Est.

Zero-Trust Security Category Creation by Forrester

Naming a security concept proved more powerful than building the technology behind it.

Columnist · · 12 min read
Cover illustration for “Zero-Trust Security Category Creation by Forrester”
Category Origins · September 21, 2026 · 12 min read · 2,758 words

Zero Trust started as a diagnosis, not a product. Before Forrester's John Kindervag put a name on it in 2010, the security industry had already figured out that trusting anyone inside a network perimeter was a bad bet. What it didn't have was a word for that bet, and words are what markets actually trade in.

The Jericho Forum had been saying this since 2003. Paul Simmonds stood up in 2004 and told a room full of security people "so much for the corporate perimeter." He was right. The insight didn't spread far beyond that room.

Meanwhile Google was quietly building BeyondCorp starting in 2009, after Operation Aurora scared the daylights out of their security team. A large government agency had its own version, something it called a "black core" architecture. Three groups, one insight, three different vocabularies. That's not a coincidence, it's what happens when a real problem exists without a shared name for it: everybody solves it in their own dialect, and the market can't hear any of them clearly enough to act.

A good idea with no name is a rumor. It doesn't scale, it doesn't get funded, and a formal purchase proposal never includes it. Kindervag's contribution wasn't spotting the vulnerability. Plenty of people had already spotted it. His contribution was engineering the two words that made the vulnerability impossible to ignore.

How John Kindervag named a vulnerability, not a product

Kindervag published "No More Chewy Centers: Introducing the Zero Trust Model of Information Security" in 2010, and the title alone tells you what kind of thinker wrote it. Chewy centers. Like a security architecture is a piece of candy: hard shell, soft interior, and one bite gets you everything.

The name "Zero Trust" wasn't a product label. It was an accusation. Kindervag's actual line was that most security teams "trust a lot but verify very little," which is a polite way of calling an entire profession lazy about the thing it's paid to be paranoid about. That's not a feature description. That's an indictment, and indictments are memorable in a way that spec sheets never are.

Naming the problem forces a conversation before anyone can pitch a solution. A vendor can't walk into a room and sell "Zero Trust compliant" anything until the buyer has already accepted the premise that their current setup runs on misplaced trust. Kindervag made the confession part of the pitch.

The report itself laid out three founding ideas, and none of them mention a product:

  • Every resource gets accessed securely, no matter where it lives
  • Access control runs on strict least-privilege, all the time
  • All traffic gets inspected and logged, without exception

Notice what's missing. No box to buy. No dashboard to license. Just a standard the whole industry was quietly failing to meet.

Positioning slots you into a category that already exists, like claiming you make the fastest version of a thing everyone already buys, while category creation means you named the shelf before anyone knew they needed one. Positioning slots you into a category that already exists, like claiming you make the fastest version of a thing everyone already buys. Category creation means you named the shelf before anyone knew they needed one. Kindervag built the shelf.

What the category looked like once the name started moving through the market

Diagram: Zero Trust Adoption: From 16% to 61% in Five Years. Visualizes: Show the sharp rise in companies with a defined Zero Trust initiative: 16% in 2018, 55% in 2022, and 61% globally in 2023, all sourced from Okta research.

Google gave Zero Trust its first real-world stage. BeyondCorp had been running internally since 2009, but Google didn't publish the details until 2014, and that publication mattered because it turned an abstract Forrester report into something with a blueprint attached.

BeyondCorp ran on three principles: access isn't determined by which network you're sitting on, access gets granted based on who you are and what device you're using, and every single access request gets authenticated, authorized, and encrypted. Simple enough for other companies to copy, concrete enough that security teams could actually build a project plan around it instead of just nodding along at a conference.

The adoption curve after that tells its own story. Okta's State of Zero Trust research found only 16% of companies had a defined Zero Trust initiative in 2018. By 2022, a separate Okta report put that number at 55%. By 2023, per Okta's own follow-up (cited in 1Password's history of the category), it hit 61% globally.

The adoption jumped sharply rather than gradually. That's a hockey stick, and hockey sticks in adoption data usually mean one thing: the vocabulary caught up with the need, and once it did, everyone could suddenly talk about the same problem using the same words.

There's a specific tell that a category name has actually landed, and it's not stock price or press coverage. It's when a prospect says the term back to you before you've said it to them. Zero Trust crossed that line when procurement conversations began treating it as a baseline requirement rather than an optional consideration. The name had left Forrester's building. It was out in the wild now, living in procurement documents and sales calls it had no supervision over.

Which sounds like a win. It's also exactly when things started to go sideways.

What happens to a category term when its creator loses control of the definition

Kindervag's original trilogy of Zero Trust papers sat behind Forrester's paywall for over a decade. Only Forrester clients and the vendors who could afford a subscription got the primary source. Everyone else got the secondhand version, filtered through whoever had a marketing budget and an incentive to bend the definition their way.

Kindervag has described watching his own concept refracted through what he called the "stained-glass windows of vendor marketing." That's a vivid way of saying: everybody saw a different color of the same idea, and none of them saw the whole picture.

Forrester itself eventually called this out, using words like "hype" and describing a "highly subjective, self-serving perspective" that had colonized a term the firm had built from scratch. That's an unusual thing for a research firm to admit about its own product. It's also an accurate one.

Former Gartner analyst Steve Riley put it about as bluntly as it gets, telling SecurityWeek that "the term 'zero trust' is now used so much and so widely that it has almost lost its meaning." When the person who coined a related sub-term says the parent term has gone mushy, that's not a hot take. That's a diagnosis from inside the building.

And the dichotomy Forrester found itself staring at was almost funny, if it weren't costing everyone money: Zero Trust was simultaneously becoming the default approach to cybersecurity and getting dismissed by practitioners as "just a marketing ploy." Same term, same industry, two completely contradictory reputations, both earned honestly because nobody was minding the definition.

The naming of sub-categories creates issues that are concrete in a way that's almost painful to read. Riley coined "zero trust network access," ZTNA, for a Gartner report in 2019. He's since said publicly he wishes he'd called it "zero trust application access" instead, ZTAA, because the access control in question isn't really about the network at all, it's about the application. He also says it's too late to fix. One analyst, one word choice, and now an entire market segment runs on a name its own creator considers slightly wrong, permanently.

That's language debt. Not a metaphor, an actual cost: buyer confusion, longer sales cycles, vendors talking past each other in the same purchase proposal, and the original category creator's authority eroding a little more with every reinterpretation nobody asked permission for.

How Forrester attempted to reclaim the definition and govern the category

Forrester's answer was to write the definition down, once, in a sentence built to survive contact with marketing departments: "Zero Trust is an information security model that denies access to applications and data by default, a definition built to survive contact with marketing departments." No wiggle room, no room for a vendor to stretch it to fit whatever they were already selling.

A definition like that does something structural. It draws a line, and everyone on either side of it, buyers, vendors, regulators, now has a shared reference point that a glossy brochure can't quietly redraw.

Then came the ZTX framework in 2018, the Zero Trust eXtended Ecosystem, which split the single term into seven pillars. That's the move that turns a phrase into an operating system for a market. Each pillar names its own sub-category, which means each pillar organizes a slice of vendor claims and gives buyers actual evaluation criteria instead of vague reassurance.

Once those pillar names start showing up in RFPs and budget meetings, whoever wrote the framework controls the vocabulary the entire industry negotiates in. That's not a small thing. That's the language equivalent of owning the toll road.

The Forrester Wave reports keep this running on a cycle. The Zero Trust Platforms Landscape, Q1 2025, mapped the major players. Then The Forrester Wave: Zero Trust Platforms, Q3 2025 evaluated ten of them by name: Akamai Technologies, Broadcom, Check Point Software Technologies, Cisco, Cloudflare, Fortinet, Microsoft, Palo Alto Networks, Trend Micro, and Zscaler. That's not a product review. That's Forrester deciding, in public, on a recurring schedule, who's inside the category and who isn't.

A name launches a category. It takes a canonical definition, a structured framework, and a repeating evaluation ritual to actually govern one. If organizations skip any of the three, the vendors will happily write the definition for them, in whatever way sells the most licenses.

What a governed category is worth: the market that the language built

Diagram: The Zero Trust Market in Numbers: From Naming to $148 Billion. Visualizes: Visualize the scale of the Zero Trust security market as a magnitude progression: USD 42.1 billion in 2025, USD 48.5 billion in 2026, and USD 148.3 billion…

The numbers here are large enough to make the whole argument on their own. Grand View Research puts the global Zero Trust security market at USD 42.1 billion in 2025, growing to USD 48.5 billion in 2026, and projected to hit USD 148.3 billion by 2033, a 17.3% compound annual growth rate. Mordor Intelligence puts the figure at USD 41.72 billion in 2025, reaching USD 102.01 billion by 2031 at a 16.07% CAGR. Different firms, different models, same order of magnitude. That convergence is itself a signal. The category's current-year valuations sit in the low-to-mid forties of billions of dollars depending on the source, with long-range projections running considerably higher, regardless of whose spreadsheet you trust.

The pattern holds when looking at just one pillar. ZTNA, the sub-category Riley named and now second-guesses, is on track to go from USD 2.2 billion in 2025 to USD 25.2 billion by 2035, according to Market.us, at a 27.6% CAGR. A slightly-wrong name still generated its own multi-billion-dollar market once it caught on. That tells you something uncomfortable about how much precision actually matters at launch versus how much momentum matters after.

Large enterprises accounted for 59.62% of Zero Trust spending in 2025, per Mordor Intelligence, though small and mid-sized companies are catching up fast, growing at an 18.02% CAGR.

Government mandate turned out to be the biggest amplifier of all. Executive Order 14028 in 2021 told federal agencies to adopt Zero Trust architecture. OMB Memorandum M-22-09 set a binding fiscal year 2024 deadline. The FY2024 federal budget carried USD 11.8 billion in cybersecurity appropriations. The DoD's FY2025 budget request went further, USD 14.5 billion for cyberspace initiatives overall, with USD 977 million specifically earmarked for Zero Trust implementation under the DoD Zero Trust Strategy.

When a regulator writes your vocabulary into policy, procurement budgets start flowing in that vocabulary automatically. Nobody has to be persuaded anymore. The money already speaks the language.

To be blunt about what this actually proves, those billions aren't a reward for better firewalls or smarter access control logic. They're the financial residue of a well-built, then well-governed, piece of language.

How AI is now amplifying whichever version of Zero Trust language an organization runs on

Feeding an AI system an organization's internal language, whether through fine-tuning or just repeated prompting, causes it to produce output at that language's native speed and scale, ambiguities included. If the underlying vocabulary is fragmented, the AI doesn't clean it up. It multiplies it.

Analysts broadly expect generative AI and AI agents to play a real role in pushing Zero Trust adoption and maturity forward. Makes sense: security systems built around human identities now have to account for a growing population of machine identities too, each one carrying its own access profile and its own risk.

That's not a footnote. As AI systems move into safety-critical, decision-making territory, sloppy internal language shifts from a communication problem to an operational one, because the same errors now drive automated decisions instead of human conversations. A confused definition sitting in a policy document is annoying. A confused definition baked into an AI agent's decision logic, running thousands of times a minute, is a different, more serious category of problem.

The symmetry with the Zero Trust story is almost too clean. Definitional drift turned a well-named category into a term practitioners simultaneously trust and mock. An organization with fragmented internal language will watch AI reproduce that fragmentation at enterprise scale, faster than any human review process can catch and correct it.

The same mechanism, flipped around, works in an organization's favor. Clear, canonical, governed language gets amplified just as efficiently as messy language does. The exact quality that made Forrester's canonical definition and the ZTX framework valuable in a human market is what makes them valuable feeding into a machine one.

Which means language governance isn't a nice-to-have that happens after the AI rollout. It's a prerequisite for the rollout going well.

What category creators across industries can take from how Zero Trust was built and nearly lost

The full arc, start to near-collapse to recovery, makes one thing undeniable: category creation was never a naming exercise. It's a language system, and systems need architecture, maintenance, and defense, not just a clever launch.

Kindervag got the founding move right on every count that mattered. He named the problem, not a product. He built the term as an assertion about the world, trust itself is the vulnerability, rather than a feature claim any competitor could match with a slightly better spec sheet. He grounded it in a critique of the status quo specific enough to be falsifiable, which made it hard to argue with and impossible to ignore.

The paywall years show the other side of the ledger. A term with no governing structure behind it doesn't just sit there neutrally, it actively compounds against its creator. Every year of vendor reinterpretation added interest to a debt Forrester eventually had to pay down through active reclamation instead of simple extension.

The fix that worked, in hindsight, needed three layers, not one. A canonical definition draws the line. A structured framework, the pillars, organizes the sub-spaces underneath it. A recurring governance mechanism, the annual Wave report or its equivalent, keeps enforcing the boundary on a schedule so the line doesn't quietly erode again.

Category creators should be actively scouting which regulators, standards bodies, or dominant operators might eventually adopt their vocabulary as policy. Once that happens, the category becomes self-reinforcing, because budgets get written in the language you built.

Riley's ZTNA regret should be remembered every single time a naming decision feels like a minor detail. A term that's merely fine at launch rarely stays a minor detail. A term that's merely fine at launch gets more expensive to fix every quarter it survives, until fixing it is no longer realistic. Precision at the moment of naming is worth more than any amount of correction attempted later, because later correction usually isn't fully possible.

For any company whose technology has outrun the market's vocabulary for describing it, the Zero Trust story carries a fairly uncomfortable moral: being technically correct isn't the finish line. The company that names the problem gets the category. The company that actually governs the name, definition, framework, and recurring enforcement all included, gets the market that grows underneath it.

And it's not just an external market problem. The pattern across Zero Trust implementation points to language and alignment issues between business functions, not technical shortfalls. Narrative infrastructure doesn't stop at the edge of the org chart. It runs straight through the middle of it.

Organizations that treat language as infrastructure, building the canonical documents, governing the definitions, architecting the vocabulary that both their people and their AI systems run on, are doing proactively what Forrester eventually had to do under pressure, after a decade of watching its own term get pulled in six directions at once. Building that discipline early is cheaper than reclaiming it later. Zero Trust is the receipt.

Sources

  1. The History and Evolution of Zero Trust
  2. History and Evolution of Zero Trust Security
  3. The history, evolution, and controversies of zero trust | 1Password
  4. A Look Back At Zero Trust: Never Trust, Always Verify
  5. marketresearchfuture.com
  6. forrester.com
  7. forrester.com
Filed underCategory Origins

More in Category Origins