CoreTech
Cybersecurity

Zero Trust in practice: a 90-day plan | CoreTech

Zero Trust is not a product. It starts with identity, critical resources, device health, least privilege and better visibility.

CoreTech tim · 7 min

Cybersecurity team monitors user, device and system access through orange trust boundaries
KEY TAKEAWAYS

What to remember.

  • Zero Trust is a continuous-verification strategy, not one tool.
  • Focus the first 90 days on identity and the most critical access flow.
  • Measure reduced risky access and detection quality, not the number of purchased licences.

The management answer

Zero Trust starts from the premise that network location is not sufficient evidence of trust. Every access request is evaluated through identity, device, resource, context and risk. This should not create constant friction for employees. It should make controls more consistent in the background.

The goal of the first 90 days is not to finish Zero Trust. It is to remove major blind spots, protect one critical access flow and establish the order of subsequent work.

Days 1 to 30: visibility and identity

Inventory privileged accounts, external collaborators, service accounts and applications without modern authentication. Identify where MFA is missing, accounts are shared or rights remain active after role changes and departures.

Select several critical resources, such as administrative access, the finance system or remote infrastructure access. Record who connects, from which devices, how access is approved and which logs are available.

Days 31 to 60: least privilege and device health

Introduce or strengthen MFA for privileged and remote access. Separate administrative accounts from everyday accounts. Replace permanent privileges with time-bound, approved access where possible.

Then include device health in access decisions. Current patching, encryption, endpoint protection and ownership should influence whether access is allowed, restricted or challenged.

Days 61 to 90: pilot and measurement

Run a pilot on one business-important but manageable flow. Monitor failed logins, risky sessions, exceptions, requests for additional rights and user impact. Rules that cause widespread workarounds are not well designed.

The pilot should produce validated policies, a list of owned and time-limited exceptions, improved logging and a plan for the next resource.

What to measure

  • Privileged accounts protected by strong MFA
  • Old, shared and inactive accounts
  • Time required to revoke access after a role change
  • Managed and compliant devices
  • Justified exceptions and their expiry
  • Quality of logs required for incident investigation

The CoreTech approach

We introduce Zero Trust through business scenarios, not product catalogues. We select the access flow carrying the highest risk, then connect identity, device, network, application and data into a measurable control path.

FAQ / AEO

Common questions

Does Zero Trust mean trusting nobody?

No. It means trust is not assumed from location or a previous login. Access is evaluated according to context and risk.

Must we replace all existing tools?

No. Work often begins by improving identity, MFA, device, privilege and logging configuration in the current environment.

Where should we start?

Start with privileged accounts and one critical access flow that is clear enough for a controlled, measurable pilot.

Sources and further reading

  1. NIST SP 800-207 Zero Trust Architecture ↗
  2. Microsoft Zero Trust Guidance Center ↗