Security

Zero Trust: A Practical Guide for Your Infrastructure

The classic perimeter is dead: identity is the new perimeter. We explain the NIST SP 800-207 principles, the pillars of a Zero Trust architecture and a realistic phased roadmap for SMEs and mid-sized companies.

business EasyDataHost calendar_today July 29, 2026 schedule 9 min read

For decades, corporate security has been built like a castle with a moat: a strong perimeter (firewall and VPN) and an internal network where, once inside, almost everything was allowed. That model no longer works. With remote work, SaaS, the cloud and attacks based on stolen credentials, "inside" and "outside" no longer exist. Zero Trust proposes the opposite: trust nothing and no one by default — "never trust, always verify" — and verify every access explicitly and continuously.

Zero Trust is neither a marketing fad nor a product with a list price: it is an architecture model formalised by NIST in publication SP 800-207 and adopted as a reference by governments and companies worldwide. In this article we bring it down to earth: which principles define it, what its pillars are and, above all, how an SME or mid-sized company can implement it in phases without rebuilding its entire infrastructure at once.

This article focuses on the strategy and the model. A detailed comparison between the traditional VPN and ZTNA solutions as products will be covered in a dedicated article later on.

The End of the Classic Perimeter: from Castle-and-Moat to Identity

The perimeter model starts from a simple premise: everything inside the corporate network is trusted, and everything outside is suspicious. The firewall acts as the wall and the VPN as the drawbridge: whoever connects via VPN "enters the castle" and, from there, usually has access to a large part of the internal network. The problem is that a single pair of stolen credentials turns the attacker into a trusted internal user, free to move laterally between servers, file shares and databases.

On top of that, the perimeter no longer matches the reality of the business: employees work from home, applications live in SaaS and in the cloud, and data is spread across the datacenter, laptops and third-party services. When most of your resources and users are outside the office, defending only the edge of the network means defending a map that no longer exists. Attackers know it: today it is far more common to log in with compromised credentials than to "hack" the firewall.

The logical consequence is that identity becomes the new perimeter: the question is no longer "which network are you connecting from?", but "who are you, on which device, with what level of privilege, and which specific resource do you need to access right now?". That change of question is the essence of Zero Trust.

The Three Principles of NIST SP 800-207

The canonical reference for the model is NIST SP 800-207 "Zero Trust Architecture", which defines the zero trust architecture around three operational principles:

  • check_circle Explicit, continuous verification: every access request is authenticated and authorised at the time it happens, evaluating identity, device, location and context. Trust is not inherited from previous sessions or from the source network, and it can be revoked if the context changes.
  • check_circle Least privilege: every user, service or device gets exactly the permissions it needs for its task, for as long as it needs them. No more domain admin accounts for routine tasks and no more "just in case" access.
  • check_circle Assume breach: you design as if the attacker is already inside. The goal is to limit their blast radius with segmentation, encryption and detection, so that compromising one machine does not mean compromising the company.

Golden rule:

Treat your internal network as if it were the Internet. If an access would not be acceptable coming from outside without strong authentication, it should not be acceptable coming from inside either.

The Five Pillars of a Zero Trust Architecture

To move from principles to practice, the architecture is usually organised into five pillars that cover the whole path between the user and the data:

  • check_circle Identity: multi-factor authentication (MFA) on every access, conditional access policies based on risk (device, location, time) and privileged access management (PAM) for administrative accounts. It is the central pillar: without strong identity there is no Zero Trust.
  • check_circle Devices: a complete inventory of the machines accessing your resources and an assessment of their security posture (patches up to date, EDR active, disk encrypted). An unmanaged or outdated device gets reduced access or none at all.
  • check_circle Network: microsegmentation so that each workload only talks to whom it should, and encryption of internal traffic (the "east-west" traffic between servers), not only traffic to the Internet. Internal TLS encryption relies on good certificate management, as we explain in our SSL/TLS certificates guide for servers.
  • check_circle Applications and data: classification of information by sensitivity, role-based access to data and DLP controls (data loss prevention) for critical information. The data is what you ultimately protect.
  • check_circle Visibility and analytics: centralised authentication, access and network logs, correlated in a SIEM with alerting. Continuous verification is only possible if you record and analyse what happens; without telemetry, the other pillars run blind.

Comparison Table: Perimeter Model vs Zero Trust

The following table summarises the change of mindset between the castle-and-moat model and a zero trust architecture:

Criterion Perimeter model Zero Trust
Trust premise Internal is trusted Nothing is trusted by default
Perimeter The network edge (firewall) Identity and each resource
Verification Once, at the entrance Explicit and continuous, per access
Access granted Broad: to the internal network Minimal: to the specific resource
Lateral movement Easy once inside Limited by microsegmentation
Internal encryption Optional (the LAN is trusted) By default, east-west included
Scope of a breach Potentially the whole network Contained to the compromised segment
Monitoring Focused on the perimeter Continuous telemetry of every access

A Phased Roadmap for an SME or Mid-Sized Company

Zero Trust is not implemented with a "big bang": you prioritise by risk and cost. This three-phase roadmap is realistic for an SME or mid-sized company, and each phase delivers value on its own. Before starting, it helps to know where you stand: our cybersecurity audit checklist is a good starting point for the initial assessment.

Phase 1 — Identity and MFA. It is the phase with the best cost/benefit ratio and does not require touching the network:

  • check_circle Enable MFA on every external and administrative access: email, VPN, management panels, remote desktops and server consoles.
  • check_circle Build an inventory of accounts and remove orphaned ones: former employees, old vendors and shared generic accounts.
  • check_circle Apply least privilege: nobody works day-to-day with an administrator account, and privileged accounts are used only for administration tasks.

Phase 2 — Network segmentation and administrative access. Reduce the blast radius of an attacker who already has a foothold:

  • check_circle Split the network into segments by function: users, servers, management and backup, with firewall rules between them.
  • check_circle Channel administration through a bastion or jump host: no exposed RDP or SSH, and every administrative access logged.
  • check_circle Use separate credentials for backup, outside the domain: if ransomware compromises Active Directory, it must not be able to reach the backup repositories.

Phase 3 — Microsegmentation and continuous monitoring. This is the maturity phase: communication policies per workload (not just per VLAN), encryption of east-west traffic between services, centralised logs in a SIEM with alerting, and periodic privilege reviews. At this point verification stops being a one-off control and becomes a continuous process.

Zero Trust Is Not a Product: It Is an Architecture

Let's say it plainly: there is no "Zero Trust" box you can buy, plug in and be done with. When a vendor sells "Zero Trust" as a single product, they are selling one piece of the puzzle: an identity provider, an EDR, a microsegmentation solution or an access platform. All of them can be legitimate pieces, but none of them is the complete architecture.

What defines Zero Trust is how those pieces are combined under a common set of principles: explicit verification, least privilege and assumed breach, applied to identities, devices, network, data and telemetry. That requires strategy, phases and governance: deciding what to protect first, which technology fits each pillar and who reviews the policies as the company changes. If your IT team cannot cover everything, leaning on managed services lets you advance along the roadmap without growing headcount.

How Zero Trust Applies to Your Hosting and Your Datacenter

The principles above do not stop at the office: they apply equally — or more — to the servers that run your business. At EasyDataHost we design the security solutions of our infrastructure following this same logic:

  • arrow_right Access to dedicated servers via VPN or bastion host: administration ports (SSH, RDP, IPMI) are not exposed to the Internet; they are reached through a controlled, authenticated and logged entry point.
  • arrow_right Backup credentials outside the domain: backup repositories use accounts independent from the customer's Active Directory, so that a domain compromise cannot reach the last line of defence.
  • arrow_right Segmented private networks: each customer's servers communicate over isolated private networks, separating service, management and backup traffic.
  • arrow_right Operational least privilege: named administrative accounts with scoped permissions, both in our own systems and in the environments we manage for customers.

The underlying idea is the same in the datacenter as in the office: no access is granted for being "on the right network", but for proving who you are and needing that specific resource.

Frequently Asked Questions

Is Zero Trust a product you can buy?

No. It is an architecture model defined by NIST in SP 800-207. Vendors offer pieces that fit into it (MFA, identity management, microsegmentation, SIEM), but implementing it requires strategy, phases and governance, not a single purchase.

Where should an SME start with Zero Trust?

With identity: MFA on every external and administrative access, an inventory and clean-up of accounts, and least privilege. It is the measure with the best cost/benefit ratio and does not require redesigning the network. Then comes segmentation with controlled administrative access; finally, microsegmentation and continuous monitoring.

Does Zero Trust mean removing the VPN and the firewall?

No. It means no longer using network location as the criterion for trust. The VPN, the bastion host and the firewall remain useful pieces within an architecture where every access is verified explicitly and breach is assumed.

Conclusion

Zero Trust is neither a specific technology nor a passing trend: it is the architectural answer to a world where the network perimeter no longer matches the company. The key takeaways:

  • arrow_right The classic perimeter is dead: with remote work, SaaS and cloud, identity is the new perimeter and every access must be verified on its own merits.
  • arrow_right Three principles (NIST SP 800-207): explicit and continuous verification, least privilege and assume breach. Everything else follows from there.
  • arrow_right Implement it in phases: identity and MFA first, then segmentation and administrative access (bastion host, separate backup credentials), and finally microsegmentation and continuous monitoring.
  • arrow_right It is an architecture, not a product: vendors provide pieces; the strategy, the phases and the governance come from your company.

If you want to apply these principles to your infrastructure — bastion-based access, segmented private networks, backup outside the domain — contact our team: we will review your scenario and propose a roadmap with no obligation.

Zero Trust Cybersecurity NIST SP 800-207 MFA Microsegmentation Security
security

Apply Zero Trust to your infrastructure

EasyDataHost: dedicated servers with VPN and bastion access, segmented private networks and backup outside the domain. Infrastructure in Spain, 24/7 support.