trust, but verify

expression

securitygovernance & risk

The old proverb of cooperative suspicion - accept the claim, then check it anyway.

A Russian proverb that Reagan made famous in arms control and IT made a habit. Zero trust sharpened it into 'never trust, always verify': identity and posture are checked continuously, not once at the door.

Trust but verify entered technical vocabulary from arms-control diplomacy, where it described treaties whose provisions were backed by inspection. Applied to systems, it names the position between paranoia and credulity: proceed on the assumption things are working, and independently confirm that they are.

The verification half is what usually gets dropped. A backup job that reports success is trusted; a restore that has never been attempted is the verification nobody ran. A firewall rule believed to be in place, a monitoring alert believed to fire, a failover believed to work: each is a trust that has never been tested, and the pattern is the same one that hope is not a strategy describes from the other direction.

It sits awkwardly beside zero trust, and the tension is worth stating rather than resolving glibly. Zero trust says do not grant access on the basis of network position; trust but verify says do not act on an assumption without confirming it. They are compatible and they are not the same, and using the phrases interchangeably, which happens in vendor material constantly, muddies both.

Also known as: never trust, always verify

All glossary entries