zero trust architecture

Zero Trust Architecture and Identity-First Security: Why ‘Trust but Verify’ No Longer Cuts It

We still come across organisations running on the assumption that if someone’s inside the network, they can be trusted. It’s understandable — that was the prevailing logic for years, and a lot of infrastructure was built around it. But it’s also one of the things that keeps us busy cleaning up after incidents that didn’t need to happen.

The problem is that the “inside the network” idea has quietly fallen apart. Your people are working from home, from hotels, from wherever. Your data is spread across cloud platforms and SaaS tools that have nothing to do with your on-premises infrastructure. There isn’t really a perimeter anymore — and if you’re still treating network location as a proxy for trust, you’ve got a gap that someone will eventually find.

Zero Trust is the answer to that. Not a product, not a box you tick — a different way of thinking about who and what gets access to your systems, and why.

The shift in thinking

The core idea is simple enough: don’t trust anything by default. Every user, every device, every connection gets verified before it gets access — and that verification happens every time, not just at login. It sounds strict, and it is, but that’s the point.

What this means in practice is that security stops being about defending a boundary and starts being about controlling access at a much more granular level. The question is no longer “did this person get past the firewall?” It’s “who is this person, what are they trying to do, and should they actually be allowed to do it right now?”

Identity becomes the thing that everything else is built around. Which is why you’ll hear people talk about identity-first security — it’s not just a buzzword, it’s a genuine shift in where the controls sit.

Where Network Access Control fits in

One of the first conversations we have with clients who want to move towards Zero Trust is about Network Access Control. NAC is what enforces the rules around who and what gets onto your network in the first place. Done properly, it means unrecognised devices get blocked, authenticated users only reach what they’re supposed to reach, and your IT team has visibility over everything that’s connecting.

We pair this with role-based access control, so that even once someone’s authenticated, they’re only seeing the systems relevant to their job. A compromised set of credentials is a serious problem, but it’s a much less serious problem if the attacker who’s using them can’t actually get to anything sensitive. That containment is one of the most underappreciated aspects of a Zero Trust approach.

SASE — security that travels with your users

A lot of our clients have moved to SASE in recent years, and it’s a natural fit for Zero Trust environments. The basic premise is that security functions move to the cloud, so they’re applied at the point of connection rather than at the edge of a data centre. Your policies follow your users, wherever they are.

We work with Fortinet and HPE on SASE deployments, and the difference it makes to organisations with a dispersed workforce is significant. Remote users get the same security treatment as someone sitting in the office. Cloud applications are covered by the same policies as on-premises systems. And your team gets a single, consistent view of what’s happening across the whole environment, rather than piecing it together from different tools.

In Zero Trust terms, this matters because inconsistency is where things go wrong. If your security policies apply everywhere except when someone’s working from home, you don’t really have Zero Trust — you have Zero Trust with a large exception carved out of it.

What about firewalls?

They still matter. Zero Trust doesn’t make firewalls redundant — it changes what they’re doing. Rather than being the wall between the trusted inside and everything else, they become one layer in a more layered defence. Our deployments include deep packet inspection and application-aware filtering that work alongside identity controls, not instead of them. The firewall can see what’s moving; the identity layer determines whether it should be moving. Both need to be doing their job.

Multi-site organisations and SD-WAN

If you’re running across multiple sites — multiple offices, a retail estate, an academy trust with several schools — applying Zero Trust consistently across all of them is genuinely hard without the right infrastructure. SD-WAN helps here. It connects your sites intelligently, manages traffic across multiple paths, and crucially lets you push the same security policies out from the centre to every location.

Without that, you end up with security that’s solid at head office and patchier everywhere else. Which is exactly the kind of inconsistency that attackers look for.

Getting there from here

We’re not going to pretend Zero Trust is a quick project. For most organisations, it’s a staged process that takes time to do properly. Where we usually start is with a consultancy engagement — not to sell anything, but to get an honest picture of where the gaps are and what a sensible path forward looks like given the existing infrastructure and budget.

From there, our professional services team handles the design and deployment, and our managed services keep things running and monitored once it’s in place. For organisations that don’t want to carry the capital cost of a major infrastructure change, our Network-as-a-Service model is worth looking at — enterprise-grade security on a monthly cost, without the upfront outlay.If any of this sounds familiar — if you’re aware that your current setup relies on assumptions that don’t really hold anymore — it’s worth a conversation. We’re not in the business of making things sound more complicated than they are, and we’re not going to push you towards a solution before we understand your situation.

hello@severntechs.co.uk  |  +44 (0) 2921 685 410  |  severntechs.co.uk

Leave a Reply

Your email address will not be published. Required fields are marked *