Most organisations that say they are "doing Zero Trust" have bought a product. Most organisations that have genuinely improved their position did a sequence of unglamorous things to systems they already owned.
The idea, stated plainly
The traditional model trusted location: inside the network was trusted, outside was not. That assumption fails the moment an attacker gets inside — which is the scenario you are defending against. Zero Trust replaces location-based trust with per-request verification of identity, device and context, granting the minimum access needed.
A sequence that works on a real estate
1. Know what you have
You cannot apply least privilege to systems you have not catalogued. Inventory applications, data stores and the identities that can reach them. This stage is tedious and consistently reveals things nobody knew were running.
2. Consolidate identity
Zero Trust is identity-first, which is impossible across six disconnected directories. Getting applications behind a single identity provider is usually the highest-value work in the entire programme, and it pays for itself in operational terms regardless.
3. Strong authentication everywhere
Multi-factor on every account, administrators first. Phishing-resistant factors where you can; app-based where you cannot. This is where the measurable risk reduction appears.
4. Conditional access
Now that identity is central, make access depend on context: device compliance, location, the sensitivity of what is being requested. Start with reporting-only so you can see what you would have blocked before you block it.
5. Cut standing privilege
Most privileged accounts hold permissions permanently that are needed occasionally. Move to just-in-time elevation with approval and expiry. Review what is left — in every assessment we run, a meaningful share of standing admin rights turn out to belong to nobody in particular.
6. Segment the network
Full micro-segmentation is a large programme. Partial segmentation around your most sensitive systems delivers most of the benefit for a fraction of the effort. Start where the crown jewels live.
What to avoid
- Buying first. Tooling helps once you know what you are enforcing. Bought first, it becomes expensive shelfware.
- Big-bang migration. Every successful programme we have supported was incremental, with each stage delivering standalone value.
- Ignoring the legacy system. There is always one that cannot do modern authentication. Wrap it, proxy it, segment it — but do not let it block the other ninety percent.
- Treating it as finished. It is a posture, not a project with an end date.
Measuring progress
Useful metrics: percentage of applications behind single sign-on, percentage of accounts with phishing-resistant MFA, number of standing privileged accounts, and mean time to revoke access when someone leaves. All four are countable, and all four move in the right direction as the work lands.
