A compromised Microsoft 365 account can give an attacker a surprisingly convincing starting point: familiar email threads, shared files, supplier contacts and access to cloud applications. A zero trust implementation is designed to limit what happens next. Rather than treating a successful sign-in or an office network as proof that someone should be trusted, it checks each request against the user, device, location, risk and resource involved.
For growing businesses, this is not about building an enterprise-sized security operation. It is about making sensible controls part of everyday IT, so a lost laptop, reused password or convincing phishing email does not become a business-wide incident.
What zero trust means in practice
Zero trust is often described as “never trust, always verify”. That is useful shorthand, but it can sound like every member of staff is being treated with suspicion. In practice, it means technology makes access decisions using evidence rather than assumptions.
A colleague signing in from a managed, encrypted laptop with multi-factor authentication may be granted access to the finance system they need. The same account attempting to download sensitive files from an unknown device in another country should face additional checks or be blocked. Access is also limited to what the person needs for their role, rather than granting broad permissions simply because they are on the company network.
This approach reflects how businesses now work. Staff use cloud platforms from home, customer sites and the office. Software is supplied by multiple providers. Traditional network boundaries have become less useful, and a firewall alone cannot protect every identity, application and device.
Why zero trust implementation matters to SMEs
Cyber security controls are sometimes presented as a choice between safety and productivity. That is the wrong framing. Well-planned controls can reduce avoidable disruption while making it easier for people to work securely from the right devices and applications.
The commercial case is straightforward. An account takeover can interrupt operations, expose personal or commercial information, trigger fraud and consume days of management time. Ransomware can take systems offline at the point a business most needs to serve customers. For legal, financial, engineering and manufacturing organisations, the consequences can include missed deadlines, lost intellectual property and damaged client confidence.
Zero trust reduces the blast radius. It will not stop every phishing attempt or eliminate every vulnerability. It does, however, make it harder for an attacker to move freely after an initial compromise. That distinction matters: early containment can be the difference between resetting one account and recovering an entire estate.
Start with the business, not the product
The strongest projects begin with a clear picture of how the organisation operates. Before selecting tools or changing policies, identify the systems that matter most, who needs them and what would happen if access was unavailable or misused.
For one business, the priority may be protecting financial approvals and payroll. For another, it may be production data, client matter files or remote access to design systems. The right controls depend on the data being handled, regulatory duties, existing technology and the way teams actually work.
This discovery stage should also expose common weak points: former employees retaining access, shared administrator accounts, unmanaged personal devices, excessive permissions, unsupported software or suppliers with broad remote access. These are practical issues that often produce more immediate risk reduction than a large technology purchase.
Build an accurate identity and access picture
Identity is the starting point because most modern attacks target people and their credentials. Every user should have an individual account, including administrators and external support providers. Shared accounts make auditing difficult and remove accountability when something goes wrong.
Multi-factor authentication should be enabled for email, cloud storage, remote access and any system holding valuable business information. Where possible, use phishing-resistant methods such as authenticator apps, passkeys or hardware security keys rather than relying solely on text messages. Multi-factor authentication is not a complete zero trust strategy, but it is one of the highest-value first steps.
Next, review permissions. Staff should receive the access required for their role, no more. Administrative rights deserve particular attention. Everyday work should be completed from a standard account, with a separate privileged account used only when an administrator task is necessary. It takes more discipline, but it greatly reduces the harm a compromised account can cause.
Bring devices into the security decision
A valid password does not make an unmanaged device safe. A zero trust model considers whether the device has current security updates, disk encryption, endpoint protection and an approved configuration before allowing access to sensitive services.
For company-owned laptops and mobiles, this normally means deploying device management. It provides visibility over the estate, supports remote configuration and allows access rules to distinguish between compliant and unknown devices. If a device is lost, the business can protect information without waiting for it to be returned.
Bring-your-own-device arrangements need a realistic policy. Some organisations can permit access only through protected mobile applications or browser sessions. Others may decide that sensitive data must remain on managed hardware. The correct answer depends on the role and risk, but the expectation should be clear before an incident tests it.
A phased zero trust implementation plan
Trying to change every access rule at once creates confusion and can disrupt work. A phased approach is more manageable, gives users time to adapt and lets the business correct issues before extending controls further.
Begin by establishing a baseline. Document critical applications, user groups, privileged accounts, devices, remote access routes and current security controls. Review recent incidents and support tickets too. Repeated password resets, unapproved file-sharing tools or remote working workarounds are useful signs that a process needs improvement.
The first rollout should focus on identity protections: multi-factor authentication, strong sign-in policies, removal of dormant accounts and a review of administrator access. Communicate the reason for the change in plain English. People are far more likely to cooperate when they understand that a prompt on their phone is protecting customer information and the continuity of the business, not adding bureaucracy for its own sake.
The next stage is device compliance. Enrol company devices, apply encryption and patching standards, deploy endpoint protection, and decide which applications can be accessed from unmanaged equipment. Test these policies with a small pilot group before applying them to the whole organisation. Senior staff and frequent travellers are often good pilot users because their feedback reveals real-world exceptions early.
Then apply conditional access to important cloud applications. Policies can require stronger authentication for high-risk sign-ins, restrict downloads from unmanaged devices, or block access from locations where the business has no legitimate activity. Start with monitoring where possible, review the results, then move to enforcement. A policy that blocks an important supplier portal at month end is technically secure but commercially unhelpful.
Finally, segment access between systems. This may mean separating guest Wi-Fi from business services, limiting who can reach servers, or ensuring a compromised workstation cannot communicate with every other device on the network. Network segmentation is especially valuable where older equipment, production systems or specialist applications cannot support modern security controls themselves.
Keep people involved and measure the result
Technology alone cannot create a secure working culture. Staff need short, relevant guidance on recognising suspicious sign-in prompts, reporting potential phishing messages and handling business information appropriately. Training should reflect real risks, not rely on annual box-ticking exercises.
The project also needs ownership after deployment. Review access when people change roles, leave the business or suppliers finish work. Monitor failed sign-ins, new administrator accounts, unusual data transfers and devices falling out of compliance. Backups remain essential as well: zero trust limits access, while tested backups support recovery when prevention fails.
Useful measures are practical rather than performative. Track the percentage of accounts protected by multi-factor authentication, the number of unmanaged devices accessing business systems, privileged accounts reviewed, patch compliance and the time taken to remove leavers’ access. These figures help directors see progress and identify where further investment is justified.
A managed IT partner can bring structure to this work, particularly where internal teams are already stretched. The value is not simply deploying licences. It is understanding the business, setting sensible policies, supporting users through change and reviewing the controls as systems and working practices evolve.
Zero trust should make the business more deliberate about access, not more difficult to work for. Start with the identities, devices and applications that matter most, make each improvement usable, and keep reviewing the evidence. That is how stronger security becomes a dependable part of day-to-day operations.
The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.