Zero trust security: what it actually means for South African SMBs
Zero trust gets thrown around as a marketing term more often than it gets properly explained. Stripped of the buzzwords, it's a genuinely useful shift in how you think about access.
The old model of network security assumed that anything inside your network perimeter could be trusted, and anything outside it couldn't. That assumption made sense when everyone worked from one office on one network. It makes much less sense now, with remote work, cloud apps and personal devices all blurring where your "perimeter" even is.
The core idea, in plain terms
Zero trust means never automatically trusting a user or device just because they're on your network or have logged in once. Instead, access is continuously verified — who is this, what device are they using, does this request make sense given their normal behaviour — every time, not just at login.
What this looks like in practice, not just in theory
For most SMBs, adopting zero trust principles doesn't mean ripping out your infrastructure. It means layering in specific controls: conditional access policies that check device health before granting access, multi-factor authentication as standard, and network segmentation so a compromised account can't roam freely.
Why this matters more for smaller businesses, not less
There's a common assumption that zero trust is an enterprise concern. In reality, SMBs are often the ones with the least segmented networks and the most implicit trust baked into daily operations — which makes the underlying principles even more relevant, even if the implementation is simpler.
Most of the businesses we work with already own the Microsoft 365 licensing needed to implement meaningful zero trust controls — the gap is usually configuration, not budget.