IT security

Zero Trust

Also known as: Zero Trust Model · Zero Trust Security

In short

Zero Trust is a security model that never trusts a device or request automatically just because it comes from inside the network.

Zero Trust is a security model in which where a request comes from – inside or outside the company network – no longer determines whether it's trusted. Instead, every request is checked individually, whether it comes from an office laptop or a device working from home. The US standards body NIST describes this model in its SP 800-207 document with the principle 'never trust, always verify'.

In practice this means that instead of logging into a VPN once and then moving freely across the whole internal network, a user or device has to prove itself again for every single access to an application. That usually involves several factors, such as a password plus a second proof tied to a device, combined with rules about which device may access which application. Zero Trust is therefore not a single product but a combination of identity verification, device control and fine-grained access rules.

A common misunderstanding is treating Zero Trust as a single product you buy – in reality it's a gradual rework of existing access patterns that's rarely finished overnight. It's equally wrong to assume an internal network no longer needs a firewall as a result; Zero Trust adds to existing protections, it doesn't replace them.

What it means in practice

For an SME, Zero Trust becomes relevant mainly where staff access cloud applications and internal systems from different locations and devices, such as working from home or on the road. One sign it's missing is a VPN login that grants unrestricted access to the entire internal network once connected. NDVDL introduces Zero Trust elements such as multi-factor authentication and fine-grained access rules gradually into existing networks.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.