As attackers exploit valid stolen logins to move undetected through corporate networks, SonicWall Platinum Partner choin! explains why Zero Trust is becoming unavoidable — and why mid-market customers still hesitate.
Zero Trust platforms are meant to replace perimeter-based cybersecurity, and the technical logic is hard to argue with. Yet many mid-market customers are still slow to adopt it. Cybersecurity specialist choin! and SonicWall Regional Manager Germany Johannes Dahmen explain why the shift is happening anyway.
The classic access model — prove who you are once at the door, then move freely inside — has become one of the biggest liabilities in enterprise IT. Once an intruder is past that door, nothing stops them from going anywhere else on the network.
“Stolen credentials — usernames and passwords — are a massive problem. We run into these cases again and again with our customers,” says Boris Wetzel of choin!, a SonicWall Platinum Partner. The hard part, he explains, is that so-called lateral movement — attackers roaming a compromised network largely undetected — is notoriously difficult to prove. Security tools rarely raise an alarm, because the intrusion is happening with valid credentials.
The problem is as old as the access method itself. For decades, organizations delegated security to end users, patching the password model with ever more friction: change it monthly, use a different one per account, make it complex enough that nobody can remember it — and never write it down. According to Wetzel, none of that made access meaningfully safer; it mostly frustrated users, while attackers refined their methods and increased their frequency.
Zero Trust infrastructure addresses the underlying design flaw directly. choin! deploys SonicWall’s Cloud Secure Edge (CSE), built on a strict need-to-know principle: anyone who wants to do something has to verify who they are, then verify again for anything else. CSE checks several factors before granting access — credentials, a second factor such as an authenticator app, device trust status, and geolocation — and approval is scoped to a single application or network segment, not the whole network.
If the logic is this straightforward, why isn’t every customer on board immediately? Because Zero Trust means real organizational change, Wetzel says: a different delivery model (CSE is cloud-delivered), a new licensing structure without concurrent licenses, and the internal work of defining who is allowed to access what. Technical hurdles, such as integrating legacy phone systems, add to the list — an area where choin! also supports other partners in SonicWall’s network.
Then there is the budget conversation, which choin!’s sales team has with nearly every customer. Zero Trust platforms like CSE license per user, since each user must authenticate through the platform for network and application access — unlike legacy setups, where licenses could be pooled. “Zero Trust isn’t about making the old model more secure. It’s a fundamentally different way of solving the problem,” Wetzel says, adding that even experienced IT leaders often struggle with that distinction, given how fast operational complexity is rising under already stretched teams. “We simply can’t keep working the way we used to.”
That is where consulting comes in, Wetzel argues: explaining not just how the new model works technically, but its long-term value. Hardware and software acquisition costs disappear, along with much of the ongoing operational burden, since customers effectively outsource part of their cybersecurity stack to the vendor and its partners. “SonicWall is simply more experienced running Zero Trust infrastructure than most mid-market IT departments,” Wetzel says. On a total-cost basis, he adds, the new model typically comes out cheaper overall — a conclusion customers usually need to work through together with their partner rather than accept on faith. SonicWall backs that process with know-how, tooling, and partner incentives designed to ease the transition.
“We want to make this as simple as possible for our partners, supporting them from presales through implementation and operations,” Dahmen confirms. He points to flexible, monthly, per-user licensing starting at a single seat as the model mid-market customers are actually asking for. “CSE also lets our partners address the AI-control requirements many customers haven’t even recognized yet.”
For mid-sized organizations, adopting Zero Trust is also a forcing function to formalize processes, Wetzel notes — it only works once responsibilities and access needs are mapped for every role and device. “We regularly define concrete use cases with our customers and then implement them,” he says, describing a shift for choin! from cybersecurity vendor toward business-process advisor: “For us, that’s a genuinely exciting development.”
The urgency is backed by SonicWall’s own threat data. Its 2026 Cyber Protect Report found that education networks — a useful proxy for any organization mixing legacy and modern systems on one flat network — recorded the highest per-device attack intensity of any tracked industry, with a single VoIP exploitation signature behind more than half of all intrusion-prevention events in the sector. SonicWall has also moved to close adjacent gaps in its portfolio, launching SonicWall Endpoint Security this year with enterprise-grade detection and response, including one-click ransomware rollback, for SMB-focused managed service providers. Whether the entry point is a network, an endpoint, or a stolen password, the argument is the one Wetzel makes about Zero Trust: continuous verification, not a fortified perimeter, limits the damage when an attacker gets in.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de