For the Army, the hard part of Zero Trust is increasingly less about defining the concept than applying it across thousands of systems that were never designed for interoperability. The service is working to bring roughly 5,000 information technology systems onto a single Enterprise-Identity, Credential and Access Management (E-ICAM) platform, including legacy systems burdened by years of technical debt. At the same time, Zero Trust requirements are expanding beyond enterprise IT to the tactical edge, operational technology, weapon systems, and now AI agents.
That makes Zero Trust less an endpoint than a continuously changing security model.
“We can’t just buy Zero Trust from a vendor; it isn’t just compliance,” said David Thompson, product lead for E-ICAM at Army CPE Command and Control Information Network (C2IN), participating in a Breaking Defense webinar on Zero Trust. “Our adversaries are not static and the Army must continually work within the ZT framework to adapt to an ever-evolving cybersecurity threat-policy process or technology.”
At the center of that effort is identity. Zero Trust, Thompson said, means that anything attempting to access a resource must first be identified, tied to a credential, and authorized. That requirement goes beyond people to encompass machines and other non-human entities.
“Everything, everything that connects to another thing to access a resource has to be positively identified, strongly bound to credential and securely granted access,” he said. “Everything means literally everything from human users to non-human interfaces and every physical or virtual component in between.”
The phrase often heard today to represent that desired end state is often called “fine grain authentication” and it’s at the heart of Zero Trust, where users, devices, data, and AI agents undergo regular steps of authentication to remain logged in.
Pulling In 5,000 Systems
The immediate challenge is applying that principle across Army systems that vary widely in age and technical capability, with many in existence for decades without keeping pace with modernization. Rather than impose one technical solution across all of them, Thompson said the Army is developing different onboarding pathways and trying to impose the fine-grain access controls that each system can currently support.
He compared the problem to securing a government building. Security can be imposed at the gate, the front entrance, the elevator, interior doors, or even individual desk drawers. But an older building may not contain all of those barriers.
“If the building doesn’t have interior doors or desks, we have to secure what we can today with the expectation that we will support the customer’s future security improvements tomorrow,” Thompson said.
Legacy systems are likely to remain one of the biggest obstacles to full compliance with Zero Trust.
“There is absolutely going to be a significant amount of technical debt that they’re going to have to solve for that,” said Curtis Dukes, executive vice president and general manager of Security Best Practices at the Center for Internet Security, who also participated on the webinar panel. “It may be that you have to look at some of these older systems and they may have to be updated as part of that movement to this new concept around Zero Trust.”
That flexibility is important as the Army drives toward its end-of-2027 deadline for meeting all Zero Trust target milestones. Thompson called getting thousands of systems into a Zero Trust posture by then “a huge goal.”
Among the approaches being pursued is onboarding systems by operational domain rather than necessarily handling every system individually. The Army is also trying to give system owners the ability to perform more of the work themselves.
“We’re trying to pioneer a way to onboard operational domains that may have hundreds or maybe a thousand IT systems within them,” Thompson said. “The Army is also developing a ‘do-it-yourself kit’ so system owners can take actions on their own without having to work with Army CPE C2IN one-on-one. We’re trying to democratize this as much as we possibly can,” he said.
Doing that requires system owners to understand not only what systems and assets they have, but how those systems operate. Thompson said Army teams working directly with system owners have sometimes discovered that the owners themselves lack complete visibility into their environments.
“It’s not one-size-fits-all; every IT system is unique,” he said. “It’s hard, but it’s not because it’s complicated. It’s because it’s very detail-oriented.”

From Identity To Data
The expansion of Zero Trust across enterprises raises a second issue: authenticating and authorizing a user or device does not by itself protect the information that user or device can reach. That means the security controls should extend to the data itself.
Mario Puras, senior vice president of Global Solutions Engineering and Architecture at Netskope, said Zero Trust therefore has to extend security controls to the data itself.
“Zero Trust must go beyond identity and access control,” said Puras, speaking in a separate Breaking Defense interview. “It must encompass continuous verification, rapid threat containment, and full-spectrum data protection. The mission fails if user access is secured but the data is compromised.”
Puras described an approach in which identity, device posture, behavior, content, and other context are evaluated to make dynamic access decisions. That’s done through policy controls at the data level while drawing context from users, devices, network connections, applications, and the data itself, he said. Those policies can then change as the underlying risk changes.
That becomes particularly important as cloud services, APIs, collaboration platforms, and encrypted traffic become part of military environments. Puras pointed specifically to attempts to move sensitive information through API calls, cloud uploads, or chat messages as examples of data movement that Zero Trust architectures may need to inspect and control.
AI And The Tactical Edge Expand The Identity Problem
The definition of identity is also becoming more complicated as AI agents begin operating across networks.
For Thompson, the underlying Zero Trust rule does not change simply because the identity is no longer human. AI agents still need identities, limited entitlements, and least-privilege access.
“It’s not a different way of doing it or different paradigms – same paradigm, but we’ve got to get faster,” Thompson said. He warned that automation could increase the speed at which malicious activity occurs from “a few attacks per minute” to potentially “hundreds of attacks per second, even thousands per second.”
Dukes said agentic AI further muddles the problem because agents may delegate tasks to other agents, requiring organizations to establish and manage trust across chains of non-human identities. He also raised the prospect of unauthorized “shadow agents” and the need to contain agents that behave unexpectedly or are hijacked.
Moving to Zero Trust at the tactical level, the Army faces a different constraint as it’s pushed from enterprise networks toward deployed formations.
At brigade and higher, Thompson said, units can reasonably expect connectivity to Army cloud resources. Below brigade, forces are more likely to operate with denied, degraded, intermittent, or limited connectivity. Those formations therefore need enough E-ICAM capability locally to continue their mission when disconnected and to update information when connectivity returns.
The same Zero Trust principles being discussed for users and devices are expected to also soon apply to operational technology such as industrial control systems and Internet of Things devices, and the individual components that make up complete weapon systems.
Thompson offered the example of a helicopter, where identity attributes could determine whether an individual is authorized to start the aircraft.
“If Dave Thompson is going to go jump in a helicopter, does Dave Thompson have the authority to turn the helicopter on?” he asked. “Again, tying it back to the identity and the attributes of that identity and what that identity is allowed to do and not do.”
That illustrates how far the Zero Trust challenge has moved beyond logging onto a network. For the Army, it increasingly means determining which human, machine, application, or AI identity can touch a particular resource, what that identity can do once it gets there, and how those permissions have to change as the technology, mission, and threat change.
As Thompson put it when discussing operational technology, “it’s not an end state, it’s a continual action.”