Help desk 24/7/365 · Office 9–5 MT, Mon–Fri +1 (208) 391-7176 Team@alcousa.org

Zero trust for a business that isn't a tech company

The term is overused and oversold. Underneath it is a simple, practical idea most organizations can start applying without buying anything.

"Zero trust" has been marketed hard enough that it now sounds like a product you buy and switch on. It isn't. It's a design principle, and the principle is unglamorous: stop treating the network as a boundary of trust.

For years, security was built like a building with a locked front door. Once you were inside — on the office network, on the VPN — you were treated as trusted. That made sense when work happened in one place, on machines the company owned. It stopped making sense the moment staff started working from home, data moved into Microsoft 365 and Google Workspace, and half of everyone's logins went to services the company doesn't host.

What zero trust actually means

The short version is: verify every time, and trust nothing simply because of where it sits. A request from a laptop in your office earns no more benefit of the doubt than one from a coffee shop. Identity, device health and context decide access — not an IP address. You do not need a six-figure platform to move in this direction. Most of the meaningful gains come from things you may already own.

Start with identity

Strong multi-factor authentication on every account is the single highest-value step, and it is the foundation everything else rests on. Not SMS codes, which are phishable, but an authenticator app or, better, hardware keys for the accounts that matter. Then make sure access is scoped: people should have the access their job needs and no more, reviewed when they change roles or leave.

Then look at devices

A verified identity on a compromised laptop is still a problem. Knowing which devices are allowed to reach your data — and that they are patched, encrypted and running current endpoint protection — closes the gap that identity alone leaves open.

The honest part

Done badly, this becomes a wall of prompts that trains people to approve without thinking, which is worse than no prompt at all. The goal is not maximum friction. It is friction in the right places: strong verification at sign-in and for sensitive actions, and as little as possible in between. That balance is a design decision, not a default setting.

Zero trust is a direction, not a finish line. You move toward it one control at a time, starting with the ones that would have stopped the incidents you actually read about.

More from ALCO

What good IT reporting should tell you

If you fund IT but can't see what it's doing, you're paying on faith. Here's what a clear report should show — and why i

Read more

Reuse is the real password problem

The weak password is rarely the one that gets you breached. The reused one is.

Read more

What break-fix really costs

Paying only when something breaks looks like the frugal choice. The math usually says otherwise.

Read more

Is this the right fit?

We qualify every engagement before we quote one. That means a technical conversation about your estate, not a sales call — and a straight answer if we are not the right firm.

Let us look at what you are running.

A scoping conversation with a senior engineer. We will tell you what we would change, what it would cost, and whether we are the right firm for it.