Skip to main content

Zero Trust

Illustration of Zero Trust

In short

Zero Trust is a security model that treats no network as trustworthy. Every request is checked on its own terms — who is asking, from which device, for which data — regardless of whether it comes from the office or from a train. The US standards document NIST SP 800-207 describes it as an architecture.

Why the internal network lost its role

Because the boundary the old model relied on no longer exists. Data sits in the cloud, people work from home, partners connect from outside. A wall around the office protects a castle nobody lives in.

The old model also had an uncomfortable side effect: once you were inside, you were inside everywhere. That is the property attackers monetise.

What it means in practice

Three questions at every request. Is the person who they claim to be (multi-factor)? Is the device known and in decent shape (device management)? Does this person need this data at all (permissions)?

None of the three requires a new product. Multi-factor, device management and conditional access all ship inside Microsoft 365 Business Premium.

What it is not

Not a product you buy. Anyone selling you Zero Trust as a licence is selling one component and naming it after the building.

And not a state you reach. It is a sequence of decisions, each one useful on its own even while the next is still outstanding.

How we handle it

We work the three questions in the order that pays off fastest: sign-in first, then devices, then permissions. Permissions last, because they need the most agreement.

Implementation: IT security.

Where this sits with us

Last reviewed: 2026-08-31

A term in your quote that nobody explained?

In a strategy call we translate the offer in front of you — even when it did not come from us.

Back to the glossary