It’s possible. Here’s a way to determine if the organization can ignore zero trust altogether:
- There is no shift to the cloud, now or in the future
- The supply chain is wholly owned by the organization or provided by vendors that allow for full auditing and verification
- All assets are self-hosted and managed by the organization
- All user devices are provided and strictly managed by the organization
- All users can be expected to connect from within a pre-determined physical location, not through a VPN
- All users are completely trustworthy at all times with no financial incentive to become compromised
- All users are well-trained in cybersecurity concepts and would never be negligent insiders
- All acquisitions and mergers are extremely audited for the above requirements, or assets are not co-mingled until the above requirements are met