Skip to content
Menu

Security model

Zero trust

Zero trust is a security approach that verifies every request on its own merits — who is asking, from what device, for what — instead of granting access because the request came from inside the network.

It matters because the assumption it replaces stopped being true. Remote work, cloud services and third-party access mean there is no longer an inside, and a model that trusts location trusts whatever has reached that location.

The common misunderstanding is treating it as a product. There is nothing to install that makes an environment zero trust; it is a set of decisions about identity, device posture and least privilege, applied over time to systems that were built assuming the opposite. A vendor selling you zero trust is selling you one component of it.