Technology
Oct 30, 20255 min read

The evolution of zero trust security

Never trust by default, always verify, and make every step an attacker takes harder.

Dr. Ravindra Shinde
Dr. Ravindra Shinde
Chief Executive Officer
The evolution of zero trust security

The perimeter is gone

Traditional security was built like a castle. Everything valuable sat inside the network, a strong wall kept attackers out, and anyone who made it inside, an employee at their desk or a server in the data center, was largely trusted.

That model stopped matching reality years ago. Employees work from home, cafés and airports. Applications run in several clouds and dozens of software-as-a-service platforms. Partners, contractors and automated systems all need access. There is no longer a clear inside and outside to defend. And when attackers do get in, usually with stolen credentials, a flat, trusting network lets them move freely.

Zero trust is the response. Its core idea is simple: never trust by default, always verify. Every request for access is checked on its own merits, based on who is asking, from what device, for what, and whether that makes sense right now.

Three principles

Zero trust frameworks, such as the widely used architecture guidance from the US National Institute of Standards and Technology, differ in detail. They share three principles.

  • Verify explicitly. Authenticate and authorize every access request using all the available signals: identity, device health, location, time and behavior.
  • Use least privilege. Give people and systems only the access they need, for as long as they need it, and nothing more.
  • Assume breach. Design as if an attacker is already inside. Limit how far they can move, encrypt data everywhere and watch for unusual activity.

How zero trust has evolved

Zero trust started as a network architecture idea. Over the past few years it has become broader and more practical.

Identity is the new perimeter

With users and applications everywhere, identity has become the main control point. Strong identity management, single sign-on across applications and consistent access policies are now the foundation of any zero trust program.

Passwords are giving way to phishing-resistant sign-in

Stolen and phished credentials remain one of the most common ways attackers get in. Traditional multi-factor authentication helps, but codes sent by text message or approved with a tap can still be phished or abused. Passkeys and hardware security keys, based on the FIDO2 standards, resist phishing by design, and they are now supported by all major platforms. They are also easier for users, which is rare in security.

Device health is part of the decision

A valid password on a compromised laptop is still a risk. Modern access decisions take the state of the device into account: is it managed, up to date, encrypted and free of known threats? Access can be limited or refused when the device does not meet the bar.

VPNs are being replaced

Traditional VPNs connect users to the whole network. Zero trust network access connects them only to the specific applications they are allowed to use, after checking identity and device each time. That shrinks the attack surface and usually improves the user experience.

Segmentation limits the damage

Inside data centers and clouds, microsegmentation divides systems into small zones with tightly controlled traffic between them. If one system is compromised, the attacker cannot easily reach the others.

Non-human identities matter as much as human ones

Applications, services, scripts and, increasingly, AI agents all access systems and data. In many organizations they outnumber human users, and their credentials are often long-lived and poorly monitored. Zero trust now has to cover these identities too, with short-lived credentials, least privilege and clear ownership.

Verification is continuous

Rather than checking once at sign-in, modern systems keep evaluating risk during a session. A sudden change in location, an unusual volume of downloads or access to unfamiliar systems can trigger a new check or end the session.

Regulation raises the bar

In Europe, the NIS2 Directive has widened the range of organizations subject to cybersecurity obligations and made management accountable for them, while DORA has applied to the financial sector since January 2025. Neither mandates zero trust by name, but both expect strong access control, risk management and the ability to detect and respond to incidents, which is exactly what a zero trust approach delivers.

Common mistakes

  • Buying zero trust as a product. No single tool delivers it. Zero trust is an approach, implemented through identity, devices, networks, applications and data together.
  • Trying to do everything at once. Large, all-encompassing programs stall. Progress comes from steady, prioritized steps.
  • Forgetting the users. Security that makes work painful gets bypassed. Good zero trust design, such as passkeys and single sign-on, often makes life easier.
  • Ignoring legacy systems. Older applications that cannot support modern authentication need to be isolated and protected, not left as exceptions forever.

A practical roadmap

  1. Strengthen identity. Consolidate on a central identity provider, enable single sign-on and roll out phishing-resistant authentication, starting with administrators and high-risk roles.
  2. Know what you have. Inventory users, devices, applications, data and non-human identities. You cannot protect what you cannot see.
  3. Protect the crown jewels first. Identify the most critical systems and data and apply the strictest controls there.
  4. Replace broad network access with application-level access for remote users and partners.
  5. Segment and monitor. Limit movement between systems and collect the logs that let you detect unusual behavior.
  6. Review and improve continuously. Remove access that is no longer needed and test your defenses regularly.

Zero trust is not a destination you reach. It is a way of designing and running systems that assumes attackers are capable and persistent, and makes every step they take harder. Our Cybersecurity team helps organizations take that journey one practical step at a time.