Controls

What is Zero Trust security?

Zero Trust is a security model based on the principle that no user, device or network location is inherently trusted. Every access request is authenticated, authorised and evaluated against current context — identity, device health, location and behaviour — regardless of whether it originates inside or outside the corporate network, and access is granted at the minimum level required.

Written and reviewed by , Group Technical DirectorLast reviewed 30 July 2026

At a glance

Core principle
Never trust, always verify
Replaces
Perimeter-based 'trusted internal network' model
Reference framework
NIST SP 800-207
Key building blocks
Strong identity, device compliance, least privilege, segmentation
Common misconception
That it is a product that can be purchased

The core principles

Zero Trust is an architectural approach rather than a technology. Most descriptions reduce to three operating principles.

  • Verify explicitly — authenticate and authorise every request using all available signals: identity, device compliance, location, service and data classification.
  • Use least privilege — grant the minimum access required, for the minimum period, with just-in-time elevation for administrative work.
  • Assume breach — design on the basis that an attacker is already inside: segment networks, limit lateral movement, encrypt data in transit, and log comprehensively.

Why the perimeter model failed

Traditional security treated the corporate network as trusted and everything outside it as hostile, enforcing controls at the boundary. That assumption collapsed as data moved into SaaS platforms, staff worked from home and personal devices, and attackers demonstrated that once inside the perimeter they could move laterally with little resistance.

In a Zero Trust model there is no privileged position on the network. A device sitting in the office receives no more inherent trust than one on a home broadband connection.

What an SME can realistically implement

Zero Trust is often presented as an enterprise programme, but the highest-value elements are accessible to small organisations already using Microsoft 365 or Google Workspace.

  • Strong identity — MFA everywhere, ideally phishing-resistant for administrators, with legacy authentication blocked.
  • Conditional access — policies evaluating device compliance, location and risk before granting a session.
  • Device compliance — enrolled, encrypted, patched devices required for access to business data.
  • Least privilege — separate administrative accounts, removal of standing global admin rights, regular access reviews.
  • Application-level access — publishing internal applications through identity-aware access rather than full network VPN.

Sources

The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.

  1. Zero trust architecture design principlesNational Cyber Security Centre
  2. NIST SP 800-207: Zero Trust ArchitectureNational Institute of Standards and Technology

FAQ

What is Zero Trust security — common questions

Direct answers to the questions asked most often about this topic.

Can Zero Trust be bought as a product?

+

No. Zero Trust is an architectural model, and no single product delivers it, despite extensive vendor marketing to the contrary. Products contribute components — identity providers supply authentication and conditional access, device management supplies compliance signals, network tools supply segmentation, and access proxies replace broad VPN connectivity. What makes an environment Zero Trust is how those components are configured together and the assumptions they enforce. An organisation can hold every relevant licence and still operate a flat, trusted internal network, which is a common finding in practice.

Is Zero Trust realistic for a business with twenty staff?

+

The principles are, even if the full enterprise architecture is not. A twenty-person business using Microsoft 365 Business Premium already has the necessary tooling: Entra ID Conditional Access, Intune device compliance and MFA enforcement. Implementing enforced MFA, requiring compliant enrolled devices for access to business data, removing standing administrative rights, and blocking legacy authentication delivers most of the practical benefit. What is usually out of reach is comprehensive micro-segmentation of internal networks, which requires infrastructure and ongoing effort rarely justified at that scale.

Does Zero Trust mean getting rid of the VPN?

+

Not necessarily, but it changes the VPN's role. A traditional VPN grants broad network-level access once connected, which is exactly the implicit trust Zero Trust removes: a compromised device on the VPN can reach everything the network permits. The Zero Trust alternative publishes individual applications through an identity-aware proxy, so a user is authorised for a specific application rather than a network segment. Many organisations retain a VPN for legacy systems that cannot be published individually, while moving modern applications behind identity-based access.

How does Zero Trust relate to Cyber Essentials?

+

They operate at different levels and are complementary. Cyber Essentials is a certifiable baseline of five specific technical controls with a pass or fail outcome. Zero Trust is an architectural philosophy with no certification and no defined endpoint. They overlap substantially in practice — multi-factor authentication, user access control and secure configuration all appear in both — so an organisation implementing Zero Trust principles will find much of Cyber Essentials already satisfied. The reverse is not true: passing Cyber Essentials does not imply a Zero Trust architecture.

Where should an organisation start with Zero Trust?

+

Identity first, in nearly every case. Enforce multi-factor authentication for all users, block legacy authentication protocols that bypass it, separate administrative accounts from daily-use accounts, and remove standing privileged access. Once identity is sound, add device compliance requirements so that only enrolled, encrypted and patched devices can reach business data. Network segmentation and application-level access publishing come later, as they require more design effort for less immediate risk reduction. Attempting segmentation before fixing identity is a common sequencing error.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way