Zero Networks has introduced the Kubernetes Access Matrix, a new tool that provides a real-time visualisation of access permissions within Kubernetes clusters.
This innovation aims to empower both security and DevOps teams with enhanced visibility and control, addressing gaps that currently expose organisations to lateral movement risks.
Understanding Kubernetes governance
Typically, in IT environments, decisions about communication between systems are handled by security and infrastructure teams. However, the decentralised nature of Kubernetes often shifts this responsibility to DevOps teams and developers. This shift can result in a governance gap where network policies are installed in various ways, creating challenges for security personnel to discern what policies are truly enforced.
As Kubernetes ecosystems grow, with increased clusters, namespaces, and labels, managing these policies becomes complex, leading to questions about the real extent of access control. Without clear answers, it’s difficult to ensure real control over network interactions.
Features and impact
Kubernetes Access Matrix turns complex network policies into a clear, intuitive matrixThe Kubernetes Access Matrix simplifies network policy management by converting complex rules into a clear, intuitive matrix. This matrix illustrates policy impacts across namespaces, applications, and workloads, offering a unified view shared between security and DevOps teams.
According to Benny Lakunishok, CEO of Zero Networks: “Kubernetes doesn't fail security teams because it is inherently insecure. It fails because access becomes opaque at scale. When you cannot clearly see who can talk to what, you cannot control blast radius. The Kubernetes Access Matrix makes every connection visible and understandable in seconds, so organisations can reduce risk before an attacker exploits it.”
Challenges in Kubernetes security
The rapid adoption of Kubernetes brings challenges in maintaining security as attackers increasingly target fresh deployments. Reports indicate AKS clusters face attack attempts within 18 minutes and EKS clusters within 28 minutes of deployment.
According to Gartner’s report, many enterprises grapple with inadequate skills and immature DevOps practices needed for effective large-scale production deployments.
Reducing the blast radius
The Access Matrix offers real-time insights into potential movement within a cluster, revealing trust relationships and over-permissive access paths before they can be exploited.
This proactive approach shifts Kubernetes security from a reactive posture to a more resilient, preventive strategy, ensuring that critical services are safeguarded even during security incidents.
Enhanced visibility and control
Onboarding with the Access Matrix involves automatic discovery of existing Kubernetes Network Policies, requiring no manual setup. Teams quickly gain visibility into namespace, application, and workload interactions, with colour-coded indicators to distinguish different levels and types of access.
This capability allows security teams to implement enforceable boundaries directly within the matrix, providing DevOps teams with flexibility while keeping within approved limits.
The Kubernetes Access Matrix is now available as an integral part of the Zero Networks platform, offering immediate utility in advancing organisational security measures.
Zero Networks announced the Kubernetes Access Matrix, a real-time visual map that exposes every allowed and denied rule inside Kubernetes clusters.
The new capability enables security and DevOps teams to see, understand, and control Kubernetes access at scale, closing "understanding what is going on inside K8s” gaps that leave organisations exposed to lateral movement and operational risk.
About Kubernetes
In most IT environments, security and infrastructure teams control what can talk to what. In Kubernetes, that responsibility often shifts to DevOps teams and developers, creating an inherent governance gap. Network policies can be introduced through multiple paths, directly in the cluster or through CI/CD pipelines, making it hard for security teams to understand what is actually enforced and what the resulting blast radius looks like.
As clusters expand, namespaces multiply, and labels proliferate, policies become fragmented and harder to manage. The result is a familiar set of questions: What can talk to what? Where are we unintentionally allowing broad access? What is the real blast radius if something is compromised? If those answers are not clear, control is only assumed, not real.
Features and benefits
The Kubernetes Access Matrix transforms complex Kubernetes Network Policies into a single, intuitive matrix view that shows what can talk to what across namespaces, applications, and workloads.
By translating policy logic into clear visual outcomes, it creates a shared source of truth for both security and DevOps teams.
“Kubernetes doesn’t fail security teams because it is inherently insecure,” said Benny Lakunishok, CEO at Zero Networks. “It fails because access becomes opaque at scale. When you cannot clearly see who can talk to what, you cannot control blast radius. The Kubernetes Access Matrix makes every connection visible and understandable in seconds, so organisations can reduce risk before an attacker exploits it. Built for InfoSec, SecOps, NetOps, and DevSecOps, it bridges the communication gap between groups to turn fragmented oversight into shared accountability.”
Adoption and ability
The result is a widening gap between rapid Kubernetes adoption and the ability to manage it safely, where attackers move in minutes while enterprises are still building operational maturity.
“Bad actors are quick to probe fresh deployments. AKS clusters face their first attack attempt within 18 minutes, while EKS clusters are targeted within 28 minutes of creation,” noted in Wiz’s Kubernetes Security Report: 2025. At the same time, in the report, A CTO’s Guide to Containers and Kubernetes: Top 10 FAQs, (May 2025) Gartner explained, “Kubernetes has become a popular platform for building cloud-native applications, but the key constraints are a lack of adequate skills and mature DevOps practices to operationalise and succeed with large-scale production deployments.”
Reducing blast radius
To close this gap, organisations need visibility that matches the speed of modern threats. The Access Matrix provides a real time understanding of how far an attacker could move once inside a cluster, exposing implicit trust relationships and over-permissive access paths before they are exploited.
Instead of relying solely on detection after compromise, teams can proactively reduce blast radius, protect critical services, and maintain uptime even during a security event. This shifts Kubernetes security from reactive response to proactive resilience, aligning operational maturity with the reality of near-instant attack attempts.
Additional features
Upon onboarding, the Access Matrix automatically discovers existing Kubernetes Network Policies with no manual configuration required. Within minutes, teams can visualise namespace to namespace, application to application, workload to workload, and egress access.
Color coded indicators clearly distinguish full access, partial access, explicit deny, and areas with no defined policy. Users can drill into any connection to view the exact policies, labels, workloads, and ports governing that flow.
More than a visualisation tool, the Kubernetes Access Matrix becomes the foundation for enforceable guardrails across clusters. Security teams can define boundaries and validate them directly in the matrix, while DevOps teams maintain flexibility within approved limits. Policy changes can be validated before deployment, preventing risky access paths from reaching production.
Availability
The Kubernetes Access Matrix is available immediately as part of the Zero Networks platform.