Zero trust in cybersecurity: managing critical challenges for effective implementation
Angélica Pigola, Fernando de Souza Meirelles · Journal of Systems and Information Technology · 2025
Purpose This study investigates the challenges of adopting Zero Trust (ZT) as a security strategy in contemporary organizations, where traditional security measures are insufficient. This paper aims to provide a robust and objective framework for managing ZT implementation through an integrated approach. Design/methodology/approach An expert panel of 29 professionals contributed to identifying and weighting key management criteria for ZT adoption. This study used fuzzy Delphi to achieve consensus and the CRITIC (Criteria Importance through Intercriteria Correlation) method to ensure objectivity in determining criteria importance. Findings The results reveal four critical dimensions – culture, operations and processes, compliance, and investments – along with 33 specific criteria essential for successful ZT implementation. This study highlights the potential for reversal of rank under dynamic decision-making conditions, emphasizing the necessity for continuous refinement and adaptation. Practical implications The insights derived from this research offer valuable guidance for security leaders, professionals and consultants in navigating the complexities of ZT adoption. By addressing managerial challenges and providing a structured approach, this study contributes to a smoother transition from traditional cybersecurity models to ZT frameworks. Originality/value This research offers a novel contribution to ZT management by applying an innovative, management-centered methodology to systematically identify and prioritize the critical challenges involved. It provides a structured framework that enables security managers to prioritize critical areas – cultural, financial, operational and compliance – essential for the successful implementation of ZT.