GlossarySecurity awareness

Zero Trust

Short answer

Zero Trust is a security model based on never trusting by default: every user, device and application must prove who it is and be authorised each time it requests access, wherever it connects from, instead of being trusted for being inside the corporate network.

Why the old model stopped working

Traditional security protected a network perimeter and trusted whatever was inside it. With remote work, SaaS applications and cloud services, there is no clear inside anymore, and an attacker who steals one password can move freely across a flat network.

Core principles

Zero Trust rests on three ideas. Verify explicitly, using identity, device health and context for every request. Grant least privilege, giving each person only the access they need for as long as they need it. Assume breach, designing systems so that one compromised account or device cannot reach everything. The reference description is NIST SP 800-207.

What it looks like in practice

Zero Trust is a direction, not a product. For most small and mid sized companies it starts with strong identity: SSO and MFA for every application, managed devices through MDM, conditional access rules, regular access reviews and network segmentation for critical systems.

Where it shows up in compliance

Zero Trust is not a certification, but its principles map directly to the access control, identity and network security controls of ISO 27001, the ENS and NIS2.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub