The security market is very good at selling the appearance of protection. Here are five things that are true whether or not anyone puts them on a slide — including the one we hold against ourselves.
The MFA most companies deployed was built to stop password guessing — and it's very good at that. But the modern playbook doesn't fight your second factor, it goes around it: push fatigue, adversary-in-the-middle kits that steal the session token after you've completed MFA, SIM swaps and infostealers. The control fires. The attacker still gets in. Move to phishing-resistant factors, and stop treating "we have MFA" as a finished security posture.
A large share of "Zero Trust platforms" weren't built — they were assembled by acquisition, then stapled together under a single brand. You find out during deployment: separate consoles, agents fighting for the endpoint, integrations between modules of the "same" suite that turn out to be on the roadmap. Over-promised architecture, under-delivered integration, and you're the systems integrator now. Ask how old each component is and who originally built it.
Zero Trust exists because implicit trust is the vulnerability. So it's baffling that a whole category answers that by backhauling every packet you own through a vendor's cloud — infrastructure you don't own, can't audit, and can't inspect. You didn't remove the trusted middle. You hired one and put it in the path of everything, with a latency tax, a new single point of failure, and a concentration target carrying thousands of companies' traffic at once. Traffic should go directly to the resource, cloaked, with nothing keeping a copy.
Read: why the exposed appliance became the attack surface →Ask a leadership team how many AI tools they run and you'll hear "two or three." The real number is closer to three to five per employee — connected through OAuth tokens approved in seconds, sending your data off-network by design, invisible to tools looking for malware. You can't govern what you can't see, and right now most companies can't see any of it. The fix isn't banning it. It's making it visible and governing access, not tool names.
Read: Shadow AI is already running on your network →This is the one we point back at ourselves. We don't just sell security — we hold ourselves to it, every day. So don't take our word for any of the above. Ask us the same hard questions you'd ask anyone: after we deploy, what does an external scan of your environment return? Do we carry the traffic or just approve it? Where does your data physically go? What are we letting you turn off? If we can't answer cleanly, don't buy from us either.
See where you actually stand — a two-minute readiness read, no maturity spider chart. Or price cloaked ZTNA + SentinelOne, bundled.
Test Your Readiness → See Pricing →