Zero Trust Moves From Buzzword to Business Necessity

Forrester coined the term, but for years Zero Trust felt more like marketing fuel than an actionable security framework. The premise is straightforward: eliminate the distinction between internal and external access environments, and never implicitly trust users or roles. In practice, the network should only serve applications and data to authenticated and authorized users and devices, with behavioral analytics driving visibility and control.

The model gained traction as high-profile breaches exposed the weaknesses of VPN-centric architectures, compromised endpoints with internal network access, and third-party attacks that exploited access or poisoned software repositories to deploy malicious code. Add SASE (Secure Access Services Edge), Gartner’s framework released around the same time, and the confusion deepened. CISOs were bombarded with competing vendor pitches, each claiming ownership of the next big thing in access security.

Then COVID-19 forced the issue. Lockdowns and remote work pushed some organizations to accelerate access infrastructure modernization. Others, constrained by procurement cycles and prior technology decisions, simply scaled up existing remote access through more licenses and capacity, without addressing employee experience or the strategic gaps in their security posture.

To understand where organizations actually stand, Cloudflare commissioned The Leading Edge to survey 1,006 IT and cybersecurity decision-makers and influencers across Australia, India, Japan, Malaysia, and Singapore in August 2021, all from companies with more than 500 employees.

Zero Trust — Not a Buzzword

The headline result: 54% of organizations reported an increase in security incidents in 2021 compared to the previous year, and 83% of those who experienced incidents said they had to make significant changes to their IT security procedures as a result.

Regional Snapshots: Where the Pressure Shows

Australia

Australian organizations reported the highest pandemic impact on their IT security approach, with 87% of 203 respondents saying COVID-19 had a moderate to significant effect. Sydney and Melbourne each spent over 100 days in lockdown in the second half of 2021 alone, so it's no surprise 48% cited challenges in maximizing remote worker productivity without introducing new device or user risks.

With 94% of Australian organizations planning a hybrid return-to-office model, a uniform security approach is difficult to maintain. Sixty-two percent saw increased security incidents year over year, while 40% struggled to secure adequate funding for security projects. That said, Australia leads the five countries in Zero Trust implementation, with 45% of adopters having started their journey in the past one to four years, consistent with the country's historically fast cloud adoption.

India

India faces a distinct set of conditions: inconsistent Internet connectivity and regular power outages outside city centers. The biggest reported challenge, though, was that organizations could benefit from newer security functionality — a sign that legacy approaches still dominate. Thirty-seven percent also said their access technologies are overly complex.

Security concerns center on the shift in application access: 59% worried that applications are protected by VPN or IP address controls alone, which Zero Trust directly addresses by applying controls to users and devices rather than network location. The human factor is also pressing — 65% identified IT and security staff shortages and cuts as a huge challenge, suggesting simpler access architectures that reduce operational burden would deliver outsized value.

Japan

Japan's experience diverged from the regional trend. Businesses largely continued normal operations through 2020 and 2021, and the pandemic's impact on IT security was noticeably lower. Still, 51% of Japanese respondents reported a moderate to significant impact on their IT security approach. The incident trend held: 45% reported an increase in security incidents, and 63% made changes to IT security procedures in response.

Malaysia

Malaysia had the second-highest pandemic impact on IT security approach at 80%, and the highest rates of employees using home networks (94%) and personal devices (92%) for work. This substantially expands the attack surface, and Malaysian organizations ranked lack of management over employees’ devices as a top risk — 65% expressed concern. They also flagged applications and data exposed to the public Internet and limited visibility into staff activity inside applications. With 57% seeing higher security incidents, 89% made significant changes to IT security procedures.

Singapore

Seventy-nine percent of Singaporean IT and security decision-makers reported pandemic-driven changes to their IT security approach, and two in five said they could benefit from more modern security functionality. Fifty-two percent saw increased incidents, including a notable rise in phishing attempts. Sixty-two percent increased security investment.

Challenges revolved around public Internet-exposed applications, limited oversight of third-party access, and applications protected by username and password alone. Notably, despite Singapore's high-speed home Internet, 40% of organizations reported latency or slow connectivity issues when using VPN, showing that concentration of traffic at a single point degrades performance even in small geographies with ample bandwidth.

Shared Pressures, Shared Priorities

Despite the regional variation, the common threads across Asia Pacific are clear:

  • Cyberattacks continue to rise
  • Flexible work is here to stay
  • Skilled in-house IT security workers are a scarce resource
  • Stakeholder education around Zero Trust remains necessary

IT teams are juggling employee experience, operational complexity, visibility into third-party activity, and tighter controls in response to more incidents. These pressures reinforce a practical conclusion: Zero Trust is no longer an abstract framework for CISOs to evaluate, but a direct response to how work — and attacks — actually happen.