Your zero-trust programme has no budget for its last 20%, so the legacy path an attacker prefers stays up — how do you get the ending funded?
answer
- value only lands at the ending
- price the double estate, not the ending
- exceptions need owners and expiry dates
- retire paths, not applications
- eighty percent invested, zero realised
basics
~20 sStop selling migration and start pricing the double estate. Put a dated, owner-signed expiry on every application left on the legacy path, and sequence the next wave to retire a whole path rather than easy applications.
solid answer
~50 sThe value only lands when a path dies, but the money was allocated per application migrated, so the last twenty percent - the vendor app without modern authentication, the till platform, the appliance - has no sponsor. I would reframe the ask as the running cost of holding two estates: the circuit contract, the rented edge subscription, two policy reviews, two sets of access evidence, and an exposure whose real admission test is a source address on a shop network. Then I would move the decision to people who can refuse it, giving every remaining application a named business owner, a dated exception and a signed acceptance renewed at a named forum. I would sequence the next wave to empty a path rather than bank easy wins, and report the programme as zero percent realised until a path is switched off.
go deeper
Understand that a migration only reduces risk when the old way in is switched off, and that switching things off is work somebody has to pay for and schedule.
Be able to explain why the last applications are the hardest — vendor software, appliances, support contracts — and why leaving one of them on a path keeps the whole path alive for everything else.
Show how you would sequence remaining waves so each one empties a route or a zone, and how you would narrow the legacy path around applications that genuinely cannot move.
Own the funding argument and the reporting: price the double estate against a dated ending, put signed and dated exceptions in front of business owners who can refuse, and change the completion metric to paths retired even though leaders will not like the first number.
## Why the ending is always unfunded Migration programmes are funded per unit of visible progress: applications moved, shops enabled, users onboarded. Decommissioning produces no demo. It produces an absence — a circuit that is no longer billed, a firewall policy that shrinks, a front door that stops existing — and absences do not get their own budget line. So the predictable end state is the one you are in. Eighty percent of applications are behind the broker, the twenty percent left are the ones nobody wants (a vendor application that cannot do modern authentication, a till platform under a support contract that forbids changes, an appliance whose supplier is out of business), and because those twenty percent still need the legacy path, the path stays up — which means the eighty percent got a stronger front door and the estate got a second one, not a replacement. ## Reframe the ask: price the double estate Stop asking for money to "finish zero trust". Ask for a decision between two costed options: keep running two estates indefinitely, or fund an ending with a date. The running cost of two estates is concrete and mostly already being paid by someone: | Line | Owner who feels it | | --- | --- | | Private circuit contract, unchanged | Network budget | | Rented edge subscription | Security budget | | Two policy sets reviewed and reconciled | Engineering time, every quarter | | Two incomplete access records at audit | Whoever answers the auditor | | Standing exposure of the least-watched path | Nobody, until it is everybody | That last line is the one you must state plainly and without melodrama: for any application still reachable over the circuit, the effective admission test is position on a shop network, and it is now the path with the least engineering attention because attention followed the new project. ## Move the decision to someone who can refuse An unfunded risk with no owner is a risk that persists. Convert it into a decision that a named person has to make repeatedly: - Every application still on the legacy path gets a **named business owner**, not an IT owner. - Each gets a **dated exception** — an expiry, not a status. Exceptions without dates fund nothing; exceptions with dates create a meeting. - Each expiry is renewed at a **named forum** with the owner present, and renewal is a signature, not a silence. This does not create budget by itself. It creates the only thing that reliably does: a recurring, minuted moment where someone senior must either pay to end it or personally accept it again. Two or three renewals in, the accounting usually changes. ## Sequence to retire paths, not to bank wins The second lever is the rollout order, and it is where most programmes lose. Migrating twelve easy applications and leaving one hard one on the circuit retires nothing; migrating three applications that happen to be the last things on one route lets you switch the route off. So choose the next wave by what it lets you **turn off**, not by how quickly it moves the application counter. A wave that ends with a path retired produces a real saving to point at, and that saving is the argument for the next wave. This is also the point where you may honestly recommend *stopping* breadth: spend the remaining money killing one path completely for a subset of the estate, rather than adding a thin new path everywhere. ## Handle the genuinely immovable Some of the last twenty percent will not move. For those, the goal shifts from migration to isolation: the application keeps the legacy path, but that path is narrowed until it reaches only that application from only the networks that need it, with the exception dated and signed. That is a much smaller surviving surface than "the circuit is still up", and it can often be delivered with the money you already have. ## Report honestly The reporting change is the hardest and the most valuable. Until a path is retired for an application, that application's risk is unchanged, so the programme is not eighty percent done — it is eighty percent invested and zero percent realised. Leaders will not enjoy the sentence, but it is the sentence that funds the ending, and stating it is the job. Pair it with the date you propose for the first path retirement and the cost of getting there, so the conversation is about a plan rather than a complaint. ## How to answer well Name the structural cause in one sentence, price the interim state, put dated owner-signed exceptions on the remainder, sequence waves to empty paths, and change the completion metric. If you also say which of these you would do first with no new money — the exceptions and the reporting, because both are free — you have answered as someone who has actually held this programme.
- A business owner refuses to accept the risk and refuses to fund the move. What then?Then it escalates, because the refusal is itself a decision that needs an owner above them. In the meantime I would narrow rather than wait: shrink the legacy path so it reaches only that application from only the networks that genuinely need it, keep the dated exception open, and record the refusal in the forum minutes. What I would not do is quietly absorb it into the security team's risk register, where it becomes invisible and unfunded forever.
- How do you choose which application moves next when everything left is hard?By what it lets me switch off. I would map each remaining application to the paths it keeps alive and pick the smallest set whose migration empties one route, one circuit or one zone entirely. Retiring a path produces a saving and a demonstrable risk reduction, which funds the next wave; migrating three more applications while every path stays up produces neither.
- What do you say when the board asks whether the programme was worth it?That the pattern is proven and the risk reduction has not been banked yet, because for any application still reachable over the old path the effective control is unchanged. Then give the number that matters — paths retired, currently zero or one — the date for the next retirement and its cost. Framing it as a plan with a date is what keeps it a funding conversation rather than a post-mortem.
saying these in an interview costs you the question
- Asks for budget to finish rather than pricing the interim state
- Leaves undated exceptions with no named owner
- Sequences waves by ease instead of by paths retired
- Reports percentage of applications migrated as risk reduced
- Parks the residual risk in the security team's own register