Insights for better technology decisions.

Practical guidance on cybersecurity, cloud strategy, infrastructure modernization, automation, and IT operations. New articles are in development.

← All Insights
SECURITY

Zero Trust Isn’t a Product. It’s a Strategy

Zero trust is a way to make access decisions continuously. It is not a product, a license, or a project that ends after deployment.

Organizations often begin zero-trust initiatives by shopping for technology. That is backwards. The correct starting point is understanding who needs access, which resources matter most, how access is granted today, and where trust is assumed without evidence.

Start with the access decision

Every request should answer four questions: who is requesting access, what device is being used, which resource is being requested, and whether current risk signals justify the request. A strong strategy uses identity, device health, location, behavior, and resource sensitivity together.

Core principle: grant the minimum access required, validate continuously, and assume that any identity or device can become compromised.

Build the foundation in the right order

1. Inventory critical resources

Identify sensitive applications, privileged systems, regulated data, administrative interfaces, and operational dependencies. Zero trust cannot protect resources that the organization has not identified.

2. Strengthen identity

Require phishing-resistant multifactor authentication where practical, remove dormant accounts, separate administrative identities, and apply conditional access based on risk. Shared accounts and permanent privilege should be treated as control failures.

3. Establish device confidence

Access policy should consider device ownership, encryption, patch status, endpoint protection, and configuration compliance. A valid password from an unmanaged or compromised device is not sufficient evidence of trust.

4. Segment access

Reduce the ability of users, devices, and workloads to move freely across the environment. Segmentation limits the blast radius of a compromised identity and makes policy enforcement more precise.

5. Protect data directly

Classification, encryption, retention, sharing controls, and monitoring should follow the sensitivity of the data. Network location alone should never determine whether data is safe.

Avoid the common failure modes

  • Buying tools before defining policy and ownership
  • Requiring MFA while leaving excessive privilege unchanged
  • Applying strict controls to employees but ignoring service accounts
  • Creating so many exceptions that policy becomes optional
  • Measuring deployment activity instead of reduced exposure

Measure outcomes, not product coverage

Useful measures include the percentage of privileged accounts using strong authentication, dormant accounts removed, unmanaged-device access reduced, critical applications protected by conditional access, standing privilege eliminated, and high-risk access attempts blocked or investigated.

A practical first 90 days

Begin with one high-value environment. Inventory identities and resources, close obvious account-control gaps, enforce strong authentication, define device requirements, and monitor the results. Use what is learned to refine policy before expanding. Zero trust succeeds through disciplined iteration, not a single large rollout.

The goal is not to distrust employees. The goal is to stop relying on assumptions that attackers can exploit.

Need a practical security roadmap?

Discuss Your Priorities