Skip to content
Cybersecurity

Zero Trust Explained Simply: A Guide for SMEs

Zero Trust explained simply: the core principle, how it differs from the perimeter model, five pillars with concrete measures and six steps to get started.

Published on 4 min read

Row of glass access gates in an empty lobby with a view over the city.

Zero Trust means that no device and no user is granted access simply because they are on the company network. Every request is checked, regardless of where it comes from. The model is not a product but a way of thinking that can be implemented step by step with existing resources.

The core principle

The classic security model works with a perimeter: the firewall separates inside from outside, and whoever is inside is considered trustworthy. Today email and files sit in Microsoft 365, employees work from home, service providers connect via remote maintenance, and a single phishing victim brings the attacker inside.

Zero Trust reverses the assumption. The principle is “never trust, always verify”: every request is assessed on identity, device state, location, time and the requested resource, at every access and not only at the morning sign-in. Access is limited to what is needed and withdrawn as soon as a condition changes.

The reference is NIST Special Publication 800-207 from 2020. For a mid-sized company, the architectural detail matters less than its consequence: security depends on identities, devices and data, not on network cables.

FeaturePerimeter modelZero Trust
Basis of trustNetwork locationIdentity, device state, context
VerificationOnce at the boundaryAt every request
Scope of accessLargely the whole internal networkOnly the requested resource
Consequence of a breachFree movement across the networkMovement stops at the next check
Remote accessVPN opens the whole networkAccess per application with conditions

The five pillars and their measures

Zero Trust is divided into five pillars: identity, devices, network, applications and data. For each there are measures a mid-sized company can implement with existing licences.

  • Identity: According to the Verizon Data Breach Investigations Report 2025, stolen credentials are the most common entry route. Hence multi-factor authentication for all accounts without exception, conditional access in Microsoft 365 (compliant devices only, expected countries, extra checks on unusual behaviour), separate accounts for administration and daily work, passkeys (FIDO2) for highly privileged accounts.
  • Devices: Management of all end devices through a central solution such as Microsoft Intune. Compliance rules: current operating system, full-disk encryption, active endpoint protection, no local administrator rights. Unmanaged private devices get no access, or only restricted access through the browser.
  • Network: The network separates internal zones instead of forming an outer boundary. Segmentation by function (workstations, servers, printers, building services, guests, service providers), firewall rules between segments, remote access per application with identity verification instead of a network VPN, logging of traffic between zones. For this we use SRX Series firewalls from HPE Juniper Networking.
  • Applications: Sign-in through the central identity (single sign-on), no local user accounts in specialist applications, service accounts without domain administrator rights, regular review of which applications run with which rights.
  • Data: Classification by protection need with a few levels, in Microsoft 365 via sensitivity labels. Encryption and access restriction for the highest level. Backups that even an administrator cannot delete.

Conditional access, device compliance and classification are already included in many Microsoft 365 licences. For segmentation, a firewall that applies rules between internal zones is usually enough. New products are rarely needed; the inventory shows what is missing.

Getting started in six steps

  1. Inventory: Which identities, devices, applications and data stores exist, who accesses what from where.
  2. Multi-factor authentication everywhere: The best ratio of effort to effect. First all external access, then all accounts.
  3. Conditional access and device compliance: Sign-ins only from managed, compliant devices.
  4. Reduce privileges: Limit domain administrators to the necessary number, review service accounts, remove shares granted to “everyone”.
  5. Segment the network: First separate servers, backup and building services from the workstations, then refine the rules.
  6. Classify and monitor data: Introduce protection levels, evaluate logs centrally, adjust rules.

Each step brings measurable progress on its own. A company at step 3 is considerably better protected than under the perimeter model, even if steps 4 to 6 are still outstanding. There is no end date: new applications, devices and employees require new rules. Patch management, backups and training remain necessary; Zero Trust limits the damage when one of these foundations fails.

Key points

  • Zero Trust checks every request on identity, device and context, not on network location.
  • The measures span identity, devices, network, applications and data and can mostly be implemented with existing Microsoft 365 licences and a zone-capable firewall.
  • Order for getting started: inventory, MFA, conditional access, reduce privileges, segment, classify.

Which measures come first in your own organisation is shown by DEVACON’s IT security check; its scope is described on the page Cybersecurity.

Topics Zero Trust Network security MFA Segmentation NIST

This article comes from the DEVACON blog and was editorially revised for the new website.