Zero Trust Is Not a Product You Buy
At some point someone is going to walk into your office, or worse, send you a LinkedIn message, offering to sell you "Zero Trust." A box. A license. A one-time deployment that checks the box and lets everyone move on with their lives.
It doesn't work like that, and if you buy it thinking it does, you'll have spent real money on something that quietly stops mattering the day after it's installed.
Zero Trust isn't a product. It's an operating model — a way of making access decisions that never assumes anyone or anything is safe just because it's already inside your network. That distinction sounds academic until you realise it's the whole point.
The old model, and why it broke
For a couple of decades, network security worked roughly like a building with one locked front door. Get past reception — a password, a VPN connection — and you could wander most of the halls freely. The assumption was: if you're inside, you're trusted.
That assumption made sense when "inside" meant an office, a handful of servers in a back room, and employees who logged in from one desk. It stopped making sense the moment work moved to laptops, cloud apps, personal phones, and contractors logging in from three time zones away. There isn't really an "inside" anymore for most SMEs. There's just people and devices, everywhere, all trying to reach data that lives somewhere else entirely.
Zero Trust starts from a much blunter premise: assume the network is already compromised. Don't trust a request because of where it came from. Verify it, every time, based on who's asking, what device they're using, and whether the request actually makes sense.
What "never trust, always verify" means in practice
The official language comes from NIST's Zero Trust Architecture standard, and it boils down to a few habits, not a shopping list:
Verify explicitly. Every request gets checked — who's asking, from what device, in what context — rather than waved through because it came from inside the office Wi-Fi.
Least privilege, actually enforced. People and systems get access to exactly what they need for the task in front of them, not the whole shared drive because it was easier to set up that way.
Assume breach. Design as though someone's already gotten in. If an attacker compromises one laptop, the question is whether they can then wander freely to everything else, or whether they hit a wall two steps later.
None of this is a piece of hardware. It's a set of decisions about how access gets granted and re-checked, applied consistently across the tools you already have.
Why the "buy a box" pitch is so tempting anyway
It's not that vendors are lying, exactly. Plenty of real products genuinely support a Zero Trust approach — identity providers, device management tools, network segmentation platforms. The trouble is that a product only does its job if it's wired into an actual policy: who gets access to what, under which conditions, reviewed on some kind of schedule.
Buy the tool without doing that thinking first, and you end up with expensive software configured close to how the old perimeter model worked anyway — because that's the default, and nobody went back and actually tightened it.
For an SME specifically, this matters more than it sounds like it should. You don't have a large security team to babysit a complex rollout. Whatever you put in place needs to survive without constant hand-holding, which means the policy thinking has to come first, and the tooling has to fit what you can actually maintain.
Where an SME actually starts
Not with a big-bang rollout. A few honest starting questions get you further than most vendor pitches:
Who has access to what right now, and does that still make sense? Most small businesses have accumulated access over years — a former contractor who still has a login, a shared drive everyone can see because it was easier that way in year one. That inventory alone usually turns up more risk than any tool would catch.
Is multi-factor authentication actually turned on everywhere it should be — not just email, but the accounting system, the CRM, the admin panel nobody thinks about? This is the cheapest, highest-leverage step most businesses haven't finished.
If one laptop got compromised tomorrow, what could the attacker reach from there? If the honest answer is "everything," that's the gap Zero Trust is actually meant to close.
The part that doesn't end
Here's the bit the box-sellers leave out: Zero Trust isn't a project with a finish line. Access needs change as people join, leave, and change roles. New tools get adopted. What made sense a year ago quietly stops making sense, the same way it did under the old perimeter model — just faster, because things move faster now.
Treat it as a policy you revisit, not a purchase you close out. That's the actual difference between an organisation that's "done Zero Trust" on paper and one that's genuinely harder to move through if something goes wrong.
Belian Advisory runs architecture reviews that look at how access actually flows through your business — not just what's plugged in. If you want a straight read on where the gaps are, get in touch.