Skip to main content
foundry

Zero trust for a business without a security team

Zero trust sounds like an enterprise programme. For a 30-person firm it is six controls, most already in your Microsoft 365 licence. The practical version.

Foundry Team

Zero trust is one of those phrases that arrived from large enterprises with a consultancy attached. Strip the programme away and the idea is simple: never assume something is safe because of where it is. Being on the office Wi-Fi, or on a company laptop, or inside the VPN, proves nothing. Every access is checked, every time, against who is asking, from what device, for what.

For a growing business that is not a project. It is a handful of controls, applied properly and kept on.

The six controls

  1. Identity is the perimeter. One identity provider (Microsoft Entra ID or Google Workspace), every application signing in through it, and no shared logins. If there is a password on a sticky note, it is the perimeter.
  2. Multi-factor authentication on everything, with phishing resistance where it counts. Passkeys or hardware keys for administrators and finance; app-based MFA for everyone else. SMS codes are better than nothing and worse than everything else.
  3. Conditional access. Sign-in rules: block legacy protocols, require a compliant device for sensitive apps, challenge unusual locations, cut sessions when risk is detected. This is the control that stops a stolen password working.
  4. Managed, encrypted, healthy devices. Every laptop enrolled, encrypted, patched and running endpoint detection. A device that is not managed does not get to sensitive data. Personal phones get managed apps, not the whole device.
  5. Least privilege, granted for the task. Admin rights when needed, for as long as needed, then removed. Leavers gone the same day. Contractors with an expiry date.
  6. Assume breach: log, monitor, isolate. Sign-in logs, endpoint alerts and mail-rule changes watched; a device that misbehaves isolated in minutes; backups the attacker cannot reach.

What it is not

Zero trust is not a product, a VPN replacement or a network diagram. It is not finished when the project ends, because the whole idea is continuous verification. And it is not an enterprise luxury: the attacks it stops, a phished password, a reused credential, a leaver's account, are precisely the ones that hit small firms.

Where AI fits

Every AI assistant you deploy inherits this. Retrieval is scoped by identity; actions are gated by conditional access; logs are how you prove what happened. A firm with zero-trust basics in place can adopt AI with controls. A firm without them is giving a very fast search engine to whoever gets in.

Start with the six. Measure them: MFA coverage, device compliance, privileged accounts, leaver removal time. Publish the numbers internally. That is a zero-trust programme sized for a business that has better things to do.

Want help with this in your business?

Talk to Foundry — we’ll talk through your situation, no obligation.

Keep reading

Before you switch on Copilot: the oversharing problem

Copilot respects the permissions you already have, which is good news and bad news. How to find what is overshared in your tenant before an assistant does.
Foundry Team

What a cyber security assessment actually looks at

A good security assessment isn't a mystery survey. Here's what we examine, what we measure it against, and what you get at the end.
Foundry Team

How AI actually automates a workflow, and where it shouldn't

Agentic AI is mostly plumbing: retrieval, business rules, approvals and an audit trail, with a model doing one step. Here is what a real AI workflow looks like.
Foundry Team

Remote-first / UK-wide / one team

Ready for a technology team that can build?

Thirty minutes with an engineer, not a salesperson: what you run today, what’s at risk, what should be automated, and what we’d build or wouldn’t.

30 min call / no pitch / no obligation