Zero Trust is now increasingly considered a necessity, especially in companies with hybrid-cloud infrastructure, remote work, and users from multiple locations. A survey by StrongDM shows that 81% of organizations have fully or partially implemented the Zero Trust model, especially for cloud security. This is because with more and more applications and data no longer confined to local data centers, traditional network perimeters have become fragile and easy to exploit.
However, the reality on the ground is not always smooth sailing. Many organizations encounter significant obstacles when implementing Zero Trust. For example, most of the tools used are still fragmented—meaning there are many different products that are not fully interoperoperable—making it difficult to apply security policies consistently, especially in multi-cloud environments. In addition, cost issues and resource constraints (both human and technological) often slow down adoption.
In Indonesia itself, the government has taken concrete steps to adopt Zero Trust. One example is the National Data Center (PDN). The government has stated that it will implement Zero Trust methods and AI technology to strengthen network monitoring and multi-layered authentication in response to the PDN hacking incident. This implementation shows that it is not only the business sector that is a concern, but also the public/strategic sector. This signals that Zero Trust is increasingly recognized as part of national security policy.
Current trends also show that Zero Trust is expanding its scope to areas previously considered “peripheral” such as IoT, OT (Operational Technology), and supply chain. Organizations are beginning to understand that connected IoT devices, third-party vendors, and mobile applications used by remote employees can be entry points for attacks. To address this, many are turning to microsegmentation, highly stringent identity and access management, and real-time monitoring tools.
However, the best implementation strategy is often a step-by-step approach. Start by identifying critical assets, evaluating risks, and implementing Zero Trust in one area first—for example, on internal networks, endpoints, or access to critical applications—before expanding to the entire organization. Training for IT teams and stakeholders is also important so that they understand the changes in working styles that may arise (e.g., stricter access controls, more frequent authentication, and activity audits). With careful planning, Zero Trust can become a sustainable security pillar that is adaptive to ever-changing threats.
References:
StrongDM Survey
“Zero Trust Adoption Soars to 81%, but Fragmented Tools and Multi-Cloud Hurdles Remain” (PR Newswire).
Market Report 2025
Zero Trust Network Access Market Report 2025 Forecast (growth & trends in multi-cloud usage, IoT) (GlobeNewswire).
Government Adoption
Local article about the Indonesian government adopting Zero Trust in PDN + the use of AI for network security (Kompas Nasional).
Practical Challenges
Data on practical challenges: fragmented tools, cost constraints, human resources, and interoperability (ZeroThreat / Comtex News).
Security Trends
Additional security trends such as microsegmentation, IoT/OT security, supply chain security (LinkedIn).