Zero Trust and Identity-First Security
Originally reported viaNIST SP 800-207 Zero Trust Architecture / Microsoft SecurityZero Trust remains, in most organisations, more aspiration than architecture. The core principle — never trust, always verify — is sound, but implementation requires answers most organisations cannot confidently provide: who has access to what, why, and is that access still appropriate?
Why identity is the new perimeter
The dissolution of the network perimeter — driven by cloud adoption, remote work, and SaaS proliferation — has made network location an unreliable trust signal. An attacker with valid credentials is indistinguishable from a legitimate user at the network layer. The 2023–2026 wave of credential-based attacks all share a common pattern: valid identities used to access resources the organisation believed were protected.
90-day Zero Trust roadmap
Days 1–30: complete an identity inventory — export all accounts from AD, Entra ID, and top SaaS platforms, identify orphaned accounts and standing admin privileges. Days 31–60: enforce MFA on all internet-facing services. Days 61–90: implement just-in-time access for privileged roles — no standing admin rights, time-boxed elevation with approval and audit logging.
- Conduct an identity inventory across all directories and SaaS platforms. Disable or delete orphaned accounts immediately.
- Enforce phishing-resistant MFA (FIDO2/passkeys) for all admin accounts and internet-facing access.
- Implement just-in-time privileged access management. Remove standing admin rights.
- Review and right-size access permissions quarterly.
- Deploy conditional access policies factoring in device compliance, location, and risk signals.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.