Resource
Zero trust for small business
Zero trust is a principle rather than a product, and it is sold as both. The principle is straightforward: stop treating the office network as a trusted place, and verify every request on its own merits regardless of where it comes from. Most of the practical benefit comes from three changes.
The old model and why it failed
Traditional security assumed a perimeter: inside was trusted, outside was not. Remote work, cloud services and stolen credentials each undermined that assumption independently.
| Question | Perimeter model |
|---|---|
| Where is the user?Location is not evidence of anything | Inside the office equals trusted |
| Is the device healthy?Checked before access is granted | Rarely checked |
| How much access?Only what the task requires | Broad once inside |
| How long does access last?Re-evaluated continuously | Until it is revoked |
| What if a credential is stolen?Additional signals still have to be satisfied | Attacker inherits full access |
The three changes worth making
A small business will not implement a full zero trust architecture, and does not need to. These three deliver the majority of the benefit.
- Multi factor authentication everywhere, including remote access and administrative accounts
- Device compliance checks, so an unmanaged or unencrypted machine cannot reach company data
- Removal of standing administrative rights, granting elevation when needed rather than permanently
- Conditional access rules based on risk signals such as unusual location or an impossible travel pattern
- Network segmentation, so reaching one system does not mean reaching all of them
What to be sceptical about
Any product marketed as zero trust in a box is describing one component of an approach. There is no single purchase that delivers it.
The useful framing for a business of this size is not whether you have achieved zero trust. It is whether being on the office network still grants access that being elsewhere does not, and whether a stolen password alone is enough to reach anything that matters.
If the answer to the second question is yes, the next step is multi factor authentication rather than an architecture programme.
Common questions
Answered before you ask.
Is zero trust realistic for a 40 person business?
The principles are, the full architecture is not, and that is fine. Multi factor authentication, device compliance and removing standing admin rights are all achievable with licences most businesses already hold. Those three close most of the practical risk without a project.
Does this mean replacing our VPN?
Not necessarily. A VPN that requires multi factor authentication and checks device compliance before granting access is behaving in a way consistent with the principles. What is inconsistent is a VPN that, once connected, places the user on a flat network with access to everything.
Where should we start?
Multi factor authentication on every account, with no exemptions for administrators or executives. It is the single highest value control available and exemptions granted for convenience invert the logic by leaving the most powerful accounts least protected.
Related
Read next.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
MFA and password management rollout
How to deploy it without a revolt.
Managed detection and response
24 by 7 human review of security alerts, with authority to contain.
Network and infrastructure
Firewalls, switching, Wi-Fi, servers and remote access, monitored.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.