Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryZero Trust
Glossary

Zero Trust

Zero trust is a security model in which every user, device and request is verified before access is granted, even when it comes from inside the network.

Definition

What is Zero Trust?

Zero trust is a security model built on the rule that no user, device or connection is trusted by default, even when it is already inside the company network. Every request for access is checked against identity, device health, location and the sensitivity of what is being asked for, and access is granted only to the specific resource needed, for as long as it is needed. The model replaces the older assumption that anything behind the firewall is safe, which stopped holding once staff worked from home and data moved to cloud services.

In practice zero trust is a set of controls that work together rather than one product. Identity is verified with multi-factor authentication. Devices must be enrolled and compliant, with disk encryption and current patches, before they can reach company data. Conditional Access policies evaluate each sign-in and can block, allow or require extra steps. Access rights follow least privilege, so an employee in accounting cannot open engineering files, and administrative rights are activated just in time rather than held permanently. Networks are segmented so a compromised laptop cannot reach the server room. Everything is logged and monitored, because the model assumes a breach will happen and plans to notice it quickly.

For a small or mid-sized business, most of these controls already exist inside Microsoft 365 Business Premium: Entra ID for identity, Intune for device compliance, Conditional Access for policy and Defender for monitoring. Zero trust for a company of fifty people is largely a matter of configuring those tools with intent and cleaning up the exceptions. The frameworks insurers and regulators point to, including NIST's zero trust architecture guidance, describe the same principles.

NetSys implements zero trust for clients through its zero trust service, starting with an assessment of identities, devices, applications and access paths, then rolling out MFA, Conditional Access, Intune compliance and privileged access controls in an order that avoids locking anyone out. The work is included in a managed agreement rather than sold as a separate project.

Why it matters for a small business

Your network perimeter no longer exists in any useful sense: people work from home and your data lives in Microsoft 365 rather than on a server in the closet. Zero trust is the security posture that matches that reality. It keeps a phished password or a lost laptop from becoming a full breach, because each is only one of several checks. If you use Microsoft 365 Business Premium, most of the tooling is already licensed and needs to be switched on and tuned rather than bought.

Common Questions

Zero Trust: FAQs

Is zero trust a product I can buy?

No. Zero trust is an architecture and a set of policies, and vendors that sell a zero trust product are selling one component of it, usually network access or identity. A business implements zero trust by configuring identity verification, device compliance, least-privilege access, segmentation and monitoring across the tools it already runs. For a Microsoft 365 shop that means Entra ID, Intune, Conditional Access and Defender, plus a firewall that supports segmentation. The buying decision is about the service that configures and maintains those pieces.

What is the difference between zero trust and a VPN?

A VPN puts a remote device onto the company network and then trusts it as if it were in the office, which is exactly the assumption zero trust rejects. Zero trust network access (ZTNA) instead connects the user to a specific application after checking identity and device health, and never exposes the rest of the network. Many small businesses still run a VPN for legacy systems; the zero trust approach is to limit what the VPN can reach, require MFA and device compliance on it, and move applications to identity-based access over time.

How long does it take to implement zero trust?

For a small business on Microsoft 365, the core controls, MFA, Conditional Access, device enrollment and admin role cleanup, can be rolled out in weeks, staged so that each policy runs in report-only mode before it enforces. Segmentation and application-level access take longer because they depend on how many legacy systems exist. Zero trust is better treated as an operating standard than a project with an end date; policies are reviewed as staff, devices and applications change.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.