Managed IT · 6 min read

Zero Trust for mid-sized businesses: where to start in 2026

Zero Trust is not a product you buy. It is a set of decisions about identity, devices and access. A practical starting sequence for organisations without a large security team.

· Bhargava Group

“Never trust, always verify” is easy to say and hard to schedule. Zero Trust replaces the old model, where anything inside the office network was trusted, with one where every access request is checked against who is asking, from what device, for what resource, right now.

Frameworks such as CISA’s Zero Trust Maturity Model organise the work into pillars: identity, devices, networks, applications and workloads, and data. For a mid-sized business, the order you tackle them matters more than the diagram.

1. Identity first

Identity is the new perimeter, and it is where most attacks begin.

  • One identity provider for everything, with single sign-on to every business application you can connect.
  • Phishing-resistant MFA, starting with administrators.
  • Conditional access policies based on user, location, device state and risk.
  • Remove standing admin rights. Use just-in-time elevation for privileged tasks.

2. Devices you can vouch for

Access decisions are only as good as your knowledge of the device.

  • Enrol company laptops and phones in device management.
  • Define “compliant”: encrypted, patched, protected by endpoint detection and response, with a supported OS.
  • Require compliant devices for sensitive applications. Give unmanaged devices browser-only, limited access.

3. Applications over networks

Stop granting broad network access to reach one application.

  • Publish internal apps through identity-aware access proxies instead of full VPN tunnels.
  • Segment remaining networks so a compromised laptop cannot reach servers, backups and management interfaces.

4. Data that protects itself

  • Classify sensitive information with labels that carry encryption and sharing rules.
  • Apply data loss prevention to email, cloud storage and AI tools.
  • Review who has access to your most sensitive repositories every quarter.

5. Visibility and response

Collect sign-in, endpoint and cloud logs in one place, and make sure someone is watching them around the clock, whether that is your team or a managed detection and response service.

A realistic timeline

Most mid-sized organisations can complete identity and device foundations in one to two quarters, then move application access and data protection forward over the following year. Each step reduces risk on its own. You do not need to finish to benefit.

Our Managed IT & Cybersecurity practice builds Zero Trust roadmaps and delivers them in stages, starting with the identity controls that stop most attacks.

All insights

Talk to us

Talk to Managed IT & Cybersecurity.

A 30-minute consultation with a senior consultant. You leave with a clear next step — whether or not it involves us.

Privacy choices

Choose which optional technologies we may use. You can change this at any time from “Privacy choices” in the footer.

Strictly necessary

Security, spam protection (Cloudflare Turnstile) and remembering these choices. Always on.

Always on