Getting Started with Zero Trust

As your organisation grows, so does the complexity of its’ estate. In today’s world you have more services, more applications, remote workers and more IoT devices connecting into the network than ever before, and to top it off it’s getting harder to meet stringent compliance requirements. So how do you stay on top of these modern security challenges securely?

 

What is Zero Trust?

Zero Trust is an approach to security in which the assets, accounts and services on your network are treated as already potentially compromised and always requiring verification. Using this concept at the core of your security strategy, you implement methods to validate assets and users, ensuring that only the right people have access to the right data at the right time.

Let’s take a look at what a Zero Trust approach offers us.

 

Why use Zero Trust:

 

 

Case Study

MITRE: Segmentation stopped lateral movement

In 2024 an unknown adversary exploited one of MITRE’s VPNs through two Ivanti Connect Secure zero-day vulnerabilities and avoiding their multi-factor authentication using session hijacking. In this case, MITRE’s identity technology wasn’t enough to prevent the attack.  

Instead, segmentation policies that were already in place enabled quick containment of the breach, stopping the attackers’ lateral movement. The infected areas were isolated and potential damage was limited. This zero trust policy was a key factor to preventing further access to the attackers.

Not only do Zero Trust practices help protect your organisation, its data, and reputation, it also reduces any cyber insurance claims, preventing up to $465 billion annually in global economic loss from cyber attacks.

 

Choosing the Right Methodology for Zero Trust

There are a few different methodologies to follow when it comes to Zero Trust. Let’s look at three well-known examples from Microsoft, NIST, and NCSC.

Microsoft

    • A Zero Trust model that integrates across its ecosystem of services.

    • Strong emphasis on Microsoft tools Entra ID, Defender, Intune, and Azure services.

NIST

    • A vendor-neutral, standards-based framework for Zero Trust, widely adopted in government and industry.

    • NIST have released a number of publications to help guide implementation.

NCSC

    • Focuses on policy-based guidance for designing Zero Trust architectures in both UK public and private sectors.

    • Offers “Eight Design Principles” as a framework to support Zero Trust adoption.

What do these three methodologies have in common?

    • They put Identity and Access Management (IAM) solutions at the heart of your estate to provide authentication and authorisation.

    • They evaluate access requests based on identity, risk and telemetry.

    • They all adhere to Zero Trust core principles: always verify, assume breach and continually monitor activity over the network, taking a risk-based approach to access.

 

No single model fits all. Each organisation has unique assets, risks, and operational environments, and different frameworks may align better with different industry regulations. The best approach is to draw from different methodologies to best suit your business needs.

 

Where to start?

Stakeholder engagement is crucial in implementing Zero Trust.

Strategic Alignment: Ensure Zero Trust initiatives support broader business objectives and are not seen solely as a technical project.

Cross-Functional Collaboration: Zero Trust requires different teams (IT, security, business units) to work together, breaking down silos to achieve a cohesive security posture.

Effective Implementation: Gaining buy-in from all stakeholders is necessary for the successful adoption and long-term sustainability of Zero Trust principles across the organization.

Risk Mitigation: Reduce the risk of data breaches and insider threats by implementing granular access controls and continuously verifying every access request. 

Zero Trust Diagram

Building a robust Zero Trust architecture for your business isn’t a one-time fix, it’s a continual process that requires regular review and should factor into security decision making.

 

Looking to establish a Zero Trust architecture for your business but need support? Reach out to one of our cyber team and we’ll help get you started.

Clare Johnson, Capability Lead: clare@itsusconsulting.com

Noah Callaghan, Cyber Security Consultant: noah@itsusconsulting.com

Noah is a Cyber Security Consultant experienced in a number of network and cyber security technologies and highly focused on providing expert cyber services to our customers.

More Articles

A laptop on a desk in an office

Securing AI in High-Assurance Environments

As AI becomes increasingly relevant across these domains, we have been exploring how it can be applied safely within controlled environments. This has included internal research, experimentation and the development of practical approaches to using AI in a way that aligns with the same security and assurance principles that underpin our wider work.

Read More »