Vendors often pitch Zero Trust as a product you can buy. It is not. Instead, it is a way of designing access so that no user, device, or connection earns trust just by sitting inside your network.
What Zero Trust actually means
The old model treated the office network like a castle. Once you were inside the walls, you could reach almost everything. The new model assumes an attacker may already be inside, so every request has to prove itself.
NIST put it formally in SP 800-207, published in August 2020. That document describes a shift from network perimeters toward protecting users, assets, and resources directly.
In practice, that means three habits. First, verify identity and device health on every access.
Second, give people only the access their job requires. Third, assume breach and limit how far an intruder can move.
Why the castle model stopped working
Your staff now work from home, from client sites, and from phones. Your data lives in Microsoft 365 and a dozen cloud apps. So the “inside” of your network barely exists anymore.
Attackers have noticed. The Verizon 2025 Data Breach Investigations Report found that credential abuse was an initial access vector in 22% of breaches. Exploited vulnerabilities accounted for 20%, and third-party involvement doubled to 30% of breaches.
Each of those paths lets an attacker start from a trusted position. A stolen password, a vulnerable firewall, or a vendor’s remote access tool all bypass the castle wall. As a result, perimeter defenses alone cannot carry the load.
The building blocks, in order of payoff
CISA released version 2.0 of its maturity model in April 2023. It organizes the work into five pillars: identity, devices, networks, applications and workloads, and data. For a smaller organization, it helps to think about them in order of payoff.
Identity
Start here, because most attacks start here. Require multifactor authentication for every account, and remove standing admin rights from daily-use accounts.
Also hunt down shared logins. When five people use one account, you cannot tell who did what, and you cannot revoke access for just one of them.
Devices
Next, make sure only managed, healthy devices can reach company data. That means current patches, endpoint protection, and encryption. Personal phones can still work, but only through controlled apps that keep company data separate.
Applications
Then control what software can run. Application allowlisting blocks unknown programs by default, which stops a lot of ransomware before it starts.
Networks and data
Finally, segment the network so a compromised laptop cannot reach every server. Also label sensitive data and restrict who can share it outside the company.
What it looks like in a 60-person office
Picture an ordinary day under this model. An employee signs in from home. The system then checks their identity and whether their laptop is managed and patched.
They reach the files and apps their role needs, and nothing else. Meanwhile, an unknown program they downloaded simply does not run.
If an attacker steals their password, the attacker still lacks the approved device and the second factor. And if malware slips through anyway, segmentation keeps it away from finance and the file server.
None of this requires a large security team. Instead, it requires good defaults, applied consistently.
A phased rollout that does not break the business
The fastest way to fail is trying to change everything in one weekend. Instead, move in phases and measure each one.
- Map your access. List who uses which systems, from which devices, and why.
- Enforce MFA everywhere. Cover email, remote access, cloud apps, and admin portals first.
- Separate admin accounts. Nobody should browse the web or read email with administrator rights.
- Require managed devices for access to company data, with conditional access policies in Microsoft 365.
- Turn on application allowlisting in learning mode, review what it finds, then enforce.
- Segment the network, starting with guest Wi-Fi, printers, and cameras.
- Review access quarterly and remove what people no longer need.
For real-world examples, see SP 1800-35, which NIST’s National Cybersecurity Center of Excellence published in June 2025. It documents 19 example implementations built with commercial products.
Three myths worth dropping
“We are too small for this.” The core controls are MFA, managed devices, and least privilege. All three are within reach for a 20-person office.
“It means we don’t trust our employees.” It is about verifying access, not doubting people. In fact, it protects staff from having their accounts turned against the company.
“We bought a firewall, so we’re covered.” A firewall is still useful. However, it cannot stop someone who logs in with a valid stolen password.
Where Zero Trust projects stall
Most projects do not fail on technology. Instead, they stall on exceptions.
A senior leader wants to skip MFA on a personal tablet. A vendor needs permanent remote access “just in case.” Then a legacy app only works with admin rights. Each exception seems small, but together they rebuild the castle wall you were trying to retire.
So set a rule early: every exception gets an owner, a business reason, and an expiration date. Review the list quarterly, and close what is no longer needed. That single habit keeps the model honest over time.
How WEBIT approaches this
We build this model into the baseline rather than selling it as an upgrade. Security Essentials runs on every managed device, including Zero Trust EDR, application allowlisting, DNS filtering, and vulnerability management. Every client is also baselined to the CIS Controls, and add-ons such as Duo MFA and privileged access management close the identity gaps.
In my experience, the hard part is not the tools. It is rolling them out without disrupting people, which is why we phase changes and explain them first. You can see how the pieces fit on our cybersecurity services page, or price them on our pricing page.
Key takeaways
- Zero Trust is a design approach, not a single product.
- Stolen credentials and exploited vulnerabilities make the old perimeter unreliable.
- Start with identity, then devices, applications, and network segmentation.
- Roll out in phases, with learning modes before enforcement.
- Smaller organizations can adopt the core controls affordably.
Related from WEBIT: free Security Scorecard and cyber insurance readiness checklist.
Want a second opinion on your access controls? Talk to an owner.





