Our starting position
Zero trust has been heavily marketed, and much of that marketing implies you can buy it. You cannot. Zero trust is an architectural principle — never trust, always verify — implemented through identity, segmentation, least privilege and monitoring, largely using tools most organisations already own.
Our approach is therefore pragmatic. We are not going to sell you a "zero trust platform". We are going to sequence changes so risk drops as quickly as possible within your constraints.
The phased programme
Phase 1 — Identity foundations
- Multi-factor authentication everywhere it is supported, prioritising VPN, email, remote access and all administrative accounts.
- Remove standing administrative privilege. Separate admin accounts, no routine work performed with elevated rights.
- Account hygiene — disable dormant accounts, review service accounts, enforce sensible password policy.
Why first: credential compromise is the most common intrusion route we see. MFA alone blocks the large majority of it, and it is achievable in weeks.
Phase 2 — Network segmentation
- Separate users, servers, management interfaces, guest Wi-Fi, IoT and backups into distinct zones.
- Firewall policy between zones, written by service rather than by subnet.
- Backups and management interfaces isolated first — these are what ransomware operators target.
Why second: this determines how far an intrusion spreads. See network segmentation.
Phase 3 — Device trust
- Endpoint protection deployed and actually monitored.
- Device posture checks — patch level, encryption, endpoint agent health — before granting access.
- Managed device inventory, so unknown devices are visible.
Phase 4 — Application-level access
- Replace broad VPN access with ZTNA, granting access to specific applications rather than the whole network.
- Continuous re-evaluation rather than a single authentication at connection time.
- Access decisions informed by identity, device state and context together.
Phase 5 — Visibility and refinement
- Centralised logging and monitoring so policy violations are visible.
- Regular access reviews — entitlements accumulate silently.
- Progressive tightening as confidence grows.
How we work
- Assessment — current identity, network, endpoint and access posture against zero-trust principles.
- Roadmap — phased plan sequenced by risk reduction per unit of effort and cost, using your existing licences where possible.
- Implementation — delivered in controlled phases with rollback plans, avoiding disruption.
- Validation — we test that controls work, including penetration testing to verify segmentation genuinely holds.
- Documentation and handover — so your team can maintain it.
Realistic expectations
You will not "complete" zero trust — it is a direction, not a finish line. Legacy applications will resist modern authentication. Some systems cannot be segmented without replacement. Our job is to get the maximum practical risk reduction within your real constraints, and to be clear about the trade-offs rather than presenting an idealised architecture you cannot fund or operate.