
Zero Trust: not a product, an order of work
Zero Trust gets sold as if it were a box. It is not. It is a principle — trust no connection on the strength of where it came from — and you introduce that principle in steps. This is which steps, and in what order.
Zero Trust is one sentence: no connection can be trusted on the strength of where it came from. Not because it came from the office, not because it came through the VPN, not because the device was here last week.
It is not a product. Every vendor sells one, and each of those products covers a single layer. Buy a box and think you are done and you have bought one layer and not the rest.
The order matters more than the technology. Start with identity, because that is the layer nearly every incident runs aground on and the layer that costs least to improve.
What Zero Trust is, and what it is not
The old model was simple: inside the network was trusted, outside was not. There was a firewall in between, and whoever got through it could reach everything. That worked as long as everyone sat in the office and every system stood in the same server room.
Neither is true any more. The people are everywhere, the systems sit with three providers, and the firewall stands around a network the work no longer lives in. Zero Trust is the answer to that shift, and it consists of one rule: trust no connection on the strength of where it came from. Every request is judged on who is making it, from which device, and whether that adds up at that moment.
What it is not: a product. You cannot buy Zero Trust any more than you can buy security. Every vendor has a box for it — one on identity, another on network, a third on the workplace — and each of those boxes covers a part. Buy one and think you are finished and you have arranged one layer and not three.
And it is not all-or-nothing. Most organisations we walk into already have two or three pieces in place without calling it that. The question is not whether you start, but which layer first.
Start with identity, always
If there is one place to start, it is this one, and for two reasons that hold independently of each other.
The first is that it is the layer things go wrong on. In the incidents we see, the way in is almost never a technical hole in a firewall. It is an account: a password leaked elsewhere, an employee who clicked a convincing sign-in page, an admin account from 2019 nobody ever cleared out.
The second is that it is the cheapest layer. Turning on a second factor takes no investment, only persistence. Setting up conditional access — who may do what, from which device and in what circumstances — usually sits in the licence you already hold.
What has to be in place, concretely:
- A second factor on everything, and on the admin accounts first. Those are worth an attacker's trouble; the one colleague in finance is not.
- Conditional access. A sign-in from a managed device should be allowed more than a sign-in from an unknown laptop in a country where you have nobody.
- Leavers as a process. An account that stays alive is an open door, and that door can be reached from outside. This is not technology but an agreement with HR.
- Admin rights that expire. Someone is an administrator while they are administering something, not permanently because they had to once, three years ago.
How we set up that layer sits under cybersecurity.
Then the device, and only after that the network
The second layer is the device. A valid sign-in from a device you know nothing about is still a risk, because the credentials may have been taken off that device. What you want here is easy to state and harder to sustain: only devices you know and that are up to date reach the work.
That collides with practice, and that is part of it. There is always an external who has to look in tomorrow and a director with a personal phone. The answer to that is not to weaken the rule but to build a second route: fewer rights, no files locally, browser only.
The third layer is the network, and it comes last on purpose. Segmentation — dividing the network so an infected device cannot reach everything — is valuable and it is also the most work. In organisations with production lines or medical equipment it moves forward, because there are things on that network you cannot patch and therefore have to fence off. In an office organisation the same effort spent on identity returns more.
The order identity, device, network is not a law. It is what removes the most risk per euro in most estates, and we deviate from it where yours gives reason to. But then we say why.
What happens to the VPN
This is the question that comes up in every conversation, so here is the honest answer.
A VPN does not fit the Zero Trust principle, because it does exactly what you no longer want: it moves someone inside, and inside is trusted. Whoever is through the VPN is on the network and can reach everything on it.
Even so we rarely advise pulling it out straight away, and that is not softness. In nearly every estate something hangs off the VPN that is not reachable any other way: an old application, a machine, a supplier connected like that. Removing those is a project in itself, and until that project is done the VPN is doing something you need.
What you can do straight away is make it smaller. Who is allowed on it, with which second factor, and where does it come out — not on the whole network but on the handful of systems it is actually for. That is an afternoon of work and it removes most of the risk without breaking anything.
What it costs in friction
Amounts do not appear on this site. What does belong here is the other price, because it is rarely named and it is the reason introductions stall.
Zero Trust means people have to confirm things more often, that a device which is not up to date stops working, and that someone who used to be able to reach everything no longer can. That produces resistance, and the resistance is fair: in the short term the work becomes more awkward.
What helps against that is not explaining that the standard requires it. What helps is setting the rule so it does not touch people working normally. A second factor that asks once a week rather than at every sign-in, conditional access that asks nothing extra on a managed device — that is the difference between a measure that stays in place and one that gets switched off after three weeks because the board tripped over it.
And count on a list of exceptions. There always is one, and it belongs written down with a reason and a date rather than quietly existing.
Questions we get about this
The ones that come up most often when this is on the table.
Is Zero Trust a product we can buy?
No, and that is not word play. It is a principle: no connection can be trusted on the strength of where it came from. Every vendor sells a product alongside it, and each of those products covers one layer — identity, device, network or application. Buy one and you have arranged one layer. What you can buy is the technology that makes a layer possible, and that often already sits in the licences you hold.
Do we have to get rid of our VPN then?
Eventually yes, immediately rarely. A VPN does exactly what Zero Trust wants to avoid: it puts someone inside, and inside everything is allowed. But in nearly every estate something hangs off it that is not reachable any other way, and removing that is a project. What can happen straight away is making it smaller: fewer people on it, a second factor in front of it, and coming out on the systems that are needed rather than the whole network. That is an afternoon of work and removes most of the risk.
Where do we start with a small team?
With identity, and within identity with the admin accounts. A second factor on them, temporary rights instead of permanent ones, and a list of who is an administrator that somebody actually keeps current. That costs no investment and it covers the scenario that occurs most often in practice. Network segmentation is valuable but it is the most work, and with a small team that is rarely where you should begin.
Does NIS2 require Zero Trust?
Not in those words. The Cyberbeveiligingswet, in which NIS2 is worked out here, asks for access control, supply chain risk management and demonstrability — and Zero Trust is one way to meet that, not the only one. What an auditor wants to see is that you know who can reach what and that you can show it. Get the identity layer in order and that evidence falls out of the management work rather than someone assembling it afterwards.
Where this lands with us
The services this subject falls under.
Want to know which layer is loose?
The identity layer can be reviewed in half a day and usually produces a list you can work through yourself.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.