Why the old model stopped working
Traditional security protected a network perimeter and trusted whatever was inside it. With remote work, SaaS applications and cloud services, there is no clear inside anymore, and an attacker who steals one password can move freely across a flat network.
Core principles
Zero Trust rests on three ideas. Verify explicitly, using identity, device health and context for every request. Grant least privilege, giving each person only the access they need for as long as they need it. Assume breach, designing systems so that one compromised account or device cannot reach everything. The reference description is NIST SP 800-207.
What it looks like in practice
Zero Trust is a direction, not a product. For most small and mid sized companies it starts with strong identity: SSO and MFA for every application, managed devices through MDM, conditional access rules, regular access reviews and network segmentation for critical systems.
Where it shows up in compliance
Zero Trust is not a certification, but its principles map directly to the access control, identity and network security controls of ISO 27001, the ENS and NIS2.




