Traditional network security assumed that anything inside the office network could be trusted. Remote work, cloud applications and personal devices have made that perimeter fuzzy. Zero trust replaces location-based trust with continuous verification.
The core principles
- Verify explicitly: authenticate and authorise every request using identity, device and context.
- Least privilege: give each user and service only the access they need, for as long as they need it.
- Assume breach: design so that one compromised account or device cannot reach everything.
What it looks like in practice
Strong identity
Single sign-on with multi-factor authentication for every application, including internal tools.
Device health
Access decisions consider whether a device is managed, encrypted and up to date.
Segmentation
Applications and data are separated so access to one does not imply access to all.
Where to start
- Inventory your applications and who can access each one
- Enforce MFA, starting with administrators and remote access
- Remove shared accounts and standing admin rights
- Centralise logs so unusual access can be detected
Zero trust is a direction, not a product. Every step that reduces implicit trust makes an attack harder.
- Zero Trust
- Identity
- Access Control


