Explain like I'm five · Security
What is Zero Trust?
Zero Trust, told as a story about a castle where every door asks again.
The old castle only guarded the gate.Once you were in, you could go anywhere.
Being inside doesn't make you trustworthy.A stolen hat gets you through the gate — without even leaving a footprint.
Zero Trust is the castle where every door asks.Even past the gate, each room asks again.
Who are you?face, hat, and a password
Any business in this room?only the rooms you need
All good right now?no mud on your shoes?
One key, one room, for a while.A kitchen key won't open the vault, and it stops working after a while.
Asking every time is a bother.So a machine checks faces in a second. It's not "trust no one" — it's "check, then trust."
In one breath
Zero Trust = the castle that asks again at every door, even past the gate. One key, one room, for a while.
Nothing is trusted just for being inside the walls. Named by John Kindervag in 2010; written up by NIST as SP 800-207 in 2020.
When grown-ups say it
- Perimeter security
- Guarding only the gate. The old way. Also called castle-and-moat.
- Identity / MFA
- Who are you? One face isn't enough, so the hat and a password are checked too — that's multi-factor authentication.
- Least privilege
- A key to one room. Only the rooms you need, only while you need them.
- Device posture
- Mud on your shoes? The computer they brought is checked too, not just the person.
- Micro-segmentation
- A guard at every door. Chop the hallway into pieces so one open room doesn't open the next. → the hallway story
- Continuous verification
- Still watching after you're in. Getting in isn't the end. The dog keeps watching.
- NIST SP 800-207
- The rulebook. The 2020 Zero Trust guide from the US standards body.
Next story
A Ticket, Not the Key →