What to remember.
- Zero Trust is a continuous-verification strategy, not one tool.
- Focus the first 90 days on identity and the most critical access flow.
- Measure reduced risky access and detection quality, not the number of purchased licences.
The management answer
Zero Trust starts from the premise that network location is not sufficient evidence of trust. Every access request is evaluated through identity, device, resource, context and risk. This should not create constant friction for employees. It should make controls more consistent in the background.
The goal of the first 90 days is not to finish Zero Trust. It is to remove major blind spots, protect one critical access flow and establish the order of subsequent work.
Days 1 to 30: visibility and identity
Inventory privileged accounts, external collaborators, service accounts and applications without modern authentication. Identify where MFA is missing, accounts are shared or rights remain active after role changes and departures.
Select several critical resources, such as administrative access, the finance system or remote infrastructure access. Record who connects, from which devices, how access is approved and which logs are available.
Days 31 to 60: least privilege and device health
Introduce or strengthen MFA for privileged and remote access. Separate administrative accounts from everyday accounts. Replace permanent privileges with time-bound, approved access where possible.
Then include device health in access decisions. Current patching, encryption, endpoint protection and ownership should influence whether access is allowed, restricted or challenged.
Days 61 to 90: pilot and measurement
Run a pilot on one business-important but manageable flow. Monitor failed logins, risky sessions, exceptions, requests for additional rights and user impact. Rules that cause widespread workarounds are not well designed.
The pilot should produce validated policies, a list of owned and time-limited exceptions, improved logging and a plan for the next resource.
What to measure
- Privileged accounts protected by strong MFA
- Old, shared and inactive accounts
- Time required to revoke access after a role change
- Managed and compliant devices
- Justified exceptions and their expiry
- Quality of logs required for incident investigation
The CoreTech approach
We introduce Zero Trust through business scenarios, not product catalogues. We select the access flow carrying the highest risk, then connect identity, device, network, application and data into a measurable control path.
Common questions
Does Zero Trust mean trusting nobody?
No. It means trust is not assumed from location or a previous login. Access is evaluated according to context and risk.
Must we replace all existing tools?
No. Work often begins by improving identity, MFA, device, privilege and logging configuration in the current environment.
Where should we start?
Start with privileged accounts and one critical access flow that is clear enough for a controlled, measurable pilot.
