At BATbern57, four major Swiss organisations, Swiss Post, SBB, Die Mobiliar, and PostFinance, shared their experiences implementing Zero Trust. The discussion started with a statement that resonated with everyone in the room: Zero Trust is a journey, not a switch.
Rethinking Security Beyond the Perimeter
For decades, enterprise security was based on the castle-and-moat model: protect the perimeter, control entry through firewalls and VPNs, and assume safety inside. This model no longer works. Cloud migration, remote work, and distributed systems have dissolved the traditional perimeter. In this environment, the notion of “inside” and “outside” simply disappears.
Security can no longer rely on location or network boundaries. It must rely on identity, context, and continuous verification.
What Zero Trust Changes
Zero Trust is not a single product or technology. It is a framework that assumes no implicit trust. Every user, device, or workload must be verified at each interaction. Its principle is simple but demanding: never trust, always verify.
This shift affects how organisations manage access, design networks, and monitor activity. Instead of static rules, Zero Trust creates dynamic, context-aware security policies that adapt in real time.
Key characteristics include:
- Identity-driven access control
- Continuous validation of users and devices
- Least-privilege access across environments
- Visibility and automation for consistent enforcement
The Swiss Perspective: Four Paths, One Vision
Swiss Post
With 70,000 employees and thousands of connected sites, Swiss Post is replacing legacy data centre routing with a Zero Trust foundation built around:
- Zero Trust Edge for ingress and egress
- Network-as-a-Service for internal traffic
- Microsegmentation for consistent policies
This approach simplifies integration, supports hybrid work, and improves resilience.
SBB
Following a 2023 security incident, SBB is moving toward a Secure Access Architecture with policy enforcement points across network, application, and identity layers, maintaining digital sovereignty while increasing control.
Die Mobiliar
Die Mobiliar defines Zero Trust as dynamic access control aligned with CISA and NIST frameworks. Its roadmap focuses on identity, devices, networks, applications, and data, and is supported by a SASE model that unifies networking and security.
PostFinance
For PostFinance, trust equals reputation. Its Zero Trust approach combines ZTNA, microsegmentation, and data loss prevention to manage risk and visibility across cloud and Kubernetes environments. Cultural change and process alignment remain central to its progress.
Lessons from the Field
Across all four organisations, one insight stands out: Zero Trust is not a project with an end date. It is an ongoing transformation in architecture, governance, and mindset.
Several elements consistently determine whether a Zero Trust transformation succeeds or stalls:
Cloud as the driver of change
Cloud adoption forces organisations to rethink traditional security assumptions. It decentralises infrastructure, dissolves network boundaries, and introduces shared responsibility. The cloud becomes both the trigger and the testing ground for Zero Trust — a place where identity, automation, and visibility must converge.
Identity as the new perimeter
In a borderless IT environment, users, devices, and workloads replace the network perimeter. Authentication and authorization become the core of security. Managing identity consistently across systems is now the most effective way to control access and reduce risk.
Automation as the enabler of scale
Manual security processes cannot keep up with the speed and volume of modern infrastructures. Automation allows continuous verification, real-time policy enforcement, and rapid response to threats. It ensures that Zero Trust principles remain operational, not just theoretical.
Collaboration between IT, security, and business, with strong leadership support
Zero Trust requires cross-functional coordination and cultural change. IT and security teams must align with business priorities, supported by clear direction and investment from leadership. Executive commitment is essential to overcome resistance, maintain focus, and ensure that security becomes part of every decision.
Ultimately, Zero Trust works when organisations see it as a practice, not a product.
The Paradox of Trust
One speaker closed with a thought worth reflecting on:
“Zero Trust is only possible if you trust your technology providers.”
Indeed, every organisation implementing Zero Trust depends on technology it does not fully control.
In my opinion, this is where open source plays a vital role. Open source software makes trust verifiable. Its transparency allows anyone to inspect, audit, and improve the code, turning blind reliance into collective assurance.
