State of IAM Survey

Free Demo Contact
What is Zero Trust? Reduce Cyber Risk with IAM

What is Zero Trust? Reduce Cyber Risk with IAM

By: KaHo Man 8 June 2026

Zero Trust is a security model in which no user, device, or system is trusted by default. Every access request must be verified, authorised based on context, and monitored continuously. This applies to communication between users and systems, and between systems themselves.

Wat is Zero Trust?How Zero Trust Differs from Traditional Security

Traditional on-premises security models focused on controlling access at the network boundary. Once inside, users were granted implicit trust and were free to move laterally across connected systems. A compromised email account, for example, could serve as an entry point to other systems within the same network.

Perimeter Security

Zero Trust

Trust model

Implicit trust once inside the network

No implicit trust; every request verified

Access control

Network-level access granted on login

Granular access based on identity, role, and context

Lateral movement

Possible once perimeter is breached

Contained; each system requires separate verification

Cloud suitability

Limited; assumes a defined network boundary

Designed for cloud, hybrid, and distributed environments

Monitoring

Perimeter-focused

Continuous across all users, devices, and sessions

In cloud environments, the network boundary no longer exists. Applications and data are hosted across multiple platforms, accessible over the internet from any location and device, and systems exchange data autonomously. Perimeter security has no meaningful boundary to defend in this context.

Zero Trust addresses this by treating every interaction as untrusted until verified. Users and systems receive only the permissions required for their specific tasks, a principle known as the Principle of Least Privilege.

Why Zero Trust Matters Now

Cloud adoption has expanded the attack surface that organisations must defend. 84% of UK businesses have adopted a cloud-smart approach, prioritising flexibility across data centres, public clouds, and edge environments, according to Nutanix's Enterprise Cloud Index. Hybrid multicloud deployments are forecast to grow significantly over the next three years, increasing the complexity of the environments that security teams must protect.

Waarom Zero Trust nu relevant isTraditional network security is insufficient for this scale and complexity. The UK Government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the preceding 12 months. Phishing was responsible for 93% of successful breaches against UK businesses.

Most cyberattacks succeed through a sequence of steps, commonly described as a kill chain. An initial compromise, such as a stolen credential obtained through phishing, becomes a staging point for further activity: accessing adjacent systems, exfiltrating data, or deploying ransomware across the network. Continuous verification at every point in that chain is precisely what Zero Trust is designed to prevent.

Zero Trust Across Key Sectors

Zero Trust is applicable across every industry. The underlying principle is consistent: verify identity, device, and context for every access request. The specific compliance drivers and operational challenges vary by sector.

Waarom Zero Trust belangrijk is in elke sector: zorg, onderwijs en overheidHealthcare

Healthcare organisations handle sensitive patient data that must be immediately available to clinical staff while being protected rigorously against misuse. The workforce is complex: permanent staff, agency personnel, contractors, and staff from partner organisations all require access, often across multiple NHS trusts and care providers.

Zero Trust addresses this by verifying every access attempt based on identity, role, and current context. Clinicians receive access only to the data they need at that moment for their current patient. Detailed logging and auditing support compliance with the NHS Data Security and Protection (DSP) Toolkit, UK GDPR, and ISO 27001.

Public Sector

Public sector organisations process large volumes of sensitive citizen and business data, with access distributed across central government departments, local authorities, executive agencies, and external partners. This fragmented access landscape introduces risks including unauthorised access, outdated privileges, and insufficient visibility into who is accessing which data and for what purpose.

Zero Trust mitigates these risks by requiring continuous verification regardless of where a user is located or which organisation they belong to. It also supports compliance and audit requirements under UK GDPR, the UK NIS Regulations 2018, and the forthcoming Cyber Security and Resilience Bill.

Education

Educational institutions are highly dynamic environments. Students progress through academic years, programmes, and qualifications. Teaching staff change roles, combine functions, and are supplemented by visiting lecturers and supply teachers. This pace of change increases the risk of stale accounts, excessive authorisations, and uncontrolled access to personal data and research records.

Zero Trust reduces this risk by replacing network-based implicit trust with continuous verification of every user, session, and device. This is particularly relevant where faculties and departments operate with significant autonomy and frequently adopt new cloud applications with limited central oversight.

Key Benefits of a Zero Trust Approach

De belangrijkste voordelen van Zero TrustA Zero Trust strategy delivers measurable improvements across security, compliance, and operational resilience.

  • Stronger authentication and access security. Multi-Factor Authentication (MFA), passkeys, and digital certificates are combined with contextual signals such as device type, network, and user behaviour patterns. Access becomes more secure without compromising usability for legitimate users.

  • More adaptive security monitoring. When all traffic, access events, and user behaviour are continuously monitored and analysed, anomalies are detected earlier. A suspicious action mid-session can trigger an additional verification step or interrupt the activity entirely before damage is done.

  • Reduced blast radius from incidents. When users hold access only to the data and functionality they require, the damage from a compromised account is contained. Exfiltrating large volumes of data unnoticed becomes significantly harder, and ransomware cannot propagate freely across adjacent systems.

  • Stronger identity governance. Every access attempt and policy decision is recorded, creating a continuous audit trail. This supports compliance with ISO 27001, UK GDPR, and the UK NIS Regulations, and enables ongoing improvement of your security posture based on live data.

Implementing Zero Trust: IAM Considerations

Zero Trust is a security strategy, not a single product. Its implementation spans multiple disciplines. From an Identity and Access Management perspective, the following steps provide a structured starting point.

  1. Manage the full identity lifecycle. Zero Trust requires that users hold correct permissions at all times, based on their current role. User provisioning automates this lifecycle from onboarding through role changes to offboarding, ensuring access rights remain accurate throughout employment.

  2. Apply Least Privilege when defining business rules. Role mining supports the construction of a role model in which every user receives exactly the permissions their role requires. This prevents privilege accumulation as people change roles over time.

  3. Implement Segregation of Duties (SoD). At an organisational level, SoD prevents individuals from holding excessive permissions or lacking appropriate oversight of their activities. Toxic combination management prevents conflicting access rights from being issued within your role model.

  4. Manage exceptions carefully. Not all access rights can be granted automatically through business rules. Service automation ensures that individual access requests are handled consistently, covering the request, approval workflow, and periodic recertification of those permissions.

  5. Clean up your access landscape regularly. Even well-managed access control accumulates redundant accounts and permissions over time, whether from legacy configurations or forgotten test accounts. Reconciliation supports a clean, auditable access landscape as a continuous practice rather than a one-time exercise.

Why is Zero Trust important for organisations?

Zero Trust helps organisations better protect themselves against modern cyber threats by continuously checking every access attempt and interaction within the IT environment. This prevents attackers from moving around a network unnoticed or abusing excessively granted access rights.

How does Zero Trust contribute to compliance?

Zero Trust helps organisations meet compliance requirements more effectively because access to systems and data is continuously checked and based on least privilege. It is demonstrably recorded who has access to which information and for what reason, which makes auditing and reporting simpler.

How long does it take to implement Zero Trust?

The duration of a Zero Trust implementation varies by organisation and depends on factors such as the size of the IT environment, the maturity of identity management, and the number of applications. In practice Zero Trust is usually not a short project, but a phased transformation.

Written by:
KaHo Man

KaHo, with 18 years of experience in consultancy, is an Implementation Consultant in Identity & Access Management (IAM) at Tools4ever. With a solid foundation in Higher Professional Education in Computer Science, he has grown into a respected mentor and trainer, sharing his knowledge with colleagues and partners. KaHo's expertise also extends to delivering HelloID sales demonstrations and technical intakes, carrying out health checks, and overseeing project reviews.