Abstract
This research investigates the challenges faced by Hong Kong public sector organisations in implementing Zero Trust Architecture (ZTA). Through surveys of 40 IT security professionals, structured interviews with 12 programme leads, and case studies of three departments at different maturity stages, we identify key barriers, partial success patterns, and governance conditions that correlate with measurable progress. Findings suggest that legacy integration and skills gaps dominate technical blockers, while executive sponsorship and phased rollout distinguish departments that move from policy intent to operational enforcement within 18 months.
Introduction
Zero Trust Architecture represents a fundamental shift from perimeter-based security to a model where every access request is verified regardless of origin, device posture, or network location. Hong Kong’s public sector faces accelerated digitisation, hybrid work persistence, and cross-boundary data flows that expose the limits of castle-and-moat designs.
Policy direction across the region increasingly treats ZTA as a baseline expectation rather than an optional modernisation. Departments must reconcile this mandate with decades of mainframe adjacency, bespoke line-of-business applications, and contractor-heavy delivery models. This paper documents how Hong Kong public bodies experience that reconciliation in practice — not as a vendor roadmap, but as an operational programme with owners, budgets, and audit trails.
Methods
We employed a mixed-methods design between October 2025 and March 2026.
Survey. An anonymous online survey reached 40 IT security professionals across 22 public sector organisations. Respondents held titles including CISO, IT security manager, infrastructure lead, and programme architect. Questions covered current ZTA maturity (self-assessed on a five-point scale), top three blockers, budget allocation, and presence of executive sponsorship.
Interviews. Semi-structured interviews with 12 programme leads explored decision history, vendor selection criteria, identity architecture choices, and how departments measured progress. Interviews were coded thematically; quotations are anonymised.
Case studies. Three departments — referred to as Cases A, B, and C — granted HKISG researchers review of redacted programme documents, architecture diagrams, and milestone timelines. Case A achieved identity-centric micro-segmentation for priority systems; Case B stalled at policy without enforcement; Case C adopted a phased SaaS-first approach with measurable MFA and device compliance gains.
Limitations of the method are noted in the Limitations section below.
Findings
Legacy system integration dominates delay
Seventy-eight percent of survey respondents cited difficulties integrating ZTA controls with existing legacy systems. Common patterns included applications that cannot support modern identity protocols, flat internal networks inherited from datacentre consolidation projects, and batch interfaces that bypass interactive authentication entirely.
Case B illustrated the risk of “ZTA on paper”: policies referenced continuous verification, but three critical systems still relied on shared service accounts and static firewall rules because application owners could not fund refactoring within the programme window.
Skills gaps constrain design quality
Sixty-five percent reported insufficient in-house expertise for ZTA implementation. Gaps appeared strongest in identity architecture (conditional access design, privilege tiering), telemetry correlation, and software-defined segmentation — areas where departments often depend on integrators without retaining internal run capability.
Departments that paired external implementation with a mandated internal “control owner” certification path (Case A) reported fewer rollback incidents after go-live.
Budget constraints stretch timelines
Fifty-two percent indicated funding limitations delay implementation timelines. ZTA programmes compete with datacentre refresh, PDPO-related privacy tooling, and end-user device replacement cycles. Respondents noted that multi-year funding envelopes — rather than single-year project bids — correlated with fewer stop-start deployments.
Cultural resistance slows enforcement
Forty-one percent noted organisational resistance to changing established security workflows. Examples included field staff expecting VPN-trust equivalence, developers requesting permanent exception lists, and business units treating MFA fatigue as a reason to weaken policy rather than improve UX design.
Case C reduced resistance by publishing department-specific “before and after” access journeys and measuring helpdesk ticket volume rather than relying on security awareness slides alone.
Success factors
Organisations that adopted a phased approach — identity and MFA first, then device compliance, then segmentation of crown-jewel workloads — demonstrated significantly higher success rates than those attempting enterprise-wide segmentation in year one. Executive sponsorship visible in steering committee minutes, not only slide decks, appeared in all three progressing case studies.
Recommendations
-
Publish a phased ZTA roadmap with named owners. Sequence identity hardening, device compliance, and segmentation; assign a single accountable owner per phase with quarterly evidence reviews.
-
Fund retention, not only integration. Budget for internal staff who can operate conditional access, SIEM use cases, and segmentation rules after vendors depart.
-
Treat legacy exceptions as tracked debt. Maintain a register of systems that cannot meet ZTA controls yet, with compensating controls, review dates, and retirement plans — suitable for Trust Review evidence.
-
Measure enforcement, not policy count. Track MFA coverage for privileged accounts, device compliance rates, and denied-access events — metrics leadership can inspect.
-
Align vendor statements to HKISG evidence standards. When procuring ZTA platforms, require demonstrable integration paths for Hong Kong identity and logging retention expectations.
Limitations
This study relies on self-reported maturity and a modest sample concentrated in departments willing to participate. It does not penetration-test departmental networks or validate control effectiveness through independent technical audit. Case studies are illustrative, not statistically representative of the entire public sector. Vendor relationships disclosed in interviews were not independently verified. Findings describe adoption challenges at a point in time; policy and technology landscapes may shift before 2028 mandate deadlines.
Hong Kong implications
Public sector bodies in Hong Kong operate under heightened scrutiny for personal data handling, cross-border access, and continuity during regional disruption. ZTA programmes that ignore PDPO-aligned logging retention, bilingual support for frontline staff, and contractor access governance may satisfy architecture diagrams while failing operational reality.
HKISG recommends that departments map ZTA milestones to the Programme Calendar assessment windows where independent review is desired, use Security Bulletins for active identity and edge exposure themes, and brief boards with materials from Online Education rather than vendor-only narratives.
Coordination with HKCERT remains appropriate for active incident contexts; this research addresses programmatic architecture, not emergency response.
Hong Kong operator checklist
- Confirm whether the systems, vendors, or practices described apply to your estate.
- Assign an owner and a review date — do not leave findings as unread newsletter content.
- Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
- Brief leadership with a dated one-page note when residual risk remains high.
What “good” looks like
- Controls are operated, not only documented
- Privileged access uses phishing-resistant MFA where feasible
- Detection and response paths are exercised at least annually
- Third-party dependencies have an owner and an exit plan
Sources and further reading
- HKISG Security Bulletins
- Assessment Methodology
- Governance & Integrity
- Online Education
- Wiki: Zero Trust Architecture
- External: HKCERT · PCPD
Editorial note
This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.
Frequently asked questions
Who should read this?
Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims — especially public sector programme leads planning ZTA before mandate deadlines.
Does this change any public HKISG rating?
No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.
How often is this content reviewed?
HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.