Zero trust for a business that isn't a tech company
The term is overused and oversold. Underneath it is a simple, practical idea most organizations can start applying without buying anything.
"Zero trust" has been marketed hard enough that it now sounds like a product you buy and switch on. It isn't. It's a design principle, and the principle is unglamorous: stop treating the network as a boundary of trust.
For years, security was built like a building with a locked front door. Once you were inside — on the office network, on the VPN — you were treated as trusted. That made sense when work happened in one place, on machines the company owned. It stopped making sense the moment staff started working from home, data moved into Microsoft 365 and Google Workspace, and half of everyone's logins went to services the company doesn't host.
What zero trust actually means
The short version is: verify every time, and trust nothing simply because of where it sits. A request from a laptop in your office earns no more benefit of the doubt than one from a coffee shop. Identity, device health and context decide access — not an IP address. You do not need a six-figure platform to move in this direction. Most of the meaningful gains come from things you may already own.
Start with identity
Strong multi-factor authentication on every account is the single highest-value step, and it is the foundation everything else rests on. Not SMS codes, which are phishable, but an authenticator app or, better, hardware keys for the accounts that matter. Then make sure access is scoped: people should have the access their job needs and no more, reviewed when they change roles or leave.
Then look at devices
A verified identity on a compromised laptop is still a problem. Knowing which devices are allowed to reach your data — and that they are patched, encrypted and running current endpoint protection — closes the gap that identity alone leaves open.
The honest part
Done badly, this becomes a wall of prompts that trains people to approve without thinking, which is worse than no prompt at all. The goal is not maximum friction. It is friction in the right places: strong verification at sign-in and for sensitive actions, and as little as possible in between. That balance is a design decision, not a default setting.
Zero trust is a direction, not a finish line. You move toward it one control at a time, starting with the ones that would have stopped the incidents you actually read about.
Más de ALCO
What good IT reporting should tell you
If you fund IT but can't see what it's doing, you're paying on faith. Here's what a clear report should show — and why i
Leer másReuse is the real password problem
The weak password is rarely the one that gets you breached. The reused one is.
Leer másWhat break-fix really costs
Paying only when something breaks looks like the frugal choice. The math usually says otherwise.
Leer más¿Encaja con lo que necesita?
Cualificamos cada proyecto antes de presupuestarlo. Eso significa una conversación técnica sobre su infraestructura, no una llamada comercial, y una respuesta clara si no somos la firma adecuada.