Zero Trust
Zero trust is a security model that grants no implicit trust based on network location or identity claims — every access request is verified. Where the human layer fits.
Zero trust is a security architecture and mindset in which no user, device or connection is trusted by default because of where it sits — inside the corporate network, on a managed laptop, or behind a VPN. Every access request is authenticated, authorized and continuously evaluated against policy, using signals such as identity strength, device health, location and the sensitivity of the resource. The model is formalized in NIST SP 800-207, which defines zero trust as a set of principles for moving defenses from static, network-based perimeters to a focus on users, assets and resources. The EU's NIS2 Directive names zero-trust principles among the basic cyber hygiene practices it expects of covered organizations.
How it works
A zero-trust architecture replaces the single perimeter check with per-request decisions. A policy engine evaluates each request — who is asking, from what device, in what state, for what — and grants the minimum access needed for the shortest time needed, following the principle of least privilege. Sessions are short-lived and re-evaluated; a change in device posture or an unusual location can revoke access mid-session. Network segmentation limits what a compromised account can reach, and strong, phishing-resistant authentication such as passkeys anchors the identity signal the whole model depends on.
Where the human layer fits
Zero trust does not remove people from the decision; it concentrates the attack on them. If the network no longer trusts location, the attacker's remaining path is to become a legitimate user — by phishing credentials, defeating MFA through fatigue or MFA bypass techniques, or talking the help desk into a reset. Zero trust therefore makes identity hygiene and social-engineering resistance more important, not less: an account takeover of a properly verified user passes every policy check. Organizations adopting zero trust should pair it with phishing-resistant authentication (our passkey migration guide covers the sequence), hardened help-desk verification, and a measured human-risk program — phishing simulation and a human risk score — so the "verify explicitly" principle extends to the human requests technology cannot judge.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo