A look at some of the challenges of zero-trust, which creates friction for users and employees as businesses try to fight hackers; only 22% of companies use MFA
Hackers keep tricking employees to gain access to corporate networks, so companies are changing their approach to make it harder to wreak havoc once they're in Tweets: @divinetechygirl , @carter_pe , and @mims Tweets: @divinetechygirl : I get it but I still really dislike the “humans are the weakest link” narrative. 🤷🏽♀️ https://www.wsj.com/... Phillip Carter / @carter_pe : Smart piece on #ZeroTrust by @mims: “The consistent theme is that every component of a system should be skeptical, even if you've identified yourself and gained access, that you are who you say you are and are doing what you should be doing.” https://www.wsj.com/... https://twitter.com/... Christopher Mims / @mims : Hackers have become better organized, more sophisticated and more numerous. Hacking is a real business now, with its own gig economies. But the real reason more big tech companies are getting hacked is: Us. We are the weak link. https://www.wsj.com/... 2/ https://twitter.com/...
Context & Ripple Effects
Christopher Mims' WSJ piece lands a year after the [[a:975313|White House ordered federal agencies onto a zero-trust strategy with hardware-based authentication]], which turned zero-trust from an architecture debate into a compliance clock. The article's contribution is the adoption gap behind the mandate: hackers still get in by tricking employees, and only 22% of companies use MFA, so the model that assumes breach remains a minority practice.
The friction complaint also has a precedent in trust scoring: [[a:940377|fraud-detection services like Sift and SecureAuth already generate user-trustworthiness scores from thousands of opaque signals]], showing how continuous verification trades transparency for security.
First-order effects
- Employees and users absorb the cost immediately: every component of a system stays skeptical even after login, so legitimate workers face repeated authentication and access checks that slow routine work.
- The 78% of companies not using MFA are the exposed population — they lack even the baseline control zero-trust builds on, while adopters must fund the hardware tokens and identity tooling the White House mandate normalized.
Second-order effects
- Vendors of behavioral and device signals — the Sift/SecureAuth model of opaque trustworthiness scoring — gain a second buyer as enterprises seek to verify continuously without adding login friction.
- Security teams will push vendors to reduce the friction zero-trust creates, shifting competition from detection capability toward authentication methods that are both stronger and less intrusive than passwords-plus-tokens.
Third-order effects
- If adoption follows the federal mandate, verification becomes a persistent background layer of enterprise software rather than a login event — and the opacity of trust scoring becomes a governance question, the same accountability gap the Cyber Safety Review Board's failure to examine Microsoft's SolarWinds weaknesses exposed.
- The 'humans are the weakest link' framing Mims' piece challenges may give way to system design as the unit of blame, pressuring regulators to scrutinize architecture rather than employee behavior.
The trend: Enterprise security is moving from perimeter defense to continuous, skeptical verification of every request, with government mandates and trust-scoring vendors setting the pace while user friction sets the ceiling.