I've long been a proponent of Zero Trust (before it was called that). To flip the concern around, however, what about the connecting end device (e.g. Internet Of Trash)? I don't expect end device security postures to improve in the foreseeable. The network can't fix their postures, but it can ameliorate somewhat; at cost. I observe that for many devices a university network is more hostile than they typically experience in home environments-- where so many problems are avoided with simple stateful inspection within those very small home perimeters.
I long for n=1 options that scale well. The architects run when they see me saunter towards their offices with that n=1 look in my eyes. I even have a theme song that plays for those watching on TV (Greenbaum's "Spirit in the Sky", where I want all the tunnels to terminate for inspection). Crazy in yesteryear, but technology has progressed to where I think it is coming into reach. Simple stateful inspection or full-cone. If someone wants more, they can take that up in software on the end devices and tunnel through perdition's flame. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community