---
title: Zero trust security at the movies
description: "You don't have to look too hard to find good and bad examples of zero trust security on the big screen, in everything from \"Monsters Inc.\" to \"Star Trek.\""
image: https://www.merlincyber.com/hubfs/AdobeStock_142389459.jpeg
---

[![Merlin-Cyber-White-Odot_1@4x-1](https://www.merlincyber.com/hubfs/Merline%20Cyber/Images/Merlin-Cyber-White-Odot_1@4x-1.png) ](https://www-merlincyber-com.sandbox.hs-sites.com/home)

[![Contact](https://no-cache.hubspot.com/cta/default/5464151/26d9375d-7d9d-4ed0-86d2-5110f37ecdce.png)](https://cta-redirect.hubspot.com/cta/redirect/5464151/26d9375d-7d9d-4ed0-86d2-5110f37ecdce)

**

# Zero trust security at the movies

 by [Dean Webb](https://www.merlincyber.com/resource-blog/author/dean-webb) | May 6, 2022

 Related Topics: [ Case Studies](https://www.merlincyber.com/resource-blog/tag/case-studies), [ Reports](https://www.merlincyber.com/resource-blog/tag/reports), [ Videos](https://www.merlincyber.com/resource-blog/tag/videos)

[Zero trust security](https://www.merlincyber.com/solutions/zero-trust) is a simple set of principles: continuous verification, limit the blast radius, automate responses. Quite a simple set of ideas to keep track of. As a buzzword, it truly is what it sounds like: zero trust. It doesn’t matter if I trusted something the last time it requested access: I check and check again, repeatedly. I only grant access to what was asked for and cleared, nothing more. And I am watching, always watching…

I suppose that’s why Roz is my favorite character in *Monsters, Inc*. Not only does she practice continuous verification—“I’m watching you, Wazowski. Always watching. Always!”—she also limits access: “This office is now CLOSED!” When Mike Wazowski tries to socially engineer Roz, she’s not having any of it: “Wazowski! You didn’t file your paperwork last night!” Oh, Roz, you had me at “always watching.”

Sadly, such maturity in security is absent in the world of *Star Wars*. “It’s an older code, sir, but it checks out.” Oh, how I cringe at that! And the multi-factor authentication (MFA) sent to the secondary device associated with that code, did that check out? Of course not. Star Wars doesn’t have MFA. That’s why the Sith Lords have to do everything themselves if they want to get anything accomplished.

THE 2022 STATE OF FEDERAL ZERO TRUST MATURITY: [DOWNLOAD OUR NEW REPORT](https://www.merlincyber.com/ztmaturity)

And that flat network on the Death Star… don’t get me started! R2-D2 plugs in to any old network port and has run of the complex. Where is the segmentation? Where is the alert that an [unmanaged device](https://www.merlincyber.com/solutions/network-security) connected to the network? Where is the automated ACL or VLAN change to block that access? These Death Star guys could have seriously benefited from a [Forescout](https://www.merlincyber.com/partners/forescout/?hsLang=en) deployment to address those use cases arising from any old droid jacking into the system.

If there are any *Star Trek* fans chuckling out there, I got bad news for you: those Federation vessels are just as flat and unsegmented as the Death Star. How many times does an alien entity wind up taking control of the entire ship after touching an exposed wire on a bridge terminal? Spoiler alert: it happens at least one more time in the new series of Picard. Well, given how often it happens, that’s not much of a spoiler. But you think the Federation would have done a network path analysis to see what vulnerabilities are exposed to an internal attacker, then moved to close off that access. We have that technology here in the 21st century with [RedSeal](https://www.redseal.net/): Can’t they get some of that secret sauce in the 24th?

While I’m picking on *Star Trek*, let’s look at their poor record on automated responses. Time and again, the Federation faces down the Borg and time and again, it’s a bag of protoplasm giving the orders to other bags of protoplasm punching buttons. No wonder the Borg are the greatest existential threat to the Federation: the Federation has failed to automate. While the organisms ponder, the automations ravage. We can coordinate responses today with products like [Swimlane](https://www.merlincyber.com/partners/swimlane/?hsLang=en); where’s the SOAR on the Enterprise?

One more beef with Federation technology: those holodecks are constantly spilling over into other systems. I can solve those issues with a few [Palo Alto](https://www.paloaltonetworks.com/) firewalls…

After all this, it seems anticlimactic to talk about how zero trust principles would have kept the guys in *Office Space* from putting a virus into the credit union software. Good DLP would have prevented Michael Bolton from copying files to external media and access rights limits would have kept Peter Gibbons from being able to make code changes. Add in an automated code validation process, and Initech would have been saved. In Initech’s defense, it was around in the 1990s, before we knew what we currently know. There’s no excuse, though, for the flyboys up in their star cruisers and Death Stars. Zero trust should have been baked into those platforms. True, it would have forced screenwriters to be a lot more inventive… or maybe they would have just given up on “here’s how someone takes complete control” plot lines. But isn’t that what we ultimately want in real life? Zero trust security principles will make hackers have to be a lot more inventive… or maybe just give up attacking the zero trust organization and go look for an easier target.

[![Eliminate the Strain](https://www.merlincyber.com/hubfs/Merlin%20Ventures/Merlin%20Ventures%20-%20Images/EP-Visibility-AdobeStock_310976948-1030x618.jpeg) ](https://www.merlincyber.com/resource-blog/eliminate-the-strain-0)

[Case Studies](https://www.merlincyber.com/resource-blog/tag/case-studies), [eBooks](https://www.merlincyber.com/resource-blog/tag/ebooks), [Videos](https://www.merlincyber.com/resource-blog/tag/videos)

### [ Eliminate the Strain ](https://www.merlincyber.com/resource-blog/eliminate-the-strain-0)

[![The Critical Role of a People-Centric Approach for Reducing Insider Threats](https://www.merlincyber.com/hubfs/Blog%20banner-Wordpress%20847x321.75-01.jpg) ](https://www.merlincyber.com/resource-blog/critical-role-people-centric-approach-reducing-insider-threats-0)

[eBooks](https://www.merlincyber.com/resource-blog/tag/ebooks), [Data Sheets](https://www.merlincyber.com/resource-blog/tag/data-sheets), [Infographics](https://www.merlincyber.com/resource-blog/tag/infographics)

### [ The Critical Role of a People-Centric Approach for Reducing Insider Threats ](https://www.merlincyber.com/resource-blog/critical-role-people-centric-approach-reducing-insider-threats-0)

[![Choosing the Right Endpoint Security Solution](https://www.merlincyber.com/hubfs/Merline%20Cyber/Images/IIM-Solution-img1.png) ](https://www.merlincyber.com/resource-blog/choosing-the-right-endpoint-security-solution-0)

[Case Studies](https://www.merlincyber.com/resource-blog/tag/case-studies), [eBooks](https://www.merlincyber.com/resource-blog/tag/ebooks), [Solution Briefs](https://www.merlincyber.com/resource-blog/tag/solution-briefs)

### [ Choosing the Right Endpoint Security Solution ](https://www.merlincyber.com/resource-blog/choosing-the-right-endpoint-security-solution-0)

[![More Power to You: Accelerating Energy Modernization](https://www.merlincyber.com/hubfs/Blog%20banner-Wordpress%20847x321.75-02.jpg) ](https://www.merlincyber.com/resource-blog/more-power-to-you-0)

[Case Studies](https://www.merlincyber.com/resource-blog/tag/case-studies), [White Papers](https://www.merlincyber.com/resource-blog/tag/white-papers), [Videos](https://www.merlincyber.com/resource-blog/tag/videos)

### [ More Power to You: Accelerating Energy Modernization ](https://www.merlincyber.com/resource-blog/more-power-to-you-0)

[![Risky Business: How Enterprise Mobility is Transforming the Government – and Introducing New Cyber Threats](https://www.merlincyber.com/hubfs/Imported_Blog_Media/SOCA-AdobeStock_192261203-1030x841.jpg) ](https://www.merlincyber.com/resource-blog/risky-business-how-enterprise-mobility-is-transforming-the-government-and-introducing-new-cyber-threats-0)

[Solution Briefs](https://www.merlincyber.com/resource-blog/tag/solution-briefs), [White Papers](https://www.merlincyber.com/resource-blog/tag/white-papers), [Data Sheets](https://www.merlincyber.com/resource-blog/tag/data-sheets)

### [ Risky Business: How Enterprise Mobility is Transforming the Government – and Introducing New Cyber Threats ](https://www.merlincyber.com/resource-blog/risky-business-how-enterprise-mobility-is-transforming-the-government-and-introducing-new-cyber-threats-0)

[![IGA Tools Ensure that Healthcare Employees Get the Job Done While “Staying in Their Lane”](https://www.merlincyber.com/hubfs/Merlin%20Ventures/Merlin%20Ventures%20-%20Images/GettyImages-736491071-1-17.jpg) ](https://merlincyber.com/)

[Case Studies](https://www.merlincyber.com/resource-blog/tag/case-studies), [Solution Briefs](https://www.merlincyber.com/resource-blog/tag/solution-briefs), [Videos](https://www.merlincyber.com/resource-blog/tag/videos)

### [ IGA Tools Ensure that Healthcare Employees Get the Job Done While “Staying in Their Lane” ](https://merlincyber.com/)

[![IoT security without unplugging everything](https://www.merlincyber.com/hubfs/AdobeStock_275018287.jpeg) ](https://www.merlincyber.com/hubfs/Merline%20Cyber/PDF%20Files/Swimlane_Case_Study_US_Government_Agency-5-1.pdf)

[Case Studies](https://www.merlincyber.com/resource-blog/tag/case-studies), [eBooks](https://www.merlincyber.com/resource-blog/tag/ebooks)

### [ IoT security without unplugging everything ](https://www.merlincyber.com/hubfs/Merline%20Cyber/PDF%20Files/Swimlane_Case_Study_US_Government_Agency-5-1.pdf)

[![Comfort, not Chaos: How to Reduce the Cyber Risk of Healthcare Operational Technology (OT) Solutions](https://www.merlincyber.com/hubfs/Imported_Blog_Media/AdobeStock_306000274-Converted.png) ](https://www.merlincyber.com/resource-blog/comfort-not-chaos-how-to-reduce-the-cyber-risk-of-healthcare-operational-technology-ot-solutions-0)

[eBooks](https://www.merlincyber.com/resource-blog/tag/ebooks), [White Papers](https://www.merlincyber.com/resource-blog/tag/white-papers), [Data Sheets](https://www.merlincyber.com/resource-blog/tag/data-sheets)

### [ Comfort, not Chaos: How to Reduce the Cyber Risk of Healthcare Operational Technology (OT) Solutions ](https://www.merlincyber.com/resource-blog/comfort-not-chaos-how-to-reduce-the-cyber-risk-of-healthcare-operational-technology-ot-solutions-0)

[![Mo Money, Mo [cyber] Problems](https://www.merlincyber.com/hubfs/New%20Merlin%20-%202021/Images/Hero-FINANCIAL-AdobeStock_354007466-BlueG-copy.png) ](https://www.merlincyber.com/resource-blog/mo-money-mo-cyber-problems-0)

[Solution Briefs](https://www.merlincyber.com/resource-blog/tag/solution-briefs), [White Papers](https://www.merlincyber.com/resource-blog/tag/white-papers), [Infographics](https://www.merlincyber.com/resource-blog/tag/infographics)

### [ Mo Money, Mo [cyber] Problems ](https://www.merlincyber.com/resource-blog/mo-money-mo-cyber-problems-0)

##### Stay up to date on the latest cybersecurity news

Share This **

** ** **

<https://www.merlincyber.com/resource-blog/zero-trust-security-at-the-movies-0#mer-sharing-box>

[![Merlin-Cyber-White-Odot_1@4x-300x149](https://www.merlincyber.com/hubfs/Merline%20Cyber/Images/Merlin-Cyber-White-Odot_1@4x-300x149.png) ](https://www-merlincyber-com.sandbox.hs-sites.com/home)

8330 BOONE BLVD, 8TH FLOOR   
TYSONS, VA 22182   
PH: 703-752-2928   
TF: 844-639-1936

 ABOUT

 SOLUTIONS

 MARKETS

 USE CASES

 PARTNERS

 INSIGHTS

Copyright 2026 Merlin International | [Privacy Policy](https://5464151.hs-sites.com/privacy-policy/)

[** ](https://twitter.com/merlin_cyber)

[** ](https://www.linkedin.com/company/merlincyber/) 

         ![](https://ws.zoominfo.com/pixel/61b7abb24261e1001b0077d6)       ![](https://secure.smart-business-foresight.com/268347.png)