The Fourth Question Your Zero Trust Stack Never Asks.....
The DC Chapter of the Cyber Breakfast Club is back asking the tough questions for security.
In June of 2025, a red team spent a day quietly living inside a simulated airport’s fuel control system. Not smashing through the front door -implanting, persisting, waiting. The range was ADEGA, a testbed built to look and behave like the OT/ICS/PLC networks running underneath any airport on earth, and the target was picked on purpose: there are, right now, thousands of internet-exposed airport fuel system devices, and thousands more peripherals hanging off them. On day two, the red team pulled the trigger -malware built to dump the fuel load and override the emergency shutdown.
It didn’t work. Not because the exploit was bad. Because the machine it was implanted on had, sometime between day one and day two, been quietly wrapped in a Byos Secure Edge. Persistence broke. The attacker tried to pivot laterally to find another way in and found nothing to pivot through. When the range’s own threat-intel and packet-capture tools were asked afterward what they’d seen, they’d captured every other vendor’s defensive traffic on the range that day. They hadn’t captured Byos’s at all.
That’s a good demo. It’s also the wrong story to lead a CISO conversation with, because it makes Byos sound like a better firewall. It isn’t one. It’s an answer to a question most zero trust architectures never got around to asking.
Four questions, three answered
Most enterprises have built real, expensive answers to the first three. The fourth is the one quietly answered by weak proxies - a certificate, an IP range that looks right, a VPN client that says “Connected,” an MDM check-in from last Tuesday that nobody has verified since. None of those are facts about the present. They’re facts about the past, wearing a green checkmark.
The reason the fourth question gets skipped isn’t laziness. It’s that the first three can all be answered by the endpoint itself, or from software running inside it. The fourth structurally cannot be - a machine cannot be trusted to accurately report on its own location and integrity from the inside, because the moment it’s compromised, that’s exactly the reporting channel an attacker owns. Answering it honestly requires a second physical object, outside the endpoint, that the endpoint doesn’t control.
That’s what Byos Edge Trust is. Not a replacement for your identity provider, your EDR, or your boot attestation. The fourth leg of a chair that’s been standing on three.
Why “outside” has to mean outside
The Byos Edge — the hardware — holds a signing key that never leaves it. Every ten seconds it re-signs a fresh attestation: correct Edge, correct firmware, correct license, correct authentication state, correct routing. Silence past a ~22-second window is read as revocation, not as “probably fine.” The verdict is a three-way split — the trust server holds a hash, the client app holds a salt, the Edge holds the signing key — so that even a fully compromised trust server can’t forge a device binding. Compromise any one piece and you have nothing.
Where it gets interesting is what happens to that verdict. Byos doesn’t gate traffic and doesn’t make the access decision — “Byos reports trust state. Vendors enforce” is the whole architectural philosophy in five words. A grant pushes the device into the Duo trusted cache and the CrowdStrike Falcon trusted host group. A revoke pulls it out of both, in seconds, and swaps the Vault ACL policy so secrets become conditional on device trust in real time. Nothing in the existing stack gets ripped out. Byos becomes a new signal feeding the controls that are already there.
Not your YubiKey. Not your Titan. Not your EDR’s rival.
It’s worth being precise about what this isn’t, because the category is full of things that sound similar and answer a different question entirely.
A YubiKey proves someone was present at the moment of login. That’s genuinely useful, and it’s also the entire lifespan of its usefulness — the moment the tap completes, a YubiKey has no further opinion. It can’t see an unattended machine, an industrial controller, or anything compromised five minutes after authentication. It’s an event. Byos is a condition, continuously re-evaluated.
Google’s Titan is a real hardware root of trust — a genuine secure element, genuinely resistant to a compromised OS forging its signatures. But the entire trust loop lives inside one chassis: the thing being measured, the thing doing the measuring, and the box they’re both bolted into are the same object. Take physical possession of the laptop and you have possession of the whole loop. Titan also attests once, at boot — a machine up for forty days is presenting a forty-day-old opinion about itself, and a stolen device that boots cleanly passes without complaint from anywhere on earth. Byos requires a second physical object the endpoint doesn’t own and can’t read, re-verified continuously, and the verdict is portable to whatever Duo, CrowdStrike, or Vault the customer actually runs — not scoped to one vendor’s ecosystem.
Your EDR isn’t a competitor either — CrowdStrike is a propagation target, not an alternative. An EDR asks the operating system to report on its own health, which is a reasonable thing to ask and catches a large class of attacks. But the agent runs inside the environment it’s assessing, and a sufficiently privileged compromise, a disabled service, or a platform the agent was never built for all produce the same output: silence. Silence looks exactly like health. Byos’s failure mode is the opposite — absence of a valid signature is the negative verdict, not the default one.
Where this actually bites
The theoretical case is nice. The practical case is that a large share of what CISOs and CIOs are accountable for today simply cannot run an agent at all — legacy OT and ICS equipment on the plant floor, PLCs, appliances, brownfield systems that predate the concept of an endpoint agent and never will run one. Byos sits in front of anything with a network interface, agentless, so those assets get a trust signal for the first time rather than a permanent blind spot in the SIEM.
The same logic extends outward to the human perimeter. As a CSfC-recognized Retransmission Device, the Secure Edge hardware meets the NSA’s Mobile Access Capability Package requirements for hardware isolation and protocol break — a hard-wired connection to the end user device, its own DHCP/DNS/NAT, a physically separate connectivity chip from the main processor. On the Apple side, the same architecture protects MacBooks, iPhones, and iPads on untrusted or public Wi-Fi without ever asking whether the endpoint’s own security posture can be trusted — because the model assumes, correctly, that it often can’t be.
The question worth asking your own diagram
None of this requires believing identity, EDR, or boot attestation are doing their jobs poorly. They aren’t the problem. The problem is the fourth question sitting quietly unanswered underneath a stack that looks complete on a slide.
Next time someone walks you through your zero trust architecture, ask it the fourth question: not who, not what software, not did it boot correctly — where is this machine, and is it still there right now? If the honest answer is a certificate and an IP range you’re choosing to trust, that’s worth twenty minutes of your time to go find out what closes the gap.
Byos is based in Ashburn, VA, FIPS 140-2 validated, and built by a team that spends its time thinking about exactly this problem. Learn more at byos.io.
Schedule a technical deep dive and demo with David Stephens (VP- Strategic)
https://www.linkedin.com/in/davidstep/
at david@byos.io
and Matias Katz (Founder/ CEO)
https://www.linkedin.com/in/matiaskatz/
at matias@byos.io.
Those of you who attended our 23 July CyberConnect- DC in Tysons, VA at W2 Communications met David & Matias there (also with Dan Emhof) as they were one of our five technical presenters that day.
Events coming up:
(Save the date and ping me for the zoom link).
The Cyber Breakfast Club - DC
Wed., August 19, 2026 - 7:45 AM to 9:00 AM (EDT) via zoom.
TOPIC: Relatively Risky: Identifying Exposures at Scale with BloodHound Open Graph.
SPEAKER: HD Moore - Founder & CEO at runZero.
*and the Next Breach Tank Meeting
Wed., August 27th
11:00 AM - 12:00 PM EDT, via zoom.
Four Firms TBD:
Zoom link will be sent out.
Startup Registration: https://www.cyberbreakfastclub.com/breachtank-startup
Attendee Registration: https://www.cyberbreakfastclub.com/breachtank






