Enterprise Trust — Zero Trust / PKI / IAM / Segmentation
Barbican Cloud designs, builds, and tests the access boundaries — identity, network, and cryptographic — that enterprises actually rely on, not just the ones on the architecture diagram.
Every request evaluated. Every decision recorded.
What We Secure
Different mechanisms, same question at every layer: what's allowed through, and what proves it should be.
Policy enforced at every request, not once at the network edge. Identity, device, and context evaluated continuously — not inherited from a VPN handshake.
Certificate authorities, issuance, and revocation that hold up under audit — not just on the day they were issued. Mutual TLS as a real, tested boundary.
Federation, provisioning, and lifecycle across the identity providers you actually run — SAML and OIDC that behave correctly under real claim mapping, not the demo case.
Boundaries drawn around what matters, not around the whole flat network. Segmentation that survives contact with how the business actually operates.
How We Work
Not a framework for its own sake — the order matters, because each answer changes what the next one has to be.
Scope the actual asset and the actual threat — not the generic checklist someone else wrote.
Audit what's really enforced, versus what's documented as enforced.
The actual mechanism — certificate, token, policy, segmentation rule — and what happens when it's bypassed.
Tested like an attacker would test it, not like a compliance form expects it to be tested.
A boundary people route around isn't a boundary. The measure of success is that nobody has to think about it.
Field Notes
Notes from building the workshop, not marketing copy about it. First pieces in progress:
"Zero Trust" is a marketing term for access control
The industry needed a name for "stop trusting the network." Here's what actually changed underneath it.
What SCIM sync actually breaks in practice
Group membership changes propagate — until they don't. Notes from wiring Entra to Cloudflare Access.
mTLS is the boundary nobody notices until it fails
Client certificates are the quietest access control mechanism in production — and the least forgiving when they expire.