Skip to content

Resource

Zero trust for small business

Zero trust is a principle rather than a product, and it is sold as both. The principle is straightforward: stop treating the office network as a trusted place, and verify every request on its own merits regardless of where it comes from. Most of the practical benefit comes from three changes.

The old model and why it failed

Traditional security assumed a perimeter: inside was trusted, outside was not. Remote work, cloud services and stolen credentials each undermined that assumption independently.

Perimeter based security compared with zero trust principles
QuestionPerimeter model
Where is the user?Location is not evidence of anythingInside the office equals trusted
Is the device healthy?Checked before access is grantedRarely checked
How much access?Only what the task requiresBroad once inside
How long does access last?Re-evaluated continuouslyUntil it is revoked
What if a credential is stolen?Additional signals still have to be satisfiedAttacker inherits full access

The three changes worth making

A small business will not implement a full zero trust architecture, and does not need to. These three deliver the majority of the benefit.

  • Multi factor authentication everywhere, including remote access and administrative accounts
  • Device compliance checks, so an unmanaged or unencrypted machine cannot reach company data
  • Removal of standing administrative rights, granting elevation when needed rather than permanently
  • Conditional access rules based on risk signals such as unusual location or an impossible travel pattern
  • Network segmentation, so reaching one system does not mean reaching all of them

What to be sceptical about

Any product marketed as zero trust in a box is describing one component of an approach. There is no single purchase that delivers it.

The useful framing for a business of this size is not whether you have achieved zero trust. It is whether being on the office network still grants access that being elsewhere does not, and whether a stolen password alone is enough to reach anything that matters.

If the answer to the second question is yes, the next step is multi factor authentication rather than an architecture programme.

Common questions

Answered before you ask.

Is zero trust realistic for a 40 person business?

The principles are, the full architecture is not, and that is fine. Multi factor authentication, device compliance and removing standing admin rights are all achievable with licences most businesses already hold. Those three close most of the practical risk without a project.

Does this mean replacing our VPN?

Not necessarily. A VPN that requires multi factor authentication and checks device compliance before granting access is behaving in a way consistent with the principles. What is inconsistent is a VPN that, once connected, places the user on a flat network with access to everything.

Where should we start?

Multi factor authentication on every account, with no exemptions for administrators or executives. It is the single highest value control available and exemptions granted for convenience invert the logic by leaving the most powerful accounts least protected.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment