Insights for better technology decisions.
Practical guidance on cybersecurity, cloud strategy, infrastructure modernization, automation, and IT operations. New articles are in development.
Zero Trust Isn’t a Product. It’s a Strategy
Zero trust is a way to make access decisions continuously. It is not a product, a license, or a project that ends after deployment.
Organizations often begin zero-trust initiatives by shopping for technology. That is backwards. The correct starting point is understanding who needs access, which resources matter most, how access is granted today, and where trust is assumed without evidence.
Start with the access decision
Every request should answer four questions: who is requesting access, what device is being used, which resource is being requested, and whether current risk signals justify the request. A strong strategy uses identity, device health, location, behavior, and resource sensitivity together.
Build the foundation in the right order
1. Inventory critical resources
Identify sensitive applications, privileged systems, regulated data, administrative interfaces, and operational dependencies. Zero trust cannot protect resources that the organization has not identified.
2. Strengthen identity
Require phishing-resistant multifactor authentication where practical, remove dormant accounts, separate administrative identities, and apply conditional access based on risk. Shared accounts and permanent privilege should be treated as control failures.
3. Establish device confidence
Access policy should consider device ownership, encryption, patch status, endpoint protection, and configuration compliance. A valid password from an unmanaged or compromised device is not sufficient evidence of trust.
4. Segment access
Reduce the ability of users, devices, and workloads to move freely across the environment. Segmentation limits the blast radius of a compromised identity and makes policy enforcement more precise.
5. Protect data directly
Classification, encryption, retention, sharing controls, and monitoring should follow the sensitivity of the data. Network location alone should never determine whether data is safe.
Avoid the common failure modes
- Buying tools before defining policy and ownership
- Requiring MFA while leaving excessive privilege unchanged
- Applying strict controls to employees but ignoring service accounts
- Creating so many exceptions that policy becomes optional
- Measuring deployment activity instead of reduced exposure
Measure outcomes, not product coverage
Useful measures include the percentage of privileged accounts using strong authentication, dormant accounts removed, unmanaged-device access reduced, critical applications protected by conditional access, standing privilege eliminated, and high-risk access attempts blocked or investigated.
A practical first 90 days
Begin with one high-value environment. Inventory identities and resources, close obvious account-control gaps, enforce strong authentication, define device requirements, and monitor the results. Use what is learned to refine policy before expanding. Zero trust succeeds through disciplined iteration, not a single large rollout.
Need a practical security roadmap?
Discuss Your Priorities