Zero Trust

Zero Trust

Zero Trust is a security principle for computer networks: no device and no user is automatically treated as trustworthy just because they are already inside the corporate network. Every access must be individually verified and approved.

In the past, companies protected their computers like a castle. A thick wall on the outside, and inside everyone could move around freely. Once you were inside the internal network, you were considered trustworthy and could reach almost all the data. Zero Trust breaks with this idea. The name literally means “zero trust”: every request is checked, regardless of whether it comes from the laptop in the office or the phone on the train. The basic rule is “never trust, always verify.”

Why the castle wall is no longer enough

The old model assumes there is a clear inside and outside. That is exactly what no longer holds true today. Employees work from home, data sits with cloud providers, meaning on servers rented from other companies. Phones, tablets, and smart devices are connected to the network every which way. A single wall can no longer be built around this jumble.

On top of that, there is a second problem. Attackers almost always get in through stolen passwords or fake emails, not by breaking through the wall. Once the attacker is inside, in the old model they can move around almost freely. Experts call this lateral movement. It is precisely this spread that Zero Trust is meant to slow down, by asking for ID again behind every single door.

For companies, this has also become a matter of regulation. Authorities in the US require Zero Trust for their own systems, and cyber insurers ask about it too. Those without such controls pay higher premiums or cannot get insured at all.

Checking every single access

At its core, Zero Trust answers three questions for every request. Who are you? What device are you coming from? And are you allowed to access exactly this file? Only once all three answers check out does access open up. And the check applies only to this one access, not to the entire workday.

Identity is usually secured with a second confirmation. Besides the password, you need something like a code from an app or a fingerprint. The device itself is also assessed: Is the operating system up to date, is antivirus software running, is the hard drive encrypted? An outdated laptop then gets fewer privileges than a well-maintained one.

In addition, the network is broken up into small zones. The accounting database is then simply invisible to the marketing department. Everyone gets only the rights they actually need for their task. If an account suddenly behaves strangely, say with a login from another country at three in the morning, the system can immediately block access.

Zero Trust in products and headlines

If you log into a school account or an online service with a password plus a code from your phone, you’re experiencing one building block of this. In companies, such systems often replace the classic VPN, the encrypted tunnel into the corporate network. Instead of a tunnel into the entire network, you get access to a single application.

The term shows up regularly in business news because a lot of money is made from it. Vendors like Microsoft, Cloudflare, Zscaler, Palo Alto Networks, or Okta sell Zero Trust products. After major data breaches, affected corporations almost reflexively announce that they are now switching to Zero Trust.

A common misconception: Zero Trust is not a product you can buy and switch on. It is a concept made up of many individual measures that grow together, and it can take years. And it does not make attacks impossible, just more expensive and slower. Anyone who intercepts a boss’s access code still gets in to some extent, even here.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.