Iran’s Banking Attacks Prove Zero Trust Pays Interest

Director of Industry Solutions
In mid-June people across Iran walked up to ATMs that had simply stopped working.
Point-of-sale systems froze mid-transaction, and bank balances didn’t match what people knew they had. The attack disrupted Bank Melli, Bank Saderat, Bank Tejarat, and the Export Development Bank of Iran. Some services stayed shaky well into July.
No group has credibly claimed the attack, and Iranian officials say the source is still unknown. It made no difference. A country’s banking system treated like a military target, because as far as the people running these campaigns are concerned, it is one.
Air, sea, and land have always been theaters of war. Cyberspace now sits right alongside them, and that changes the math for every security leader — and not just the ones working in high-risk sectors.
If cyberattacks are acts of war, any company can become collateral damage in a conflict it has nothing to do with. Zero Trust is the only strategy built for that reality.
Cyberspace is the newest theater of war
Striking a country’s banking infrastructure or freezing its ATM network is now discussed with the same seriousness as a missile strike or a naval blockade.
Cyberspace is now a battlefield. The tools and tactics used in state-sponsored conflict are being tested, refined, and eventually recycled, and none of it stays contained to the two countries actually fighting.
The Five Eyes intelligence alliance has already weighed in. It’s told businesses that cybersecurity can no longer be treated as a back-office IT concern.
When an intelligence agency that’s usually focused on tracking terrorists and hostile governments starts talking to boardrooms, it’s a sign the line between geopolitics and everyday commercial risk has effectively disappeared.
You don’t have to be the target to become collateral damage
A bank, hospital, manufacturer, or logistics company can be hit by nearly identical tactics tomorrow. None of them needs any connection to whatever conflict inspired those tactics in the first place.
Most security teams still operate as if their perimeter defenses are the whole story. That mindset assumes an attacker needs a specific reason to target you.
But plenty of attackers don’t need a reason at all in a world where cyberattacks double as geopolitical signaling. They need just one vulnerable system to wreak havoc, and increasingly, they’re using AI to find one faster than ever.
Zero Trust assumes you’re already in the blast radius
This is exactly the scenario Zero Trust was built for.
A Zero Trust architecture doesn’t need to know who the attacker is or why they’re inside the network before responding. It assumes attackers are already there, or will be soon, and focuses entirely on limiting how far they can move once they arrive.
That’s a different posture than most traditional incident response frameworks. Many teams spend precious hours trying to attribute an intrusion before deciding how to contain it.
If a system starts behaving abnormally, segmenting it off immediately matters far more than knowing where the traffic came from. It doesn't matter whether it’s a hostile government or a criminal group renting the same tools.
There’s no neutral side in the cyberwar
AI is shrinking the gap between a state-sponsored campaign and a copycat attack on an unrelated company. Techniques that once stayed locked inside classified briefings now show up in common attack kits within months.
Unfortunately, some teams still treat Zero Trust as optional. They tell themselves they’re not geopolitically significant enough to be a target.
But those are the ones most likely to learn the hard way that significance was never really the point.
There’s no neutral ground in this kind of war, only security teams that contain the blast radius in time and those that didn’t. Assume you’re already a target, and let Zero Trust handle the rest.


