Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryIT Security

Zero Trust

Zero trust is a security model that grants no implicit trust based on network location. What NIST SP 800-207 defines, how it maps to OT and vehicles, and what it is not.

Updated This page as Markdown

In short

Zero trust is a security architecture in which no user, device or connection is trusted because of where it sits in the network. Every access to a resource is authenticated, authorised and checked against policy per session, with device posture and context taken into account. NIST SP 800-207 defines the model and its components. It is a design principle and a programme, not a product you install.

What is zero trust?

Zero trust is a security model that removes implicit trust from the network. NIST SP 800-207 describes it as a set of paradigms that move defences from static, network-based perimeters to users, assets and resources, with no trust granted to an account or device solely because of its physical or network location or because the company owns it. Every request to a resource is authenticated and authorised before a session is established, and the decision considers who asks, from which device, in what state, and whether the request fits policy.

The classic alternative is the castle-and-moat model: a firewall around the company network, and once you are inside, you can reach most things. Zero trust assumes the attacker is already inside, because after a phishing click or a compromised contractor laptop, they usually are.

Where is it defined?

The reference is NIST SP 800-207 (August 2020). It lists seven tenets, among them: all data sources and computing services are resources; all communication is secured regardless of location; access is granted per session; access decisions follow dynamic policy that includes client identity, application and asset state; the enterprise monitors the integrity of all assets; and authentication and authorisation are enforced strictly before access. It also names the logical components: a policy engine and policy administrator that make the decision, and policy enforcement points that apply it in front of each resource.

CISA’s Zero Trust Maturity Model structures the work into five pillars (identity, devices, networks, applications and workloads, data) and three cross-cutting capabilities, and describes maturity stages for each. In the EU, NIS2 recital 89 names zero-trust principles among basic cyber hygiene practices, and Article 21(2) requires access control policies, multi-factor authentication and secured communication for essential and important entities.

What it means in practice

In most companies zero trust starts with identity: one identity provider, phishing-resistant multi-factor authentication for every person, device compliance as a condition of access, and application access through an identity-aware proxy instead of a flat VPN. The second step is segmentation so that a compromised workstation cannot speak to servers that it has no business with. The third is telemetry: the policy engine can only decide dynamically if it sees logins, device state and unusual behaviour, which is why zero trust and a SOC belong together.

In our penetration tests the gap between the architecture diagram and reality is usually in the exceptions: service accounts with static passwords, a jump host that every administrator shares, a legacy application reachable without MFA, or an OT network reachable from the office network through a forgotten dual-homed machine. The assumed-breach test is the honest way to measure it.

For industrial plants and vehicles the principle holds but the mechanics differ. A PLC or a CAN node cannot authenticate per session; the trust boundary moves to a conduit, gateway or data diode in front of it, as IEC 62443 describes with zones and conduits. For vehicles, authenticated in-vehicle messaging and strict gateway filtering are the equivalent.

Common misunderstandings

Zero trust is not a product, although many are sold under the name. It is not the same as replacing the VPN with a cloud proxy. It does not mean no trust at all, but trust that is established explicitly, per request, and can be withdrawn. And it is not all or nothing: every account moved to phishing-resistant MFA and every segment cut off from the flat network is progress, even if the programme takes years.

FAQ

Frequently asked questions

Is zero trust required by NIS2?

Not as a named requirement. NIS2 recital 89 lists zero-trust principles among the basic cyber hygiene practices it expects, and Article 21(2) requires access control, multi-factor authentication and network security measures that point in the same direction. You can meet Article 21 without calling it zero trust, and you can call something zero trust without meeting Article 21.

Can zero trust be applied to OT or vehicles?

Partly. A PLC from 2008 or a CAN node cannot authenticate per session, so the enforcement point moves to a gateway or conduit in front of it. In practice OT zero trust looks like IEC 62443 zones and conduits with strong identity for every human and remote access path. Inside a vehicle, authenticated messaging (SecOC) and gateway filtering play the same role.

How do you test whether a zero trust architecture works?

With an assumed-breach penetration test: we start with one compromised user account or one workstation and see how far lateral movement gets. If a single stolen credential reaches file servers, hypervisors or the OT network, the architecture is zero trust on slides only.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab