Executive technology leadership for growing and regulated organizations

Cybersecurity • Identity • Access Governance

Zero Trust Without the Buzzwords

Zero Trust does not require redesigning your entire technology environment at once. A practical program starts by strengthening identity, reducing unnecessary trust and introducing better access decisions in deliberate stages.

By Teddy Cerra, MBA Executive Technology Advisor August 23, 2026

Zero Trust is often presented as a major transformation program, a product category or an architectural destination. In practice, the useful idea is much simpler: do not automatically trust a user, device, application or network location simply because it is already inside the environment.

Instead, access decisions should be based on identity, device condition, risk, sensitivity and the minimum level of access required for the task. Organizations can move toward that model in deliberate stages without attempting to redesign the entire technology environment at once.

What does Zero Trust actually mean?

Zero Trust is a security model built around continuous verification and least privilege. It assumes that identities, endpoints, applications and networks can all be compromised, so access should be evaluated using current context rather than permanent trust.

The practical objective is not to challenge every user every minute. The objective is to make stronger decisions about who is requesting access, from what device, under what conditions and to which resource.

Zero Trust is not a single product

Buying an identity platform, endpoint product or network security service does not by itself create Zero Trust. The model comes from how identity, devices, access policies, applications, data and monitoring work together.

Why organizations struggle with Zero Trust

Many organizations already own technology capable of supporting stronger access controls. The difficulty is usually operational. Policies have grown over time, legacy authentication remains enabled, administrative accounts are inconsistent, devices are not uniformly managed and business applications have different requirements.

01

Identity is inconsistent

MFA may exist, but enrollment, enforcement, exceptions and administrator protections vary between users or applications.

02

Devices are not equally trusted

Managed corporate devices, personal devices and unknown endpoints may all receive similar access despite very different levels of control.

03

Legacy access remains

Older protocols, service accounts or applications can bypass the stronger authentication model used by modern systems.

04

Privilege accumulates

Administrative access often grows over time without regular review, separation of duties or clear ownership.

05

Policies are deployed too quickly

Security controls can create business disruption when dependencies, emergency access and rollback requirements are not understood first.

06

Applications differ

Cloud services, legacy applications and third-party platforms may support different authentication and access capabilities.

A practical Zero Trust roadmap

The strongest approach is usually staged. Build a reliable identity and access foundation first, then progressively use stronger device, application and data signals.

01

Inventory

Identify users, administrators, devices, applications, authentication methods, external access and critical business dependencies.

02

Strengthen Identity

Enforce MFA appropriately, reduce legacy authentication, protect administrators and establish emergency access.

03

Add Context

Use device compliance, sign-in risk, location and application sensitivity to improve access decisions.

04

Govern

Review exceptions, privileged access, policy results and changes on an ongoing basis.

Start with identity before adding complexity

For many organizations, identity represents the highest-value starting point. Attackers frequently target credentials, sessions and administrative identities because successful identity compromise can provide access to email, cloud data, applications and administrative functions.

A practical identity-first program normally includes consistent MFA, Conditional Access or equivalent policy controls, administrator separation, emergency access, legacy authentication reduction and a documented account lifecycle process.

Multi-factor authentication

MFA should be treated as an enforced control rather than simply a registration statistic. Leadership should know where MFA is required, which users or applications are exempt and why those exceptions exist.

Conditional access

Conditional access policies can use information such as user identity, device status, application, location and risk to determine whether access should be allowed, blocked or challenged.

Privileged access

Administrative identities deserve stronger controls than ordinary user accounts. Standing privilege should be minimized, administrative roles should be reviewed and emergency access should be deliberately maintained.

Bring devices and applications into the decision

Once identity is reliable, organizations can make access decisions using device and application context. A managed, encrypted and compliant corporate device does not represent the same risk as an unknown personal endpoint.

This does not mean every organization must immediately block all unmanaged devices. The appropriate policy depends on the sensitivity of the data, the user population, operational requirements and the organization’s ability to manage devices consistently.

Control should follow risk

High-value administrative portals, financial systems and sensitive data may justify stronger access requirements than lower-risk applications. Zero Trust works best when controls are proportional to business consequence.

Deploy stronger controls without breaking the business

One of the most important parts of a Zero Trust program is change control. Restrictive policies should not be deployed broadly without understanding who and what will be affected.

  • Use report-only or simulation modes when the platform supports them.
  • Begin with pilot groups before broad enforcement.
  • Document exclusions and the business reason for each exception.
  • Establish and test emergency access before restrictive identity changes.
  • Verify application and service-account dependencies.
  • Define rollback procedures before policy enforcement.

How should leadership measure Zero Trust progress?

Progress should be measured through evidence and reduced exposure rather than the number of security products purchased.

AreaUseful EvidenceExecutive Question
IdentityMFA enforcement, legacy authentication status, risky sign-in controls.Can a stolen password alone still provide meaningful access?
PrivilegeAdministrative role inventory, separate admin identities, access reviews.Who has elevated access and why?
DevicesEnrollment, compliance, encryption and endpoint protection status.Do we know the security condition of devices accessing sensitive systems?
ApplicationsApplication inventory, SSO coverage, access policy and service-account review.Which applications can bypass the primary identity controls?
GovernanceException register, policy review, change records and ownership.Who is accountable for maintaining these controls?

What does a mature Zero Trust program look like?

A mature program does not necessarily have the most complicated policy set. It has clear ownership, strong identity controls, known devices and applications, limited privilege, documented exceptions, measurable evidence and disciplined change management.

The goal is to reduce implicit trust while keeping the environment usable. Security should become more deliberate and predictable, not more confusing.

Zero Trust FAQ

Common questions about Zero Trust security.

Zero Trust is a security operating model, not a single product or one-time project.

Do we need to replace our firewall or network to implement Zero Trust?

Not necessarily. Many organizations can make meaningful progress by improving identity, MFA, administrative access, device management and application controls before making major network changes.

Is MFA the same as Zero Trust?

No. MFA is an important control, but Zero Trust also considers privilege, device condition, applications, data, risk and ongoing governance.

Can Microsoft 365 support a Zero Trust approach?

Yes. Microsoft Entra ID, Conditional Access, Intune, Defender and Microsoft 365 governance capabilities can support major parts of an identity- and device-focused Zero Trust program when configured and governed appropriately.

Should we block all personal devices?

Not automatically. Access policy should reflect the sensitivity of the resource, business requirements and the organization’s ability to manage devices. Some environments may require strict blocking while others may use limited or browser-only access.

How long does a Zero Trust implementation take?

There is no universal timeline. The work is better treated as a staged security program. Identity and administrative controls can often be improved first, while device, application and data governance mature over time.

How do we know whether our Zero Trust controls are working?

Use evidence such as MFA enforcement, legacy authentication status, privileged role reviews, device compliance, policy results, exception records and validated access tests rather than relying only on product licensing.

About the Author

Teddy Cerra, MBA

Teddy Cerra is the Founder and Executive Technology Advisor at CyberPoint IT. His background includes CIO and CTO leadership, cybersecurity, Microsoft 365, CRM and infrastructure, along with service as a Special Agent with the United States Secret Service. He advises organizations on technology strategy, risk, governance and executive decision making.

About CyberPoint IT

Cybersecurity & Identity Governance

Build stronger access controls without creating unnecessary complexity.

CyberPoint IT can help evaluate identity, Microsoft 365, device and access controls and develop a practical security roadmap around your environment.