Zero trust for a business without a security team
Zero trust sounds like an enterprise programme. For a 30-person firm it is six controls, most already in your Microsoft 365 licence. The practical version.
Zero trust is one of those phrases that arrived from large enterprises with a consultancy attached. Strip the programme away and the idea is simple: never assume something is safe because of where it is. Being on the office Wi-Fi, or on a company laptop, or inside the VPN, proves nothing. Every access is checked, every time, against who is asking, from what device, for what.
For a growing business that is not a project. It is a handful of controls, applied properly and kept on.
The six controls
- Identity is the perimeter. One identity provider (Microsoft Entra ID or Google Workspace), every application signing in through it, and no shared logins. If there is a password on a sticky note, it is the perimeter.
- Multi-factor authentication on everything, with phishing resistance where it counts. Passkeys or hardware keys for administrators and finance; app-based MFA for everyone else. SMS codes are better than nothing and worse than everything else.
- Conditional access. Sign-in rules: block legacy protocols, require a compliant device for sensitive apps, challenge unusual locations, cut sessions when risk is detected. This is the control that stops a stolen password working.
- Managed, encrypted, healthy devices. Every laptop enrolled, encrypted, patched and running endpoint detection. A device that is not managed does not get to sensitive data. Personal phones get managed apps, not the whole device.
- Least privilege, granted for the task. Admin rights when needed, for as long as needed, then removed. Leavers gone the same day. Contractors with an expiry date.
- Assume breach: log, monitor, isolate. Sign-in logs, endpoint alerts and mail-rule changes watched; a device that misbehaves isolated in minutes; backups the attacker cannot reach.
What it is not
Zero trust is not a product, a VPN replacement or a network diagram. It is not finished when the project ends, because the whole idea is continuous verification. And it is not an enterprise luxury: the attacks it stops, a phished password, a reused credential, a leaver's account, are precisely the ones that hit small firms.
Where AI fits
Every AI assistant you deploy inherits this. Retrieval is scoped by identity; actions are gated by conditional access; logs are how you prove what happened. A firm with zero-trust basics in place can adopt AI with controls. A firm without them is giving a very fast search engine to whoever gets in.
Start with the six. Measure them: MFA coverage, device compliance, privileged accounts, leaver removal time. Publish the numbers internally. That is a zero-trust programme sized for a business that has better things to do.
Want help with this in your business?
Talk to Foundry — we’ll talk through your situation, no obligation.