Zero trust architecture has spent years securing users, devices, and network perimeters. In Q4 2025, the paradigm expanded into the runtime layer of cloud workloads, addressing a gap that defenders have struggled with since the first containers shipped to production: east-west traffic between services that share a trust boundary by default.

The expansion matters because lateral movement remains the most common tactic adversaries use after initial access. Once inside a network segment, attackers exploit implicit trust between workloads to escalate privileges and exfiltrate data. Applying zero trust principles at the workload level eliminates that implicit trust, requiring every service-to-service communication to authenticate and authorize before data flows.

Aviatrix Launches Zero Trust for Workloads

On November 12, 2025, Aviatrix introduced Zero Trust for Workloads, a new product line built on its Cloud Native Security Fabric (CNSF) platform. The product extends zero trust enforcement to every workload type: virtual machines, containers, Kubernetes pods, and serverless functions, spanning AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure.

Advertisement

CyberTech Your brand belongs here. Reach the decision-makers who read CyberTech every day. Premium placements across the site and newsletter. Advertise with us

CEO Doug Merritt stated: “Zero Trust for Workloads is not just an extension of our platform. It is a new product line that operationalizes pervasive zero trust enforcement for the first time.” The product operates at the network layer without requiring agents or application changes, embedding enforcement directly into the cloud fabric.

Key capabilities include workload-to-internet controls, workload-to-workload microsegmentation, SmartGroups for dynamic traffic isolation by VPC, region, or process, and continuous audit-ready evidence of enforcement posture. Aviatrix also released a free Workload Attack Path Assessment tool that maps lateral movement risk across cloud environments.

Google Cloud Clears Regulatory Hurdle for Wiz Acquisition

The U.S. Department of Justice cleared Google’s $32 billion acquisition of Wiz in October 2025, issuing early termination of its antitrust investigation. The all-cash deal, announced in March 2025, represents the largest acquisition in Google’s history and the biggest pure cybersecurity transaction on record.

Wiz crossed $1 billion in annual recurring revenue in 2025, growing at approximately 40 percent annually. The platform provides cloud security posture management, vulnerability management, and workload protection across multi-cloud environments. Wiz’s agentless architecture scans cloud infrastructure through API connections, identifying misconfigurations, vulnerabilities, and exposed secrets without deploying software to production workloads.

Upon closing (expected Q1 2026), Wiz will join Google Cloud while retaining its brand and continuing to support customers across all major cloud environments, including AWS and Azure. For defenders operating multi-cloud estates, this independence commitment is significant: it means Wiz’s risk visibility will not become exclusive to Google Cloud.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

Zscaler Strengthens Digital Experience Monitoring

On October 29, 2025, Zscaler unveiled innovations to its Zscaler Digital Experience (ZDX) platform that complement its zero trust architecture by ensuring that security controls do not degrade user productivity. New capabilities include Network Intelligence that reroutes traffic around ISP bottlenecks, managed SaaS monitoring with 24/7 multipath insights, and enterprise-wide device health scoring with remote remediation.

EVP of Products Dhawal Sharma noted that “ISP disruptions cause significant outages” and that the innovations “give enterprises end-to-end visibility and control to keep users productive, resolve issues in minutes instead of days.” Zscaler reported a 98 percent reduction in issue detection time with the new features.

Implications for Cloud Security Teams

The convergence of workload-level zero trust enforcement, cloud security posture management at scale (via acquisitions like Wiz), and digital experience monitoring creates a more complete security stack for cloud-native environments. Defenders planning 2026 architecture should prioritize three capabilities: agentless workload visibility that does not require kernel-level access, microsegmentation that operates at Layer 3/4 without application rewrites, and continuous compliance evidence that maps to frameworks like NIST 800-207.

The era of trusting anything inside the cloud perimeter is ending. Q4 2025 made that transition operational rather than aspirational.

Related: Cloudflare Launches Mesh to Unify AI Agent, Human, and Multicloud Connectivity Under Zero Trust Controls