Security

Zero Trust vs. Perimeter Defence: New Research on Enterprise Risk Reduction

A sweeping analysis of security incident data across 500 enterprises asks whether zero trust architecture has delivered on its promise, and what the data reveals about implementation gaps that persist.

MW
Megan Wells
· May 8, 2026 · Security
Network security architecture diagram showing zero trust segmentation across enterprise infrastructure

Key Takeaways

  • Organisations with mature zero trust implementations report 61% fewer lateral movement incidents and a 44% lower mean breach impact cost compared with perimeter-dependent peers.
  • Only 23% of enterprises have achieved what researchers classify as mature zero trust, despite 78% citing it as a strategic priority.
  • The most common implementation gap is identity governance: 67% of partial zero trust deployments have incomplete identity and access management coverage.
  • Organisations that frame zero trust as a network project rather than an enterprise architecture programme consistently underperform on security outcomes.

For years, the security industry has debated whether zero trust architecture delivers measurable risk reduction or whether it is, in practice, another rebranded perimeter with a better marketing narrative. A new body of research from Forrester's Security and Risk practice, drawing on incident telemetry and post-breach forensic data from 500 enterprises across North America and Europe, now provides the most granular empirical answer the field has produced. The findings are striking: organisations that have achieved what the researchers define as mature zero trust implementation recorded 61% fewer lateral movement incidents over the 24-month study period and a 44% reduction in mean breach impact cost. Those numbers are large enough that they should reshape budget conversations at the CISO level, and large enough that they demand careful interpretation of what "mature" actually means.

The research methodology distinguished four implementation states: no zero trust (traditional perimeter-only), early-stage adoption, partial implementation, and mature. Organisations reached the mature classification only when they could demonstrate continuous verification of all user and device identities before granting access, enforced least-privilege access controls across all application tiers, micro-segmented network zones with default-deny policies between segments, and comprehensive access logging with automated anomaly detection. That is a demanding set of criteria. The fact that only 23% of the study population met it, despite 78% of respondents describing zero trust as a stated strategic priority, is one of the study's most telling findings. Intention and execution are separated by a considerable gap.

What the Incident Data Actually Shows

The 61% lateral movement reduction is the headline figure, but the underlying mechanics explain why it is so significant. In a traditional perimeter model, a threat actor who successfully compromises a single endpoint or user credential gains a foothold from which lateral traversal is constrained primarily by internal network segmentation, which in most enterprises is either coarse-grained or inconsistently enforced. In a mature zero trust environment, every lateral move requires a fresh authentication and authorisation decision, one that is evaluated against contextual signals including device health, location, time of access, and behavioural baselines. The attacker who has stolen a credential cannot simply pivot; every attempted movement triggers a new verification challenge that a stolen credential alone cannot satisfy.

The 44% reduction in mean breach impact cost is a separate but related finding. Detection time is the intervening variable: mature zero trust organisations achieved a mean time to detect of 11 days across the incidents studied, compared with 29 days for organisations in the partial implementation category and 47 days for those still reliant on perimeter-only controls. The relationship between dwell time and breach cost is well-established in the security literature. Every day an intruder moves laterally undetected represents additional data exfiltration, additional systems compromised, and additional remediation scope. The zero trust organisations are not only containing the blast radius; they are shortening the timeline within which a breach can inflict compounding damage.

What the research also clarifies is what partial implementation looks like in practice, because it is not simply a less mature version of the same thing. Partially implemented zero trust often means network segmentation has been applied at the perimeter and between major zones, but identity governance has not been extended to cloud workloads, SaaS applications, or privileged service accounts. In those environments, an attacker who compromises a cloud identity may find the internal network segmentation irrelevant because the critical data is accessible through the application layer, which has not been brought within the zero trust perimeter.

Where Zero Trust Is Falling Short

Identity governance is the single most common failure mode in zero trust implementations, appearing as an incomplete or absent capability in 67% of the partial implementations studied. This is not a surprise to practitioners who have worked through these deployments, but the data puts a precise figure on a problem that security leaders often describe in qualitative terms. The pattern is consistent: organisations begin their zero trust journey with network segmentation because it is a defined infrastructure project with measurable milestones, discrete deliverables, and a clear completion state. Network engineers can architect it, project managers can track it, and leadership can see tangible progress. Identity governance, by contrast, is an ongoing programme that touches every application, every user population, every service account, and every cloud entitlement. It has no natural completion state because the identity landscape is in constant motion as applications are added, roles change, and cloud footprints expand.

The SASE convergence trend has added a structural dimension to this challenge. As organisations migrate workloads to cloud environments and adopt hybrid access models, the network perimeter has fragmented to the point where a purely network-centric zero trust approach cannot follow users and data to where they actually live. Secure Access Service Edge frameworks address this by collapsing network and security controls into a cloud-delivered service layer, but SASE adoption without commensurate investment in identity governance simply relocates the same identity gaps to a new architectural plane. The Forrester analysis found that SASE-adopting organisations in the partial implementation category showed no statistically significant improvement in lateral movement outcomes over non-SASE peers when identity governance remained incomplete. The network architecture matters far less than the identity governance architecture.

The research also surfaces a governance problem that is less often discussed: the ownership question. Zero trust architectures that span network, identity, endpoint, application, and data domains inherently require cross-functional ownership, yet 71% of partial implementation organisations had assigned zero trust programme leadership to either the network team or the security operations team in isolation. Neither group typically has the authority or the scope to drive identity governance changes across the application portfolio, negotiate entitlement model changes with business application owners, or enforce least-privilege requirements on cloud workloads managed by DevOps teams. The result is a programme that stalls at the network layer because that is the only layer the programme owner can actually control.

"The organisations that have truly closed the lateral movement gap are not the ones with the best firewalls. They are the ones that can answer a simple question: who accessed what, when, from where, and why. Most enterprises still cannot answer that question reliably."

Dr. Amara Osei, Principal Research Analyst, Forrester Security and Risk

A Prioritisation Framework for Partial Implementers

For the 77% of enterprises currently in pre-mature implementation states, the research suggests a clear prioritisation sequence. Identity governance must come first, specifically the construction of a comprehensive identity inventory that maps every human user, every service account, and every non-human identity to its actual access entitlements across all systems, including cloud workloads and SaaS applications. This inventory is the prerequisite for enforcing least privilege, because you cannot reduce access to the minimum necessary level if you do not know what access currently exists. Most organisations are surprised by the volume of orphaned accounts, over-provisioned service accounts, and standing privileged access they discover when they conduct this exercise rigorously.

The second priority is privileged access management, specifically the elimination of standing privileged access in favour of just-in-time privilege elevation. The Forrester data shows that 84% of the lateral movement incidents recorded in partial zero trust organisations involved the abuse of standing privileged credentials, either stolen outright or escalated from a lower-privilege account. Just-in-time access dramatically reduces the attack surface available for this class of attack, because the privileged credentials exist only for the duration of the specific task they were requested to perform. This is technically achievable with current tooling across both on-premises and cloud environments, and represents one of the highest-return investments available to organisations currently operating with incomplete zero trust.

Third, micro-segmentation should be extended from network zones to the application and workload layer, specifically for the applications that handle the most sensitive data or provide the highest-value access paths for an attacker. The temptation to pursue comprehensive micro-segmentation immediately is understandable but tends to stall programmes because of the discovery and dependency mapping work required. A risk-tiered approach that applies the tightest segmentation controls to the highest-value targets first delivers meaningful risk reduction while the broader programme matures.

The overarching lesson from this research is that zero trust is not a product category or a network topology. It is an architectural philosophy that has to be applied consistently across identity, device, network, application, and data domains to deliver its headline risk reduction numbers. Organisations that treat it as a bounded infrastructure project will achieve bounded results. Those that elevate it to an enterprise-wide architectural programme, with cross-functional ownership and persistent investment in the identity governance foundation, are the ones producing the outcomes that justify the strategic priority designation 78% of enterprises already claim to have assigned it.

Share

More in Security

All Resources →