Zero trust for a small business: where to start
KINNEX Team5 min read
Zero trust means no user or device is trusted just because it is on the office network. Every request is checked. That sounds large, but the first steps are modest.
The principles
- Verify explicitly: check identity, device health and context for each access.
- Use least privilege: give people only what they need.
- Assume breach: design so that one compromised account does not expose everything.
Practical first steps
- Strong identity. Single sign-on and multi-factor authentication everywhere.
- Device management. Know which devices are company-managed, encrypted and patched.
- Conditional access. Require compliant devices for sensitive applications.
- Replace broad VPN access with per-application access (ZTNA) where it is practical.
- Segment the network so a compromised laptop cannot reach servers and cameras.
- Log and watch. Collect sign-in and endpoint logs, and alert on unusual behaviour.
Common traps
Buying a product labelled zero trust and stopping there; skipping the inventory of users, devices and applications; and making controls so awkward that people work around them.
A sensible order
Identity and devices first, then access to applications, then network segmentation, then monitoring. Each step reduces risk by itself, and none needs a big-bang project.
The aim is simple: a stolen password or an infected laptop should be an incident, not a disaster.