verifying who is acting (Identity) to validating what they are trying to achieve (Intent).
By architecting for AI intent today, we are setting the benchmark. We aren’t just reacting to the future; we are actively codifying the standards that the industry will adopt tomorrow.

RELATED ARTICLES
- Advertisment -
Google search engine

Most Popular

Recent Comments