Architecture
Zero trust beyond the buzzword: a realistic 90-day path
Zero trust programmes fail when they start as an architecture diagram. Here is the sequence that survives contact with a real organisation.
Zero trust is not a product you buy, and it is not a project you finish. It is a set of assumptions applied progressively: no implicit trust from network location, verification on every request, least privilege by default.
Days 1–30: see what you have
Nothing works without an accurate identity inventory. Enumerate every human account, service account, API key and integration. Map which of them can reach production data. In almost every assessment, this stage alone finds accounts nobody can explain — usually with more privilege than the people asking about them.
Days 31–60: harden the front door
Migrate to phishing-resistant authentication for administrators first, then all staff. Implement conditional access with device compliance as a signal. Kill legacy authentication protocols that bypass your policies. Expect this to be the politically hardest phase; it touches everyone.
Days 61–90: reduce the blast radius
Introduce just-in-time elevation so standing admin rights disappear. Segment your highest-value systems so that a compromised workstation reaches a wall rather than a database. Begin access reviews with real owners rather than a rubber-stamp workflow.
What comes after
Ninety days does not finish zero trust — it establishes the foundation the rest depends on. Micro-segmentation, continuous authorisation and data-centric controls all become viable once identity is trustworthy. Attempting them first is why so many programmes stall in year two.
Seeing something similar in your environment?
Talk to our team