The old security model assumed a hard perimeter — a trusted inside and a dangerous outside — and it stopped matching reality years ago. Cloud, remote work, third-party access and mobile devices dissolved the perimeter, and the response that has become the default is zero trust: an architecture that trusts nothing by default and verifies every access on its merits, with identity as the control point. For most organisations the question is no longer whether to move this way but how far along they are, because the perimeter model they may still be running does not fit the environment they actually operate in.
What zero trust actually means
Stripped of the marketing, zero trust is a simple principle applied consistently: never assume trust based on network location; verify every request based on who is asking, what they are asking for, and the context. A user inside the office network gets no free pass; a service calling another service must prove it should. Identity becomes the primary control plane — the thing you check on every access — which is why the practical shape of zero trust is identity-first. Access is granted per request, least-privilege, and continuously evaluated, rather than granted once at the network boundary and trusted thereafter.
Why it has become the default
Three forces made zero trust the sensible baseline rather than an advanced option. The perimeter genuinely dissolved, so perimeter defence protects a boundary that no longer contains the important things. Attacks increasingly involve legitimate credentials and lateral movement, which a trusted internal network makes easy and zero trust makes hard. And regulators and frameworks — DORA, NIS2, and security standards generally — expect strong authentication, least privilege and access governance, which is the substance of zero trust under a different name. Adopting it is increasingly how you meet those expectations, not just how you improve security.
Free · 4 minutes
Would you survive contact with a determined attacker — or an auditor?
Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.
Getting there without boiling the ocean
- Start with identity. Strong authentication everywhere, especially for privileged access, and a clear picture of who can access what. Identity is the foundation and usually the highest-value first move.
- Segment to limit lateral movement. The internal network should not be flat; a compromise in one place should not reach everything, which is where zero-trust segmentation pays off directly against real attack patterns.
- Verify services, not just people. Machine and service identities need the same scrutiny, especially as automation and AI agents multiply the non-human actors in your systems.
- Treat it as a direction, not a product. Zero trust is an architecture you move toward incrementally, not a box you buy. The firms that succeed sequence it by risk rather than attempting a big-bang rebuild.
Identity-first, zero-trust architecture is now the default expectation for a regulated firm, because it matches the environment everyone actually operates in and the controls regulators actually ask for. The useful board question is not “should we do zero trust?” but “how far are we, and what is the next highest-value step?” — because the perimeter model, if it is still the working assumption anywhere, is protecting a boundary that has already gone.
Who this is for
This reading is for:
- CTOs and architects designing or modernising security architecture
- Boards hearing “zero trust” and wanting to know what it means for them
- Security leads whose model still assumes a trusted internal network
- Regulated firms whose auditors increasingly expect it
Sixteen Pillars helps you move toward identity-first, zero-trust architecture by risk, starting with the highest-value step rather than a big-bang rebuild. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Can you trust the architecture you have?
Architecture diagrams rarely show the reality of how systems actually operate. An independent review establishes what is really there.