Much ink has been spilled about how zero trust is a framework and a mindset, not a product. There’s no single solution that “achieves” zero trust for federal agencies. Even though various security products can help federal and defense agencies meet zero trust security requirements, zero trust is not a product that you buy or a checklist that you complete.
It’s not even an idea that originated in any government security policies, having been pioneered years earlier by John Kindervag at Forrester Research.
Zero trust happens when smart people face a real threat and respond rationally.
I know because I lived it during my 20-year tenure as a communications officer in the Marine Corps.
In the fall of 2013, Iranian hackers embedded themselves in Navy-Marine Corps internet, or NMCI. It was a reconnaissance mission targeting the largest private network in the world at the time. Once they were in, they were able to look at boundaries between classified and unclassified systems and map the entire network.
My mission was simple: shut down servers and quarantine devices so IT teams could then restore and bring them back online clean.
But all I had was a spreadsheet, printed out and stapled at the top, full of unique machine IDs and IP addresses. Commands reported devices I didn’t even have on my list. Machine IDs didn’t match. And we were at headquarters, supposedly the most resourced organization in the enterprise.
We had no live visibility, no enterprise common operating picture, no lines of authority, no communications control. The Pentagon had declared cyber a domain, but we had none of the fundamentals we take for granted in any other military domain.
Take the air domain as an example: we have a COP that shows all of our aircraft and all resources on board those aircraft. We can see a picture of the enemy and where they are in three dimensions.
We have a maritime picture, a threat intelligence picture, and a ground picture. Then we stitch all that together into what we call a single pane of glass where we can see the entire battlespace.
In cyber, I had a spreadsheet.
We were doing zero trust before it had a name
What we needed was what every commander needs: it’s what SolarWinds calls observability, or a live full-stack view of the entire enterprise. What we needed was a nervous system.
Here’s what’s remarkable about Operation Rolling Tide: we were practicing zero trust without calling it “zero trust.”
We called every subordinate commander to verify device ownership. We shut down access wherever we couldn’t be sure, removing implicit trust and operating on the principle of never trust, always verify. We assumed the adversary was already in every corner of the network, treating all activity as potential insider threats.
Assume breach was our starting point. We enforced the principle of least privilege access the hard way, one device and one connection at a time.
The instincts behind zero trust were already in the DNA of every single operator that has ever had to fight through network compromise and sophisticated cyberattacks.
Policies like the National Institute of Standards and Technology (NIST) 800-207 (2020), EO 14028 (May 2021), and OMB M-22-09 (January 2022) formalized what we as practitioners already knew: the adoption of cloud services dissolved the traditional perimeter model, and remote work ensured it never returned.
Why observability is the foundation of zero trust
Traditional continuous monitoring asks, “Is the network up or down? Observability asks “Why?” and “What happens next?” Traditional monitoring is reactive, but observability is service-centric. It collects metrics, logs, traces and events across the entire stack, correlates them, and may use AI and ML for proactive threat detection to predict what’s coming next.
On the watch floor in 2013, I had monitoring, but really what I needed was observability.
This is not a nice to have with zero trust; it’s the foundation under which every zero trust control depends. You can’t enforce least privilege on what you can’t see. You can’t detect lateral movement if you’re not watching. You can’t verify devices you haven’t inventoried.
Every zero trust pillar, users, devices, networks, applications, and data, require real time visibility to function. That truth holds whether you’re sitting at a data center at the Pentagon or whether you’re managing a cloud workload in GovCloud or operating at the forward edge.
The mission doesn’t stop at the enterprise boundary or the network perimeter, and neither does the adversary. You need to have that observability all the way to the forward edge.
This is where platforms like SolarWinds® Observability come in. Agencies need a way to see across hybrid and multi-cloud environments, legacy systems, and edge deployments from a single pane of glass, so they can align their zero trust controls to what’s happening in real time.

How federal agencies “win” at zero trust
The agencies winning at zero trust are not the ones with the biggest budgets or the newest infrastructure; they’re the ones that started with visibility, analytics, and some kind of observability platform. From there, they build out their zero trust roadmap in phases:
See everything. Map every device, user, endpoint, and connection. Establish an authoritative inventory and baseline behavior.
Centralize identity. Implement strong identity and access management (IAM) with single sign-on, multi-factor authentication (MFA), and risk-based access for every access request.
Segment and contain. Use what you can see to build firewalls through microsegmentation and network segmentation, limit blast radius, and slow lateral movement.
Automate response. When the platform detects an anomaly, the response can’t wait for someone to get back to their office and check email. It has to happen in near real time.
Technology and strategy alone won’t solve the gap. It’s often easier to get funding to maintain legacy systems than it is to justify the upfront cost of modernization, but this only creates a massive expanding attack surface that grows faster than any agency can secure it.
Add to that procurement bottlenecks, so the tech is obsolete by the time you’re approved for funding, or organizational cultures where leaders delay transitions to avoid hard problems for their successors.
These aren’t tech problems, they’re human problems and leadership problems. No zero trust framework, VPN replacement, zero trust network access (ZTNA) implementation, or zero trust architecture will address them. But you can’t solve them without observability, and without observability, you cannot prioritize.
Zero trust as doctrine
The hardest part about zero trust comes after you’ve secured leadership buy-in, phased your approach, and deployed your tools: when the warfighter deploys beyond the perimeter to a bandwidth-constrained, intermittently connected, forward-operating environment, observability must go with them.
The battlefield is everywhere, so security must be as well. Zero trust is not a destination, it’s a doctrine.
That night on the watch floor, you had one Marines communications officer, one spreadsheet, 700,000 users and devices, and an adversary already inside the walls.
The lesson wasn’t that we weren’t prepared; it was that our instincts were right, and the tools hadn’t caught up yet.
Zero trust policy mandates are the codification of something every operator already knows. Observability actualizes that at scale.




