IT glossary

Zero trust

Zero trust designs security around the idea that no user, device or connection is trusted just because it is inside your network, everything gets checked.

The older model assumed a boundary. Inside the office network you were trusted; outside it you were not. That assumption stopped describing reality once the applications moved to the cloud, the staff moved to kitchen tables, and the phone in someone’s pocket became a work device.

It is an approach, not a product

This is the thing to be clear about, because a great deal of software is now sold as “zero trust”. You cannot buy zero trust. You can buy tools that support it, identity systems, device compliance checks, network access controls, and any vendor telling you their product delivers it is describing a philosophy in a price list.

In practice, adopting it looks like a series of unglamorous decisions: every login verified with more than a password, devices checked for health before they are allowed at data, people given access to the specific things their job needs rather than the whole file share, and access removed promptly when a role changes.

Why it matters to you

Because most of the damage in a real incident comes after the first account is compromised, not from it. If one stolen login opens the entire environment, a small problem becomes an organization-wide one. If it opens one mailbox and one folder, you have an incident that is annoying rather than serious.

There is a second benefit that gets less attention: it makes offboarding honest. When access is granted deliberately, it can be removed deliberately.

Where it gets oversold

Zero trust done badly is just friction. If every action asks for approval, people find routes around it, and you have made the environment less safe while feeling more secure. The version that works is boringly targeted: strong verification on identity, tight control on administrator accounts, and least-privilege applied to the handful of systems that would genuinely hurt if they were opened.

A sensible first step

Start with identity, because that is where nearly everything now begins. Multi-factor authentication everywhere, conditional access rules that consider device and location, and a real review of who holds administrator rights. That is a meaningful move toward zero trust and it does not require a new platform.

The service this relates to

See also

All terms

Still not sure what you actually need?

That is a normal place to start, and a 30-minute call usually settles it faster than more reading.