Definition

Zero Trust is a security model that trusts no user, device or service on the strength of its location in the network. Every access is evaluated individually – on identity, device state and context.

At a glance

Trust comes from verification, not from location.

Every access is decided individually, not once per session.

Zero Trust is a model, not a product you buy.

Zero Trust replaces the question “where are you?” with “who are you, on what, and are you allowed to do this now?”.

There is no inside any more

The classic model knew a trusted inside and a dangerous outside. With cloud, home working and partners, that inside no longer exists. Zero Trust therefore pulls the control down to every single access.

Real-world examples

  • An access from the office is refused because the device has not been patched for weeks.
  • A service account is granted rights only for the duration of a single job.

Common misconception

Myth “Zero Trust is a product you roll out.”

Reality It is a model that works its way into existing systems over years. Buying it as a product gets you one building block at most.

Frequently asked questions

Where do you start with zero trust?

With identity and multi-factor authentication – the block with the greatest effect. NIST SP 800-207 describes the architecture.

Does zero trust replace segmentation?

No, it builds on it. NIST SP 800-125B covers the network side.