Loading summary
A
Foreign. And welcome to this Soapbox edition of the Risky Business Podcast. My name's Patrick Gray. For those of you who aren't familiar, every edition of the Soapbox podcast that we publish here at Risky Business Media is wholly sponsored. And that means everyone you hear in one of them paid to be here. And, you know, that's the usual disclaimer. But I got to add an extra disclaimer on today's soapbox, because today we're chatting with Adam Poynton, who's the chief executive of Knock Knock. And I'm actually on the board of Knock Knock. So very much involved with this business, and yes, clearly, obviously a very big fan of it as well. So for those of you who don't know what Knock Knock is, I mean, I've talked about it a million times on the weekly show, but I'll just give you a very quick recap. The idea behind Knock Knock is it glues SSO to network controls, right? So you've got Octa, you've got a bunch of Palo Alto Networks, or fortnet or, you know, Cisco firewalls, and you've got a bunch of really vulnerable craft at the edge of your network that's accessible to everyone. The idea behind Knock Knock is why not just firewall all of that stuff out, firewall all of that stuff off, and then when someone needs to access it, they log in via sso, as they normally do. Then they can just hit one web app and say, open a port to this service, please. And then in the background, Knock Knock goes, and, you know, adds that IP to a list in the existing firewalls, and all of a sudden the user can access that ip. There's a few more bells and whistles than that, but that's the rough idea. Like, there's a gray noise integration, so if someone's logging in behind a dodgy gateway, you can stop them from being able to do that, and so on and so forth. But the idea here is it massively, massively reduces your exposure to remote code execution from unauthenticated users. Of course, there's an internal use case for Knock Knock as well. There's like a Windows agent that can instrument the Windows firewall. So if you've got a bunch of Windows boxes on your internal network that are all running RDP and you don't think every user should be able to reach RDP on those Windows boxes, you could just Knock Knock those ports, and people can't reach them. So this is the idea. It's all about restricting the ability of unauthenticated users to hit certain network services, both internal and external. And it got me thinking, like, this is a simple idea. So it's kind of crazy that it's taken until like, you know, 2026 for this to become a product that people are buying. And there's a number of reasons for that. And that's kind of the basis of today's conversation, which is zero trust orthodoxy has kind of failed. The market has just delivered us platform after platform of zero trust. You know, Zero trust platforms which aren't really tailored for the real world, whereas Knock Knock is kind of tailored for the real world, which is. It's very simple and it does something very simple. It's very simple to roll out. So we're going to explore this who concept of, like, how zero trust is best thought of as a guiding principle and not as an architecture, which is where I've landed on this since working with these guys. And yeah, that's, that's the basic rundown of the, of the conversation. But we're going to start here, Adam, by really looking at, I guess, the drivers behind Knock Knock's growth at the moment, because things have picked up in a few fairly insane way. Right. Things were going okay last year. Things are going very well now. And the reason behind that is just the risk that people are experiencing when it comes or feeling when it comes to stuff that's exposed to the Internet. And, and I, I guess a good way of thinking about that is, you know, it's, it's a big. It's a big part of this is AI. You know, AI agents are now able to reverse engineer patches from vendors and have weaponized exploits out there owning stuff on the Internet within hours of those patches coming out. I mean, this is really what's changed and what's driving the urgency behind people signing purchase orders for your product.
B
Yeah. Removing Attack Surface has always been the same thing to do. Right. Like, it's always been a bad idea to have things exposed on the Internet. Right. We kind of went from this early firewall days of having a machine exposed on the Internet, all the ports, etcetera, down to let's only allow certain ports port through stateful firewalls, all that kind of thing. But it was always a bad idea to have any host or service on the naked Internet. It just sort of took time for people to find the vulnerability, exploit the vulnerability. And now with AI, it's a proper mess and there's no time to respond. It's too quick.
A
Yeah. I mean, you cited some figures to Me recently, which is this thing called the zero day clock, right. And what they try to do is look at the time between a CVE hitting a database and that exploit to actually turn up in the wild. And that time is like, I mean, you know, it's been coming down for 20 years, right? And now it's like kind of hilariously
B
small, scarily small, same day and like predicted to be within minutes next year, 2027. And that's just the proliferation of AI reversing a patch. You know, taking the CVE, developing an exploit and then running around wild. It's same day is pretty scary. And minutes next year is out of control.
A
I mean you had one when you were, I think when you were at rsa, that was when some Citrix bug dropped, right? Like it was announced and then three days later everything was burning down because of.
B
Yeah, it was RSA this year when I was out there and I think it was 9:31am on the Monday. I remember looking at it and thinking, okay. And then by Thursday, the same week it was reported that there was exploitation in the wild. And that's, you know, a couple of days during, you know, during the week to patch something like that. Pretty, pretty rough couple of days.
A
Yeah, yeah. So we should mention too that even some of the like remote access software, like that's the stuff that you're having to use knock knock to protect. So your Fortinets, your Palo Altos, which were, you know, they're from security companies apparently and they're getting people owned. So the idea is they're putting knock knock. The joke is, yo dog, I heard you like firewalls. So I put a firewall on your firewall. But the idea is you can actually use knock knock to instrument the firewall on a Palo Alto or a Fortinet device to restrict itself from being seen, which is a bit of a concept to get your head around. But Citrix as well has turned out to be a big driver of sales for Knock Knock. So I guess that explains why you were paying attention to that one.
B
Yeah, and it's just, you know, complicated pieces of software sitting on the naked Internet with that sort of walled garden, soft, squishy inside, but complicated exposure stick tack surface on the outside. It's just not a good recipe, right? Knock knocks being brought in, as you say, to add another procedural layer in the order. But it kind of allows them to hide those attack surfaces, which gives them time to respond and all those sorts of things. But the fundamental is hiding assets, removing attack surface, removing exposure comes Back to kind of zero trust concepts, but just an easier way to do it without all of the complicated pieces in the chain.
A
Yeah, I mean, I think where we've landed when we've just been talking about this, you and I, talking about where this is going is stuff like if you're running stuff like Citrix, if you're running stuff like Fortinet on the edge, you are not going to be able to outrun attackers with patching. Right. Like that is just not going to happen. So you've got a couple of options. You can try to ditch those remote access solutions and move to something more contemporary. That's one option. There's some issues there. If it was easy, everybody would be, would be doing that. You can apply a mitigation like knock knock, which actually is going to extend the life you get out of that stuff. But they're your options. Patching ain't going to do it. So then you look at, well, what's left in terms of exposure for the average organization and currently it's all sorts of stuff. It's all sorts of cruft, weird little admin interfaces for equipment that should or should not be published to the Internet, file transfer appliances, payroll systems, all sorts of stuff that just happens to be there. Some Iot stuff or whatever that for whatever reason has to be on the Internet, maybe some RDP or whatever, that stuff is probably going to have to go away or get mitigated with something like knock knock, because again, patching it just ain't going to work. Where I think the effort, though, where the effort is going to go into actually improving something so that it, you know, like something that has to be available. I'm expecting we're going to see a lot of investment into things like the primary applications offered by large enterprises. Right. So if you're an airline, you know, you can't get rid of your online booking system. You can get rid of basically everything else from the edge of your network or the edge of your cloud, if you will, but you can't get rid of your primary applications. Right. So that's where there's going to be this twofold effort in security, I think, where you've got people putting massive effort into improving the quality of their primary applications and taking everything that isn't that into a paddock and putting a bullet in its head.
B
Yeah, it sounds a bit extreme, but yeah, I agree. I think you're going to put all your token. Right. Think about it.
A
So you agree with this, but maybe less violence.
B
Yeah, some tokens will Be slayed and some networks. Look, there will definitely be those systems that go to the paddock and get killed off, but probably not enough of them fast enough. Right. We all know there's going to be legacy systems hanging around for the next 20, 30 years, which is pretty scary to think. But I agree. Put all of your tokens into like your primary application that's exposed to everything and is complicated is like your main thing and everything else you just kind of hide it, you know, put it in layers of, of defenses and yes, they head towards the paddock where they're eventually retired cleanly and nicely and all those things. But I agree with that. I think securing the primary thing and everything else, you sort of have to nurse the vulnerability and nurse those systems through to the end of life.
A
Yeah, I mean, but this, so this is coming back to this central topic that we're, that we're talking about today, which is that I think zero trust as a rigid architecture, as a rigid ideology doesn't really reflect the real world, does it? Like, you know, we've made efforts over the last. I mean this started with the, was it the Jericho forum or whatever and deperimeterization and then Operation Aurora leading Google to do, you know, beyond trust and zero trust stuff. It hasn't really worked in the sense that it can't be all encompassing and we've got this weird situation where the market keeps delivering solution after solution which is an all encompassing, encompassing zero trust solution. Whereas I think you and I would agree zero trust is more of a guiding philosophy. It's something you do where you can not everywhere. Because that's not possible.
B
Yeah, definitely. It's a way of thinking. Right. Like systems should be self defending full stop regardless. And then how you do that depends on what the system is. And it's definitely a way of thought. Right? A way of thinking. It's, it's a discipline. It's a. Sadly, so far there's no software that's kind of got it right I feel. And it's always too complicated. But that idea, well, they've got it
A
right if you wanted to do everything their way, they just haven't got it right. If you actually just. Okay, so a great example is there are products out there that you could put on every single endpoint in a Windows network and they're fantastic. They will really lock down that, that network. But you know, if your primary concern is you've got 100 Windows machines in a data center that are running RDP and you don't think people should be able to access that RDP from the lan. You know, you want to just put software on those 10 machines. You don't want to have to do the whole network, right? So that's like one example, right? And that software meanwhile, it's fantastic, right? But again just the way it's licensed seems a bit weird. And then you've got other ones where they've just like overthought it, you know, like, oh, we'll take your applications and we'll put them in this network sandbox with this and the control and the analysis. And man, can we just have an agent that we put on a box that instruments the firewall to reduce the
B
risk which, you know, you're describing. Knock knock there right back to the kind of it's simple, it just makes systems disappear in a simple way. But I think the other thing, like coming back to the kind of, you know, purest offensive thinker in me from back in the day, systems should be self defending, assume breach, you shouldn't trust anything, etc. If you're kind of installing software and connecting all these systems through this, you know, cloud or through this complicated system that's doing analysis of everything where you're kind of trusting that same stack and environment and vendor or deployment, right. So how we think about it is from a threat model perspective, those systems need to be self defending still. And knock knock kind of operates in that way. But if you're putting in this all encompassing layer that you're talking about or glue between everything that then becomes the risk. So you're not really taking the self defending, zero trust thought pattern either but you know, simple. And actually if you, it depends, it
A
depends because some of these products do allow you to actually apply policies and like this bit shouldn't talk to this bit and whatever, like they do do that now like I think earlier iterations didn't, but they do that now. I don't think that's a fair criticism if I'm honest.
B
Yeah, no, no, it's just more I guess the, the way of thinking having glue between, you know, virtual network layers and that isn't simple. And the Jericho era zero trustee thing is, you know, one of the guiding principles is like keep it simple, you know, you should be able to see what's happening, understand it should be simple and resilient and then as soon as you got all these things that rely
A
on it gets a bit opaque. I see what you mean now.
B
Yeah, yeah, yeah.
A
Well and speaking of that, right, one of the big ztna, you know Cloud ZTNA companies, we won't mention the name, but you play nice with them because there's been these hilarious situations where right now there is a real sense of urgency out there, right. People are just desperately trying to get stuff off the Internet. They're desperately trying to lock down their internal networks as well because they understand that AI enabled lateral movement is fast. Right. So you need to put in some controls now. So, you know, that's, you know, been great for Knock Knock's business, but it's also been great for some of these ZTNA companies. But the funny thing is there's been some unintended side effects. When people go in, they do this huge ZTNA project and then they're like, oh, now we can't admin this, these boxes over here because we've ZTNA everything and it's not compatible with the way that we were adminning them. And the interesting thing there is you've gone in, solved that problem with Knock Knock and then the ZTNA company has come along and said, oh, how would you like to come in on some other deals? Right? And this is just validation that. But of what I was saying before, which is, I think so many of the zero trusty sort of companies, you know, there's an ideological purity that doesn't match the real world, which is, well, hang on, you know, it's good to use this stuff, but we're still going to need access over here that isn't through this CTNA product.
B
Yeah, there's the kind of ideal design and then when you apply it to a real world network, it's like, okay, these are all the exclusions, here's all the workarounds. You know, these are the things that we have to open up because we locked everything down so hard that now actually we can't use it. So rethinking the design in a grayfield's existing environments too hard, right? So you have to accommodate how those environments, networks actually operate, how the business and the humans operate in that. So yeah, it's. To your point earlier, nobody has solved the kind of zero trust everywhere. Everything just magically works in one technology.
A
Because it's not realistic. I mean, that's the whole point, right? It's just not realistic to think that you can do that, that for everything unless you Google. And even then, I reckon if you hit up the right part of Google's internal network with nmap, you're still going to find some, some gnarly stuff.
B
I reckon while hitting it up with nmap. I mean, I guess the brave thing to do would be if Google came out and said we let a bunch of AI just go wild internally and guess what? It didn't get anywhere. That's the ultimate test. I can't imagine that'd be very irresponsible to do, of course, but it's kind of the driver. As you said, people are coming to Knock Knock, going to ZTNA providers, saying the AI thing is here, everything's lateral movement happens, you know, automatically and all those sorts of things. What do we do? We need to control, we need to hide things, we need to, you know, segment them. We need to do that fast though. We can't do a big long project to re architect everything. And you know, that's where Knock Knock comes in and does a great job of that. These three Windows machines, I don't want them always on, always except exposed. Easy put. Knock knock done. You know that, that's taken care of.
A
Yeah, yeah. Well, this is where we're going to introduce a concept here which is zero trust. Ish. Right. Because I think for typical, typical enterprise environments, right, Like a lot of them, the networks, once you get inside, they're pretty flat. Like even the ones that aren't completely flat are pretty flat. So you've got options like you can do a whole network re architecture, micro segment, everything and try to put all of these controls in place. But I think what we're seeing and where Knock Knock is really getting some runs on the board is people come to you and they're like, we've got this flat horror show network. We've identified the 150 riskiest assets on it. We want to put Knock Knock agents on those assets to seal them off from the rest of the network. So they're almost treating, you know, they're almost treating their LAN as the Internet. Like it's a hostile place and just trying to zero trust certain things instead of trying to zero trust all the things. And that's as I say, this is why I'm kind of calling it zero Trust ish networks, right, where you're applying zero trust where you can, you're applying zero trust principles to the riskiest stuff, but you're not doing it to everything because it's too hard and you probably don't need to anyway.
B
Yeah, yeah. And that is the kind of concept around Zero trust really is risk based. What's the riskiest thing? Let's reduce the attack surface, let's reduce the exposure and it's meaningful, it makes a meaningful difference it's easy to do, it's not complicated, they don't need to redesign and they get wins. And like treating the internal network as the Internet hostile external network, like you said earlier, it's about time. And the AI threat is driving that, of course.
A
Zero trust. Zero trust says that you treat every asset, every network connected asset as if it's connected to the Internet. Right. And fair enough, that's hard work, right? So I think what they're doing is they're like, okay, well these things over here can probably get owned. Like that's okay. We can limit the blast radius of that if we are, you know, paying enough attention and detecting and whatever. But these things over here, if they get popped, it's the end of the world. So that's where we're going to, you know, apply those, those principles.
B
Yeah. Which again, like the zero trust issue nails it because assume breach, you know, all of the things is like, well, if we assume breach, these things we actually care about, if they're breach these things over here, you know, lower priority, lower, you know, lower impact overall. Let's just close the, you know, close these issues over here and get that out now instead of waiting.
A
Yeah. If these things over here get owned, it's not, it's not existential, right? And this is funny because a while ago you guys released like a proper Windows agent. So now you can tie your Windows firewalls to like SSO events, right? So user Patricky Biz tries to access RDP ports or whatever ports on a Windows box on the lan. It just says connection closed, connection refused. I go hit a web app, say open up that port please. And then the agent on that Windows machine will open up that port to my IP for a set amount of time, like say 20 minutes or you know, specified by user. What's interesting here is like is the initial sort of batch of customers for Knock Knock are very much around that, instrumenting Palo Alto networks and Fortinet and Checkpoint and you know, all of those sort of big old school firewalls. Whereas when you released this Windows agent, which is go based by the way, just very modern, very modern means it only works so far back though. So you know, good luck running that on your Windows 2000 servers. But, but you release that and I remember saying to you, man, there are going to be customers who come along who only want that. That's actually happened. You've had a couple customers who've got these real Windows server heavy internal environments who've just come along and they're like, yoink, yes please. We need them yesterday. Can you help us install them?
B
Yeah, yeah, it's exactly that. We've got these Windows machines. We, we want to hide them. How can we easily do that? Oh, Knock knock. Okay, done. And then they're looking at, okay, I've also got a palo. They're looking at this to kind of do you know, both sides. But yeah, I think the captive portal for your LAN is another way of thinking about it. Like I, I can't get to any of those, I can't see any of those machines. Those Windows RDP things just aren't there. I have to go to captive portal, single sign or whatever and then suddenly I can connect to those Windows machines internally, which is, it's pretty simple. And the elegance of Knock Knock is that we don't sit in line. There's other benefits around the architecture and the threat model, but that's the experience for people. I used to be able to just see everything and attack everything and now I just go to the simple website and then now I can go to those machines. Simple but super effective. And the Windows people that have those systems that want to hide them, it's, it's, yeah, they love it. It's great.
A
It's great. Well, and I will say now, and this we might have to edit out if we haven't announced by the time this goes out in a couple of weeks. But you know, Knock Knock is succeeding, right? And as a result of that there's been another capital raise, proper seed round this time because it was like, you know, previously you only had a pre seed round and you know, slowly, slowly, then quickly, quickly. What's been interesting though and one of the things that's underpinned this latest capital raise is the variety of organizations that are using Knock Knock. Right. So with a lot of startups you tend to see success in one vertical or another. With Knock Knock, what's really interesting is you're seeing as you say there's these customers who've got like, oh man, we've got all these Windows boxes, we need to take care of them. There's a global farmer that is using Knock Knock on its big firewalls at the edge. There are banks, there are hedge funds, there's like, it's just all sorts of organizations. Even small SME is like that's what's been really interesting here is every customer seems to be from a different vertical and they all have different use cases but it's all using zero trust principles in non zero trust networks. In networks you would not describe as zero trust networks. Universities are a great example though, because they are so good for Knock Knock because they have these absolutely gigantic flat networks full of hostile students. It's so funny.
B
Yeah, yeah. The university is like the real testing ground because you've got an open environment. You're aiming for open, you're aiming for, you know, knowledge. But with that comes complexity. And yeah, I think the reason we're in all of these environments in different industries is because people have said, I have the same. They've just got the same problem. You know, like I want to remove attack surface. Whether it's critical infrastructure, university, whatever, it's the same thing. I want to reduce my problems. You have a solution to the problem, let's deploy.
A
Yeah, but it's a different problem. I mean, it's the same problem, but it's different. It's like I want to reduce my exposure.
B
Yes, Right.
A
But it could be a Windows box running a remote management tool. Like it could have VNC on it and it needs VNC on it because it's some weird ICS thing that they bought 25 years ago. Right? It's like, what do we do? What do we do with that? So you could do it there. You might use Knock Knock because you need MFA on a box on your network to meet some compliance requirement. And Knock Knock is a way to actually apply MFA to that thing. You might want to restrict a OT or ICS jump box. Right. It's a way to do that. But the point is it's all about reducing exposure, reducing network access to risky assets. But what people are doing with that, like which assets it is, it's like a. All the colors of the rainbow, which is fantastic. It's what you want when you're running a startup.
B
Yeah, absolutely. And I think that comes down to our architecture and the approach of taking which is you can't install a Windows agent on some ancient, you know, fancy delivered, HMI ish thing. But because Knock Knock can talk to the firewall that's between the user and that thing, we solve that problem. Or it's a Windows RDP environment which we can run on that solves that. Or they've got Apollo on the edge and you know, they want to remove some other exposure that they've got there. So they'll look at Knock Knock and they're like, okay, proper Swiss army knife vnc. I can hide that thing by doing this and then I can hide my Windows machine by doing that. And it's just easy. Right? Which is, which is why People have, once they understand how it works, then they just like, oh, I can put it there, I can put it there, I can put it there. And it's just removes the attack surface. It does a simple thing, but does it really well. And yeah, it ends up going in different parts of the business and solving different problems, which we love because it's, it's, we, we get the genuine excitement in customers when they're like, oh, I can put it over here and solve this thing that I haven't been able to solve before. We've all just kind of, you know, put it on the risk register and assumed that that VNC thing is just a problem. But until now I haven't really been able to do anything about it.
A
So this is, this is an alternative to the risk accepted stamp. Right. Which is nice, but like, you know, you and I kicking around the idea for this, you know, conversation, last couple of days, you know, we think we're pretty profound by coming up with something that I think most CISOs know, which is when it comes to zero trust, I think this is where we've landed. You know, you cannot be ideological about it. You know, you have to be pragmatic. You just have to do it where you can with the tools that make sense. And I think that's where we are. Right? And that's why it's working. That's why it's working. That's why people are buying it. Which I'm so happy about because regular listeners would know that, you know, I certainly have had a hand in helping this business come out to the market. You know, I've been just thrilled to be a part of this story so far. And it's just so immensely satisfying seeing people actually buy it.
B
Well, yeah, I agree with that, but I actually really get a lot of, I get a kick out of just seeing it be deployed and when people like, you know, I had all these complication and I was trying to work out how to do this and then with Knock Knock, I can just remove, like just remove the problem, like remove the risk, remove the asset. It's just so simple.
A
Well, and then, you know what's really funny is there's all these startups that try to work on their land and expand, right? They try to work on their land and expand strategy. And ultimately, man, you don't need a strategy for land and expand. What you need is a good product. And that's what happens with Knock Knock is people will buy 20 licenses because they've got these like mega risky, like absolutely horror show bits of equipment or applications, they just get a very limited set of licenses, they roll it out, it takes a day, and then they come back and they ask you to quote for like 4,000 licenses. Which is kind of how it goes, right? Like, it's wonderful.
B
Yeah. The really nice one is when it's like the CISO's office and then like the networking team come across and then it's like the other, you know, we vibe coded this thing. Can you also talk to these guys over here and work out how we can solve that problem too? So, you know, it depends on the organization side, but different size, different people within the business coming to us saying, hey, we heard that they bought a thing and it solves their problem. Can you explain how it kind of solves ours over here? So, yeah, it's. It's when you have a good product, a good experience, it actually works. It actually does the thing. It's sad that that's the reason why people get a lot of growth and a lot of adoption, but that's just. That's the reality. And I love being in that space at the moment. Yeah.
A
Yeah. Well, I mean, I think, you know, it was very easy to know that Knock Knock was a winner when early conversations was. You'd explain people to people what it does and they're like, huh, Nobody's done that yet. And it's like, that's. That's, you know, it's a good idea because it's fundamental, it's very simple and it's enables. Enables Zero trust principles in zero trust ish networks. And on that note, Adam Pointon, we're going to wrap it up, mate. Lovely to see you, Lovely to catch up. Lovely to have this conversation. I wish you all the success with this, obviously, and I'll see you at the next board meeting. It's a bit of. A. Bit of a different sort of sponsorship arrangement, this one, but. Yeah, I'll catch you soon, pal. Thanks for the. Thanks for the chat.
B
Thanks, Patrick. Great to be here.
Podcast Host: Patrick Gray (Risky Business Media)
Featured Guest: Adam Poynton (CEO, Knock Knock)
Release Date: August 14, 2026
In this Soap Box edition, Patrick Gray sits down with Adam Poynton, CEO of Knock Knock, to dissect the shifting reality of zero trust security architectures in the modern enterprise. The conversation focuses on why zero trust, as originally conceptualized, has largely failed to fit messy, real-world networks, and why pragmatic, “zero trust(ish)” approaches—embodied by solutions like Knock Knock—are taking off in response to mounting AI-driven threats and legacy system exposure. Key concepts explored include the acceleration of exploit development due to AI, the need for simple controls that fit existing environments, and a candid exploration of what “zero trust” actually means in practice.
What Knock Knock Does:
"Put a firewall on your firewall" ([05:55]):
Selective Application:
LAN as a Hostile Network:
Simplicity Drives Adoption:
Swiss Army Knife for Policy:
Easy Wins, Big Impact:
Rapid Growth:
Diverse Problem Solving:
On the New Attack Landscape:
On Zero Trust Architecture:
“Zero trust as a rigid architecture, as a rigid ideology doesn’t really reflect the real world, does it?”
—Patrick ([10:07])
“It’s a way of thinking... a discipline. Sadly, so far there’s no software that's kind of got it right I feel. And it’s always too complicated.”
—Adam ([10:58])
On Real-World Approaches:
On Knock Knock’s Appeal:
On Customer Excitement:
In this refreshingly candid episode, Patrick Gray and Adam Poynton break down why strict zero trust models struggle in the real world, and why pragmatic, surgical controls—like those enabled by Knock Knock—are gaining traction amid the AI-driven security arms race. The future, they argue, is “zero trust(ish)”: applying strong controls where risk and exposure demand it, using tools that are simple, flexible, and tailored for messy networks, not just clean whiteboard diagrams. The takeaway: security is about pragmatism, not perfection—focus on shrinking risk where it matters most, and let philosophy guide you, not bind you.