Go back

What's Already in the Room: Google's New "Beyond Zero" Framework

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

Industry Insights
August 11, 2026
3m read
3m read
3m listen
3m watch
3m watch
What's Already in the Room: Google's New "Beyond Zero" FrameworkWhat's Already in the Room: Google's New "Beyond Zero" Framework
speakers
speakers
speakers
authors
Belem Regalado
Material Research Team
participants
No items found.
share

Google's Beyond Zero framework strengthens AI-era security, but Material Security's analysis reveals a critical gap: the sensitive data already accumulated in enterprise environments before any breach occurs.

Last month, Google published Going Beyond Zero, an evolution of the zero trust framework for the AI era. Instead of just verifying who is connecting, it authorizes every individual action taken by every user and every agent, at machine speed, with context enriched at the point of decision. It is the right architecture for a world where AI agents operate on behalf of users and attackers move faster than any human response can match.

We think Google is right. And we want to add something to the picture.

The part 'assume breach' tends to skip

In February, we wrote that the 'assume breach' mindset tends to stop at the point of authentication. Security teams apply rigorous skepticism to every login and session token. Then, once a user authenticates into Google Workspace, the posture quietly shifts from 'assume breach' to 'assume safety.' Files accumulate. Emails persist. OAuth tokens are granted. None of that gets the same scrutiny as the login itself.

Beyond Zero extends authorization deeper, to the action level, closing a real gap. But there is another dimension it cannot address on its own: the question of what is already there.

What we found before any breach occurred

We did a systematic analysis of a Google Workspace environment using Material Security's data export, covering Drive, email, and OAuth connections. Every number below comes from that environment, in its normal operating state, before any attacker arrived.

In Drive: more than 83,000 files containing sensitive data across five categories, passwords embedded in documents, financial reports, payroll data, Social Security numbers, and source code. These files were not created by attackers. They were created by employees doing their jobs. The content accumulated because work accumulates. Every month in the data window, users shared more files publicly than they restricted.

The most striking single finding: an OpenAI-connected integration had downloaded a compensation spreadsheet 632,730 times across 15 employee accounts. The download counts follow exact multiples, the signature of a synchronized polling loop. The integration was doing exactly what it was designed to do. Nobody told it not to.

More concerning were apps that could not be identified at all. One has been running since September 2025 and has read sensitive files 87 million times, accessing compensation data, bank account entries, and multi-year financial planning models. Every day.

The email environment told the same story. Finance team inboxes contained 45,550 emails with bank routing numbers, 18,824 invoices, and 4,702 SWIFT codes, not because of any breach, but because that is what finance teams receive. Alongside that: 1,875 emails flagged with Business Email Compromise indicators. Attackers have already found these accounts. The inboxes they are probing contain exactly what they need.

Two questions, not one

Beyond Zero answers: how do we control what agents and users can do going forward, fast enough to match machine-speed threats?

The second question is: what does an attacker actually inherit the day they get in?

These are not the same question. Authorization controls govern what can happen at the gate. Blast radius awareness tells you what is behind it. The industry has always been better at building gates than taking inventory. Beyond Zero advances the gate significantly. What our investigation shows is what the inventory looks like when nobody has taken it.

The data we found was not created by a breach. It was created by three years of normal enterprise operations. It was there before any attacker arrived, and it would still be there after any authorization framework was implemented. Beyond Zero will make future access decisions better. Knowing what is already in the environment is what makes those decisions meaningful. You cannot protect what you have not measured.

Frequently Asked Questions

Find answers to common questions and get the details you need.

No items found.

Related posts

Our blog is your destination for expert insights, practical tips, and the latest news in technology. Stay informed with our regular updates and in-depth articles. Join the conversation and enhance your understanding of the tech landscape.

blog post

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

Marie Ketner
5
m read
Read post
Podcast

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m listen
Listen to episode
Video

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m watch
Watch video
Downloads

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m listen
Watch video
Webinar

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m listen
Listen episode
blog post

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

Rajan Kapoor
3
m read
Read post
Podcast

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m listen
Listen to episode
Video

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m watch
Watch video
Downloads

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m listen
Watch video
Webinar

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m listen
Listen episode
blog post

Why We Built an MCP Server

Learn how Material built a secure, open Model Context Protocol (MCP) server to connect AI agents directly with enterprise email security detection and remediation capabilities.

Cindy Wang
10
m read
Read post
Podcast

Why We Built an MCP Server

Learn how Material built a secure, open Model Context Protocol (MCP) server to connect AI agents directly with enterprise email security detection and remediation capabilities.

10
m listen
Listen to episode
Video

Why We Built an MCP Server

Learn how Material built a secure, open Model Context Protocol (MCP) server to connect AI agents directly with enterprise email security detection and remediation capabilities.

10
m watch
Watch video
Downloads

Why We Built an MCP Server

Learn how Material built a secure, open Model Context Protocol (MCP) server to connect AI agents directly with enterprise email security detection and remediation capabilities.

10
m listen
Watch video
Webinar

Why We Built an MCP Server

Learn how Material built a secure, open Model Context Protocol (MCP) server to connect AI agents directly with enterprise email security detection and remediation capabilities.

10
m listen
Listen episode
blog post

Documentation as a Service

Material's documentation is a core product feature, providing interactive, machine-readable guides that empower users to evaluate, deploy, and operate our security tools with complete transparency and independence.

Cheyenna Eversoll Duggan
5
m read
Read post
Podcast

Documentation as a Service

Material's documentation is a core product feature, providing interactive, machine-readable guides that empower users to evaluate, deploy, and operate our security tools with complete transparency and independence.

5
m listen
Listen to episode
Video

Documentation as a Service

Material's documentation is a core product feature, providing interactive, machine-readable guides that empower users to evaluate, deploy, and operate our security tools with complete transparency and independence.

5
m watch
Watch video
Downloads

Documentation as a Service

Material's documentation is a core product feature, providing interactive, machine-readable guides that empower users to evaluate, deploy, and operate our security tools with complete transparency and independence.

5
m listen
Watch video
Webinar

Documentation as a Service

Material's documentation is a core product feature, providing interactive, machine-readable guides that empower users to evaluate, deploy, and operate our security tools with complete transparency and independence.

5
m listen
Listen episode
Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New