northdan.
Vezi pagina în română

IT Glossary

What is Zero Trust?

The security model in which no person, device or application receives implicit trust — every access request is verified, wherever it comes from.

The old security model looked like a fortress: thick walls facing outwards and complete freedom inside, which meant an attacker who got past the wall could wander the entire network unchallenged. Zero Trust inverts that logic through one simple principle: trust nobody by default, verify everything. Every access request — to a file, an application, a database — is authenticated and authorised individually, whether it arrives from the office, from home or from the managing director’s phone. Every user receives only the minimum rights their role requires. And the network is divided into small segments, so that compromising one laptop does not mean compromising the company. For European businesses the relevance exploded alongside hybrid work and cloud applications, because the inside of the network simply no longer exists as a safe place: the applications live at a provider, the people live everywhere, and the perimeter that was being defended has quietly dissolved. In practice the model answers an uncomfortable question. If an employee account were compromised right now, how far would the attacker get? In a well-designed architecture, remarkably little.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

Damage contained during an incident

Segmentation and minimum rights turn a compromised account from a general catastrophe into a local event, with the attacker stuck inside one small perimeter.

Remote work without a trusted network

Employees work equally safely from the office, from home or while travelling, because security follows the identity and the device rather than the network socket.

Complete visibility over access

Every verified access is also a recorded one — who, from where, to which resource and when — exactly the trail that incident investigations and audits demand.

Frequently asked questions

Is Zero Trust a product I can buy?

No — it is an architecture and a strategy, implemented with instruments you probably already own in part: multi-factor authentication, identity management, network segmentation, conditional access policies, device health checks. Vendors sell components under the label, but the model emerges from how you combine them and from the policies you apply, which is why a purchase order on its own has never produced one.

Does this model make sense for a small company?

Yes, arguably more than it appears. The core principles — minimum rights, multi-factor authentication everywhere, no shared passwords, access granted per application instead of a network tunnel with the run of everything — apply perfectly well at ten employees, using tools already included in ordinary cloud subscriptions. A small company does not need a corporate programme; it needs the same rules applied consistently, which is mostly a matter of decision rather than of budget.

Where does the transition start?

With identity: inventory the accounts, remove orphaned ones and unnecessary administrator rights, and make multi-factor authentication mandatory. Then map the critical resources and restrict access to them by role. Only after that come network segmentation and advanced device policies. It is a staged journey rather than a weekend migration, and the first two steps alone remove a disproportionate share of the practical risk for most organisations.