Trust no one. Question everything. It sounds like a spy novel or a whodunit mystery, but, in reality, it’s the beginning of making your network more secure.
Zero trust is a framework for continuously validating your users before allowing them access to applications and data. In the past, organisations had a defined “border” for their network – on-premise, in the office, connected to the server. Now, however, we have cloud, hybrid, VPNs and various other challenges. There is no longer a network edge, so our approach to security must expand beyond our traditional borders.
Asset tracking
Working towards zero trust is one arm of your organisation’s digital strategy, or your ongoing plan for continuous improvement. To successfully implement a zero-trust policy and approach, you need a strong asset management solution in place. This enables you to identify what is on your network, who uses it, what applications and websites are accessed, and how often. ITAM solutions also benefit your digital strategy, as you can plan for future growth more effectively and quickly identify outdated equipment or unused licences.
Connection
With so many companies moving to hybrid or remote working models, organisations run the risk of exposure from devices connected to home networks or public Wi-Fi. Although VPN solutions were often the go-to, they can be easy to circumnavigate or abuse.
Remote access solutions provide extra layers of security, especially if they offer multi-factor authentication, event logging, and access privileges – and in today’s environment of dispersed working with technology devices out in the field, secure remote support is vital. Creating a more secure connection to the network or office devices is a strong initial step towards adopting zero trust. However, just because someone has access doesn’t mean they should be able to open every door.

Collaboration
Consider your home – you allow guests inside, and may even give some family members a key. You do not let them into every room or provide access to everything you own.
The same is true for your IT assets. Different users require different privileges, and those will depend on their roles, departments, and the tools necessary to complete their responsibilities.
To determine who gets access to what, you’ll need to collaborate with members from every department. Invite representatives to the proverbial table to understand what is mission-critical, nice to have, and peripheral to their roles, then update user profiles and settings to allow for the least possible access necessary.
Professional development
End users are often left out of the discussion regarding zero trust until implementation day. That is a mistake. If you want your organisation to continue functioning smoothly, you’ll need your end users on board for any changes you make. Piloting any planned changes with a small group works like a restaurant’s soft opening – you’ve already planned the menu and trained the staff, but you want to ensure you have all the problems ironed out before you’re fully operational. You get the added benefit of end-user buy-in when that small cohort is successful and can assist their colleagues with navigating any changes.
Additionally, organisations should consider appointing a Security Awareness Lead. This person is a go-to for explaining the changes, provides ongoing professional development and education around security awareness, and can help end users adopt zero trust. Continuing education about security awareness has the added benefit of bringing it top of mind for end users who might otherwise not prioritise it. The more aware they are of potential digital pitfalls, the more vigilant they become (and likely to avoid them).
Zeroing in
Zero trust is a journey; one that isn’t completed in a single step. There are many facets to bringing your organisation closer, and while it’s tempting to focus on one area, you’ll benefit more from adopting a zero-trust mindset when it comes to developing your digital strategy.
Ultimately, it will take the onus off one person or department, instead changing the approach to one the entire company can adopt and embed into the culture. Through collaboration, better asset tracking and continuing education, you can develop a more resilient, secure and prepared environment.
Originally published 3 July 2023. Updated 28 March 2025.
