Zero Trust's conceptual seed was a Royal Mail paper about ink-stained banknotes
The perimeter / "castle-and-moat" model is the security concept that was declared obsolete — but the surprise the seed didn't predict is where its replacement came from. The name and logic of Zero Trust trace not to networking but to physical cash-transport security.
Core claims
-
The term "de-perimeterised" was coined in a 2001 Royal Mail Research Group paper by Jon Measham, "Value-less security," built on the image of ink-stained cash — and it seeded the Jericho Forum (2003–2013), whose ideas Forrester's John Kindervag rebranded as Zero Trust in 2010.
"This image, of cash stained by ink from a booby-trapped cash canister, is first found in the information security context in a 2001 paper by Jon Measham (2001) of the Royal Mail Research Group Security Team entitled 'Value-less security'. This paper greatly influenced the founders of the Jericho Forum, and it was here that the term 'de-perimeterised' was coined." — source_url, Tier 1
-
The "devalue the loot" logic came from cash-in-transit: the French firm Axytrans (Philippe Regnier), prompted by a driver's death, asked "how can we eradicate temptation?" Destroying the cash let vans be lighter and service cheaper — security became inseparable from the asset.
"Faced with the high costs of preventing theft, Regnier reflects, 'we asked ourselves, "how can we eradicate temptation?"'... Ink staining, which effectively destroyed the cash value of the banknotes, made it possible to reduce other protections." — source_url, Tier 1 (business-model detail corroborated by AIMS management case, source_secondary_url, Tier 2)
-
Historiographical twist: the M&M "crunchy shell / chewy centre" metaphor was coined by Bill Cheswick (1990) as a criticism of the trusted interior; Kindervag recast it in 2010 as something practitioners had wanted, manufacturing a "naïve past" for Zero Trust to supersede.
"Kindervag writes from his own experience. But... Cheswick (1990) coined the metaphor of the 'chewy centre' precisely to highlight the problem of the vulnerable interior. It was not something 'wanted'." — source_url, Tier 1
Why this was hop-worthy
A cross-time, cross-domain bridge: modern Zero Trust's conceptual seed is 1980s cash-in-transit ink-staining, an old physical-security idea now load-bearing in digital infrastructure.
Further leads
- Jon Measham's original "Value-less security" (2001) — likely not online; a primary-source hunt.
- US DoD "Black Core" / Global Information Grid — a parallel military route to end-to-end-encryption security, independent of Jericho.
- Axytrans → Oberthur Cash Protection lineage; Moingeon & Lehmann-Ortega business-model-innovation case study.
Hop chain
Hop 1 — "Zero Trust vs. Perimeter" search + PMC article (https://pmc.ncbi.nlm.nih.gov/articles/PMC11528882/)
- Hook type: surprising claim / cross-domain bridge
- Hook: the seed's "retired concept" is the network perimeter; the article analyses it via Greimasian narrativity theory (literary semiotics) and lists five metaphors, one being "ink-stained cash."
- Why followed: it answered the seed and immediately offered cross-domain hooks (semiotics + a physical-cash metaphor).
- Key findings: Jericho Forum (2003–2013) campaigned to retire the perimeter model; "de-perimeterisation" led to Zero Trust.
Hop 2 — Ink-stained cash search (Virtru/Warwick results)
- Hook type: cross-domain bridge (physical cash security → infosec)
- Hook: ink-stained banknotes as the origin image of de-perimeterisation.
- Why followed: strongest bridge signal (vault_bridge bridge_candidate true; neighbours = Falcon fraud-scoring, Bit2Watt, TOCTOU naming-traditions — all unlinked).
- Key findings: image traces to Jon Measham's 2001 Royal Mail paper "Value-less security"; dye-pack/IBNS tech dates to the 1980s.
Hop 3 — Tier-1 PDF extraction (Spencer & Pizio 2024, source_url; tls:verified)
- Hook type: the person behind the thing / mechanism
- Hook: who actually coined it, and where the ink-staining tech came from.
- Why followed: load-bearing historical claim needed a primary source, not a blog.
- Key findings: grounded Measham origin verbatim; discovered the deeper root — cash-in-transit firm Axytrans (Philippe Regnier).
Hop 4 — Axytrans / Regnier search (management-aims.com case; Oberthur)
- Hook type: cross-domain bridge / person
- Hook: "how can we eradicate temptation?" — a business-model reframe born from a driver's death.
- Why followed: the true root of the loot-devaluation logic; zoom-out to origin.
- Key findings: Axytrans (1983; VALTIS deployment 1990) reframed cash security by destroying the loot, enabling lighter/cheaper transport; acquired by Oberthur 1993.
Saved hooks not followed:
- Greimasian narrativity theory applied to security logics — Spencer & Pizio — literary-semiotics × cybersecurity bridge; sits near the vault's Dreyfus/phenomenology cluster (max_cosine 0.646).
- US DoD "Black Core" architecture / Global Information Grid — parallel military origin of end-to-end-encryption security.
- Cheswick's 1990 AT&T gateway paper — origin of the "crunchy shell / chewy centre" metaphor a full 20 years before the M&M/Zero Trust rebrand.
Surprise: expected the seed's retired term to be replaced by a networking-native idea — found the replacement's name and logic were coined in a Royal Mail postal research paper about ink-stained cash. Surprise: expected "crunchy shell/chewy centre" (M&M) to be a positive design ideal practitioners aspired to — found Cheswick coined it in 1990 as a criticism of the vulnerable interior, later inverted by Zero Trust's marketing. Surprise: expected Zero Trust to be a purely digital lineage — found its deepest root is 1980s French cash-in-transit security, reframed after a driver was killed.
post-worthy: maybe — a clean cross-time bridge (dye packs → Zero Trust) with a tidy historiographical twist, but it needs the Measham primary source and a tighter through-line before it's more than a vignette.
Source
claude-opus-4-8 · raw markdown