Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when organisations try to do Zero…
Governance, Ownership & Risk

What happens when organisations try to do Zero Trust without defining their crown jewels?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Without clear crown jewels, Zero Trust efforts tend to spread too thin and lose prioritisation. Teams end up protecting everything at once, which usually means protecting nothing well. Defining the most important data, applications, and systems gives security leaders a rational basis for sequencing controls, measuring progress, and demonstrating business value.

Why Zero Trust Stalls Without Crown Jewels

zero trust is supposed to reduce implicit trust, but crown jewels give it a practical starting point. Without that prioritisation, teams often treat every system as equally important, which makes policy design vague, rollout slower, and control decisions harder to defend. The result is usually broad coverage with weak enforcement where it matters most.

That failure is not just theoretical. A crown-jewel definition creates the boundary for where stronger controls, tighter segmentation, and more frequent verification should land first. In practice, it is the difference between an architecture that is sequenced and one that becomes a general security aspiration.

What Gets Lost When Everything Is Protected at Once

When organisations skip crown-jewel identification, Zero Trust programmes lose their ability to rank risk. Security leaders cannot easily decide which applications, data sets, or services need the strictest access paths, so controls tend to be applied by habit, politics, or broad blast-radius assumptions rather than business criticality.

That usually produces one of two patterns: either the programme spreads across too many assets and never reaches depth, or it focuses on infrastructure optics while the most consequential business workflows remain only partially protected. The practical loss is sequencing. Without sequence, it is hard to prove reduction in exposure, justify investment, or show that a particular control change materially improved security.

For workload and service-to-service environments, that sequencing problem becomes even more visible. Identity-centric controls such as Zero Trust Identity Guide and Guide to SPIFFE and SPIRE work best when teams know which services are crown jewels and which are supporting dependencies, because segmentation and authentication depth should reflect actual business impact.

How Crown Jewel Mapping Turns Zero Trust Into a Sequenced Programme

The operational value of crown jewels is that they let you convert a broad principle into an ordered control plan. Once the most important data, applications, and systems are identified, leaders can decide where to start with stronger authentication, tighter authorisation, micro-segmentation, logging, and privileged-path reduction.

That also improves governance. The conversation shifts from “are we doing Zero Trust?” to “are we reducing the highest-value exposure first?” In parallel, IAM and IGA Basics helps with the entitlement side of that sequencing, while Ultimate Guide to NHIs is useful where critical systems depend on service identities, long-lived credentials, or machine-to-machine access. Those dependencies are often part of the crown jewel path even when the business owner does not describe them that way.

Good crown-jewel mapping also makes measurement possible. If you cannot name the most important systems, you cannot credibly measure whether their access paths are getting safer, whether privileged exposure is shrinking, or whether the controls that matter are being deployed in the right order.

Risk and Threat Considerations

Without crown jewels, Zero Trust becomes a diffuse control strategy that can leave the most valuable assets under-prioritised. The main risk is not that nothing gets done, but that scarce effort is spent on low-value surfaces while high-impact systems remain reachable through broad access paths, weak segmentation, or overly generic policy exceptions.

Failure mechanism: Organisations misclassify everything as equally important, so policy design and enforcement become flat instead of risk-based. That makes it easier for an attacker or insider to reach a high-value target through a less-protected adjacent system, shared identity path, or overlooked dependency.

Impact: Security teams lose blast-radius control, control coverage becomes harder to justify, and the programme may create a false sense of progress while the most consequential assets still carry disproportionate exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5RA-9 — Criticality AnalysisCrown jewels require ranking system importance to sequence controls.
Recommendation — Perform criticality analysis to prioritise the highest-value systems and data first.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureZero Trust depends on defining protected resources and policy scope.
Recommendation — Define protected resources and policy boundaries before sequencing Zero Trust controls.
NIST CSF 2.0ID.AM-01 — Physical devices and systems within the organization are inventoriedCrown jewel work starts with knowing which assets matter most.
GV.RM-01 — Risk management objectives are established and agreed to by organizational stakeholdersCrown jewels translate business priorities into security sequencing.
Recommendation — Inventory the assets and services that support crown-jewel classification. Set stakeholder-agreed risk priorities to drive Zero Trust rollout order.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsCrown jewel identification depends on knowing and classifying key assets.
Recommendation — Maintain an asset inventory that supports crown-jewel identification and prioritisation.

Practitioner Guidance

What to prioritise: Start with the few systems, datasets, and workflows that would create the largest business, operational, or regulatory impact if compromised. Zero Trust sequencing should follow that list, not the other way around.

What to verify: Confirm that every candidate crown jewel has an accountable business owner, a defined access path, and a clear dependency map, including machine and service identities where they materially support the asset.

What good looks like: The programme can explain why one system received tighter controls first, what exposure was reduced, and how that decision will be extended to the next tier of assets.

Practitioner takeaway: Zero Trust without crown jewels is usually control sprawl, not control precision, so the first real security decision is deciding what matters most.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org