The perimeter collapsed
When infrastructure lives across multiple clouds, SaaS, and edge locations, a network perimeter no longer exists as a meaningful boundary. Identity is the new perimeter.
The three pillars
- Verify explicitly — authenticate and authorise every request based on identity, device posture, and context.
- Least privilege — grant just-enough, just-in-time access. No standing admin.
- Assume breach — segment, encrypt in transit and at rest, and log everything.
Where to start
Most organisations cannot flip to Zero Trust overnight. Start with the highest-risk blast radius: privileged access to production. Replace standing admin with just-in-time elevation and require MFA on every privileged path.
The role of the landing zone
Your cloud landing zone should encode Zero Trust from day one: private endpoints by default, no public storage, managed identities over secrets, and policy-driven network controls.
Zero Trust is not a product. It is a property of how you architect access.

