ZERO TRUST ARCHITECTURES IN MULTI-CLOUD ENVIRONMENTS: MITIGATING DATA BREACHES AND IDENTITY MISUSE
DOI:
https://doi.org/10.46121/pspc.51.3.6Keywords:
Zero Trust Architecture, Multi-Cloud Security, Identity and Access Management, Data Breach Mitigation, Micro-Segmentation, Privileged Access Management, Behavioural Analytics, SIEM/SOAR, Cloud Security Posture Management, Continuous Authorisation, FIDO2, Software-Defined PerimeterAbstract
The proliferation of multi-cloud deployments — in which enterprises concurrently operate workloads across two or more public cloud providers, private cloud infrastructure, and on-premises data centres — has rendered the classical perimeter-based security model structurally inadequate. The dissolution of a clearly defined network boundary, compounded by the explosive growth of machine identities, service accounts, API integrations, and federated user populations traversing cloud tenancy boundaries, has elevated identity misuse and lateral movement to the dominant vectors in enterprise data breaches. This paper proposes and evaluates a comprehensive Zero Trust Architecture Framework for Multi-Cloud Environments (ZTA-MCE) that operationalises the three foundational Zero Trust principles — verify explicitly, enforce least-privilege access, and assume breach — across heterogeneous cloud provider landscapes. Through systematic synthesis of empirical security outcome data from 47 enterprise deployments spanning financial services, healthcare, government, and technology sectors, the framework demonstrates a mean reduction in identity-related breach incidents of 58.3%, a mean decrease in lateral movement events of 62.7%, and a mean reduction in mean time to detect (MTTD) of 44.1% relative to pre-implementation baselines. The paper systematically characterises the identity plane, data plane, network plane, and workload plane requirements of ZTA-MCE, specifies the AI-driven behavioural analytics, continuous authorisation, and automated threat response architectures required at each plane, and provides a five-stage maturity model enabling structured capability progression for organisations at diverse security investment levels. Implementation barriers — including cloud provider API fragmentation, privileged access lifecycle complexity, and cryptographic key management at multi-cloud scale — and their mitigating architectural patterns are systematically addressed.

