Zero Trust
In short
Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
What is zero trust?
Traditional network security works like a castle with a moat: everything inside the company network is trusted, and a firewall protects the edge. Zero trust drops that assumption and follows the principle never trust, always verify. Every request to an application or service must prove who is making it and whether it should be allowed, whether it comes from the office, a home network, or another server in the same data center.
In practice, zero trust combines several controls: strong authentication for users, ideally with phishing-resistant MFA; checks on device health, such as whether the operating system is up to date; fine-grained authorization with least privilege; encryption of all traffic, including between internal services with mutual TLS; and continuous monitoring. Access decisions are made per request and per resource, rather than once when someone connects to a VPN.
Think of a modern office building where your badge must be scanned at every door, not just the front entrance, and the system also checks the time and which floor you work on. If an attacker steals one laptop or breaks into one server, they cannot freely move sideways through the network, an attack technique called lateral movement.
Zero trust is a strategy and architecture, described in guidance such as NIST SP 800-207, not a single product you can buy, even though many products carry the label. It also does not mean distrusting employees; it means not treating network location as proof of trust. Organizations usually adopt it gradually, starting with strong identity and MFA, then segmenting networks and protecting the most sensitive applications first.
Key takeaways
- Zero trust assumes no user, device, or network is trusted by default.
- Every request is authenticated, authorized, and encrypted.
- Being inside the corporate network grants no automatic access.
- Least privilege and segmentation limit lateral movement after a breach.
- Zero trust is an architecture and strategy, not a single product.
Example
// Every request is verified, even from "internal" services on the same network
// (verifyServiceToken and policy are defined elsewhere)
app.use(async (req, res, next) => {
// 1. Who is calling? Check a signed, short-lived token, not the source IP
const caller = await verifyServiceToken(req.headers.authorization);
if (!caller) return res.sendStatus(401);
// 2. May this caller perform this action on this resource?
if (!policy.allows(caller, req.method, req.path)) {
return res.sendStatus(403);
}
req.caller = caller;
next();
});Readers ask
What does never trust, always verify mean?
It is the core idea of zero trust: no request is trusted just because of where it comes from. Each one must be authenticated and authorized, even if it originates inside the company network.
Does zero trust replace VPNs?
Often, yes. Zero trust access tools give users access to specific applications after verifying their identity and device health, instead of placing them on the whole internal network the way a traditional VPN does.
Is zero trust a product?
No. Zero trust is a security model that combines identity, device checks, least-privilege access, encryption, and monitoring. Vendors sell tools that help implement it, but no single product makes an organization zero trust.
See also
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- MicroservicesSoftware Architecture, p. 27Microservices are an architectural style where an application is split into small, independently deployable services that communicate over a network.
Spotted a mistake or something missing on this page?Suggest an edit