Zero trust without buying a product

You can start zero trust with what you already own. It is a set of design principles, not a product category, and the first phases are configuration work in your identity provider, your device management and your network. Buy something only when a specific gap is left over.

Why zero trust is not a product

No. Zero trust is a set of design principles for deciding access, and no single product delivers it. Products can enforce parts of it, but only once you have decided who should reach what.

NIST SP 800-207, the publication most often cited, describes zero trust as moving defences from network perimeters to users, assets and resources. It sets out principles and a logical model. It does not name a product, and nothing in it can be installed.

A platform sold as zero trust can enforce a policy. Deciding that policy is still your job.

What to do first, in order

1. Identity and MFA everywhere

Start with identity. Put MFA on every account that can sign in from the internet, use phishing-resistant methods for administrators, and remove sign-in paths that bypass the identity provider. Legacy protocols that accept a password alone are the usual gap, along with service accounts nobody has looked at in years.

2. Device health as a condition of access

If you already manage laptops, you can require a managed, encrypted, up-to-date device before sign-in succeeds. Many identity providers can enforce this as a conditional access rule.

3. Least privilege

Remove standing admin rights. Grant elevated access for a task and let it expire. Review the vendor with admin access to your payroll system: does it need that access every day, or twice a year?

4. Segment the crown jewels

List the five systems whose loss would hurt most. Make sure a compromised workstation cannot reach them directly. This is firewall and routing work, and the equipment is often already in place.

5. Log and verify continuously

Keep sign-in and access logs long enough to investigate, somewhere a compromised admin cannot delete them. Then review them on a schedule, because logs nobody reads verify nothing.

When buying something does make sense

After those five steps, gaps become specific. You may find remote access cannot be narrowed to named applications with what you have, or that contractors on their own devices cannot be checked for health. A purchase that closes a named gap is easy to justify and easy to measure.

A purchase made first tends to go the other way. It gets deployed in a permissive mode to avoid breaking things, and it stays there.

Where the VPN fits

Not first. A VPN is a problem when it drops a user onto a flat network with broad reach, and narrowing what a connected user can reach removes most of that risk before any replacement is chosen. Requiring a healthy device to connect closes much of the rest.

How to measure progress

Pick a few measures you can count: the share of sign-ins with MFA, the number of standing admin accounts, and how many systems a single compromised laptop could reach. If those numbers move each quarter, the programme is working.

For the full design across cloud and on-premises environments, see our zero trust architecture service. Identity is covered in more depth on identity and workplace security, and cloud configuration on the cloud security review.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Is zero trust a product?

No. Zero trust is a set of design principles for deciding access, and no single product delivers it. Products can enforce parts of it, but only once you have decided who should reach what.

Where should a smaller organization start with zero trust?

Start with identity. Put MFA on every account that can sign in from the internet, use phishing-resistant methods for administrators, and remove sign-in paths that bypass the identity provider.

Do we need to replace our VPN?

Not first. A VPN is a problem when it drops a user onto a flat network with broad reach, and narrowing what a connected user can reach removes most of that risk before any replacement is chosen.

How do we know zero trust is working?

Pick a few measures you can count: the share of sign-ins with MFA, the number of standing admin accounts, and how many systems a single compromised laptop could reach. If those numbers move each quarter, the programme is working.

Planning your first phase

Tell us which identity provider you use and how staff reach internal systems today. The reply says what a first phase could look like. More of our writing is at writing.

Discuss a scope