“Zero Trust appears in every security vendor's presentation and almost always with a six-digit price tag attached. To a Portuguese SME, that sounds like something for a bank or a multinational. It isn't. Zero Trust is a simple idea — do not trust anyone just because they are inside the network — and most of the steps are done with tools the company already pays for. This article translates the concept into four concrete steps, in the order that makes sense for a company with 10 to 200 workstations.
The old model: the moated castle
For twenty years, corporate security operated like a castle: a firewall at the entrance, and anyone inside the network could move around freely. That worked when everyone worked in the office, on company computers, with servers in the rack. Today, people work from home, email and files are in Microsoft 365, suppliers connect to the network, and mobile phones access everything. The “inside” has ceased to exist. When an attacker gets in using an employee's credentials — which is how most attacks begin — the castle doesn't stop them, because as far as the network is concerned, they are a legitimate user.
The Zero Trust model in one sentence
Every access is verified: who the user is, what device they are using, from where, which resource they want to reach and whether they actually need it. Not just once, at the entrance, but on every single request. It sounds heavy-going, but most of the verification is automatic and invisible to those doing the work.
Step 1 — Identity: knowing who is who
Without reliable identity there is no Zero Trust. The concrete step is to enable the multi-factor authentication across all accounts, starting with Microsoft 365, and clean up the accounts of former employees. Then, reduce the number of administrators to two or three identified people and get rid of shared accounts. Cost: zero in licences for most Microsoft 365 plans; the work involves organising and communicating. It is also the step with the highest return: with MFA enabled, a password stolen via phishing is no longer enough to log in.
Step 2 — Equipment: only those known to the company are permitted
A personal laptop without an antivirus, running unpatched Windows, should not access company email in the same way as a managed workstation. The specific step is to have an inventory of company devices, ensure that all have active endpoint protection and up-to-date patches, and restrict data access to devices that meet these requirements. In Microsoft 365, this is done with Conditional Access policies; on local networks, with device authentication on Wi-Fi and network ports. Workstations still on unsupported Windows 10 are the first problem to solve — see what to do about the end of Windows 10 support.
Step 3 — Network: divide and conquer
If a workstation is compromised, the attacker must not be able to reach the billing server, the cameras or the POS terminal. The concrete step is to segment the network into VLANs: workstations, servers, visitors, printers and cameras on separate networks, with the firewall deciding what passes between them. We explained how to do this in the article about VLANs and network segmentation. In an SME with managed switches and a managed firewall, this is configuration, not procurement. It's also the step that most reduces the damage of a ransomware attack: instead of encrypting everything, it encrypts a single segment.
Step 4 — Least privilege: everyone only gets what they need
Sales don't need to write to the accounts folder; the intern doesn't need to be an administrator of their laptop; the management software vendor doesn't need permanent access to the whole network. The concrete step is to review permissions on shared folders and SharePoint, remove local administrator rights from users, and replace the open VPN with logged access to specific applications. We talked about this in the article a VPN is no longer enough. It is the most laborious step because it messes with habits — and for that reason it should be the last one, when the others are already working.
What gets left out (and why)
“Complete” Zero Trust includes things like behavioural analytics, application-level micro-segmentation and continuous device posture checks. They are useful, they are expensive and, in an SME, the return on investment is small until the four steps above have been completed. Order matters: MFA without segmentation protects the accounts but not the network; segmentation without MFA protects the network but not the accounts.
How long does it take
Step 1: one to two weeks, chiefly communication with users. Step 2: two to four weeks, depending on the state of the equipment. Step 3: a network intervention, usually out of hours, plus a few days of adjustments. Step 4: ongoing work, carried out department by department. In our contracts managed cybersecurity these steps are the foundation of the plan — and are put in writing, with the status of each one in the monthly report.
Frequently Asked Questions
Is Zero Trust a product you can buy?
No. It is a way of designing access controls. There are products that help, but the essential steps — MFA, device inventory, network segmentation and least privilege access — are done with tools that most companies already have.
Will it delay people's work?
Well done, it is barely noticeable: MFA asks for confirmation once a day per device, and Conditional Access is invisible when the device meets the requirements. What people notice is when they can no longer install programs on their own — and that is intentional.
Does a company with 15 workstations need this?
You definitely need steps 1 and 3: MFA and a separate guest network. Steps 2 and 4 scale with the size and sensitivity of the data handled.
Does NIS2 require Zero Trust?
It doesn't use the term, but it requires access management, multi-factor authentication and segmentation as risk management measures. Whoever follows these four steps gets a large part of the technical work done. Look if your company falls within the scope of NIS2.
Want to know what stage your business is at?
We survey the access, network and equipment and deliver a written plan with priorities and deadlines. See our managed cybersecurity for businesses or call 211 459 950.





































