Why Identity, Not the Network, Has to Be the Perimeter
SC Media, Monday, September 28th, 2026
In Kubernetes and multi-cloud, zero trust must rest on cryptographic workload identity, not ephemeral network location.
An SC Media Perspectives column argues network-based zero trust hits a hard limit in cloud-native environments, where pods scale in seconds and IP addresses constantly change, so leading organizations now ask what a workload is cryptographically and whether it can prove it.
The shift rests on three legs: identity-centric microsegmentation that follows the workload rather than the subnet, workload attestation and continuous risk assessment across multi-cloud estates.
The author warns that static Kubernetes service account tokens and leftover IP allow rules are riskier than they appear.