Zero trust has moved far beyond being just a theoretical framework. For cybersecurity leaders, architects and decision-makers, the challenge is not understanding what zero trust is, instead it is about turning principles into practical plans that deliver measurable results.
That is exactly the focus of the Creating a Zero Trust Roadmap Workshop, a two-day immersive learning experience taking place as a pre-conference workshop on October 24-25 at ISC2 Security Congress in-person at the Gaylord Rockies Convention Center. Led by facilitator Lewis Heuermann, CISSP, the workshop helps participants advance zero trust architecture from a security concept into a clear, defensible and actionable organizational strategy. Participants will earn 16 CPE credits while working through realistic commercial and government scenarios, building implementation roadmaps and developing executive-ready deliverables they can take back to their organizations immediately. 
Moving Beyond "Zero Trust Is a Journey"
One of the most powerful themes from previous workshops was the idea that while zero trust is often described as a journey, organizations still need destinations along the way.
According to Heuermann, a common challenge is that organizations become focused on products rather than outcomes. The workshop helps attendees establish meaningful milestones, create actionable plans and develop a common language that enables productive conversations between technical teams and business leaders.
Participants receive strategic and tactical roadmap tools designed to help assess organizational readiness, identify capability gaps, prioritize initiatives and create phased implementation plans. These practical exercises turn an often-ambiguous concept into a structured path forward.
Real-World Value for Security Leaders
Past attendees consistently highlighted the workshop's practical nature and immediate applicability.
For Michael Marriott, whose organization was actively implementing zero trust within a federal agency, the workshop provided a critical perspective on zero trust frameworks and how they can be applied across both government and commercial environments.
“There is not just one set framework that is recommended for either the federal government sector or the commercial sector,” Marriott said. “They are flexible and you can pick and choose how to apply it to your scenario when implementing zero trust principles.”
For Dr. Margaret (Meg) Layton, CISSP, CSSLP, Director of Security Architecture and Engineering at Children's National Hospital, the workshop arrived at the perfect time. Her organization had already completed foundational modernization efforts and was looking for guidance on the next steps. The workshop helped her prepare executive communications and strategic presentations to advance the organization's zero trust initiatives.
“We’re in the middle of a Zero Trust migration right now,” said Layton. “We have upgraded a number of our devices and put in place a lot of the foundations. This workshop really helped me to make sure that we are ordering our next actions correctly and be able to hold that discussion with leadership.”
Another attendee, Serenity Smile, CISSP, CCSP, described the experience as "enlightening," noting its applicability across corporate, nonprofit, higher education and government sectors. Among the most valuable takeaways was learning how to break complex security challenges into manageable components and leverage established frameworks to justify zero trust investments to stakeholders.
“I’m grateful to participate in the Zero Trust workshop because I really believe that prevention is better than the cure,” Smile said. “Security architecture is a very important principle to help keep organizations safe.”
A common theme emerged among participants: the most valuable deliverable is not a template or framework; it is the ability to effectively communicate a zero-trust strategy to leadership and drive meaningful action after returning to the office.
What You'll Learn
The workshop is built around a structured progression from assessment to action.
Participants will explore:
- Zero trust frameworks, including comparative approaches and implementation considerations
- Assessment of organizational readiness and maturity
- Zero trust pillars and their relationship to real-world threats and vulnerabilities
- Vendor-neutral architecture design
- Gap analysis and capability prioritization
- Governance,risk and compliance integration
- Executive communication strategies
- Development of a phased 18-month implementation roadmap
By the end of the workshop, attendees will have developed a clear roadmap tailored to their environment, along with board-ready materials that help secure support from decision-makers.
Who Should Attend?
This workshop is designed for cybersecurity professionals who find themselves asking questions such as:
- Where do we start with zero trust?
- How do we move beyond technology purchases and build a true strategy?
- Which framework is right for our organization?
- How do we communicate the value of zero trust to executives and boards?
- How do we prioritize initiatives anddemonstrate progress?
The workshop is particularly valuable for mid- and senior-level professionals with decision-making responsibilities, cybersecurity architects, transformation leaders, security managers and practitioners tasked with creating or advancing a zero-trust strategy.
Leave Security Congress with More Than Ideas
Security Congress is known for bringing together cybersecurity professionals to learn, network and explore emerging threats. The Creating a Zero Trust Roadmap Workshop offers something more: the opportunity to leave with a practical plan.
Rather than returning to work with a notebook full of concepts, participants walk away with a strategic roadmap, governance considerations, implementation priorities and an executive-focused communication framework designed to accelerate organizational adoption.
As previous attendees discovered, the workshop helps transform zero trust from a complex industry buzzword into an achievable business strategy.
Register Today
Join cybersecurity leaders from government, healthcare, nonprofit and commercial organizations for this hands-on learning experience at ISC2 Security Congress.
Learn more and register: Creating a Zero Trust Roadmap Workshop
Earn 16 Group A CPE credits, receive a certificate of completion and take home a practical zero trust roadmap you can put into action immediately.