Back to Glossary

Entry · Business

Zero Trust Architecture

Zero trust architecture is a cybersecurity approach that does not grant access merely because a user or device is inside a company network. It checks identity, device and policy before access to a specific resource, then limits what the session can reach.

It is a design approach, not a single product or a promise that every intrusion will be stopped.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A remote employee opens a payroll application from a company laptop. Traditional perimeter thinking may trust the connection because it came through a corporate VPN.

A zero trust design asks whether this user, device and requested action meet current policy for payroll access. NIST SP 800-207 says location or asset ownership alone does not create implicit trust.

Authentication and authorisation are distinct checks before a session to a resource. The emphasis is on protecting resources rather than merely guarding a network boundary.

Inventory resources first, identifying applications, data sets, service accounts and systems that matter, since a business cannot apply focused policy to payroll records if it does not know where they live or which services use them. Map identities and roles, because employees, contractors, customers and automated services need different entitlements, and a shared administrator account makes it hard to know who performed a sensitive action and when access should end.

Use strong authentication appropriate to risk, since multifactor checks and resistant credentials can reduce account takeover, but recovery routes and support processes also need protection because an attacker may target the weaker reset flow. Assess devices where relevant, as a patched managed laptop and an unknown personal device may pose different risks, and device signals are imperfect, so policies need a route for legitimate users whose devices are misclassified.

Apply least privilege by giving an employee access to the data and functions needed for the job, not every system in the department, and review permissions when a role changes or a contract ends. Segment access to sensitive resources, so that if one account is compromised the attacker does not automatically move from email to finance databases, with network design, application permissions and data controls working together.

The CISA Zero Trust Maturity Model describes a progression across identity, devices, networks, applications and data, with cross-cutting visibility and automation, as a roadmap for agencies rather than a rule that a small business must buy five products at once. Make access decisions using current context where practical, so a sign-in from a new device or unusual location may trigger an extra check, without relying on one signal or making every ordinary action so difficult that users seek workarounds, and log decisions and activity so security teams can investigate an unexpected access or false block, protecting logs from tampering and limiting retention to legitimate needs.

Design policy enforcement near the resource, because a gateway that checks only the initial connection cannot necessarily stop a later unauthorised API call, and include machine identities, since an automated integration with broad permanent credentials can bypass the spirit of least privilege even when employees use multifactor authentication, so rotate secrets and scope service access. Plan for outages: if the identity provider fails, ask what critical work continues and under what controlled emergency procedure, since an unsafe universal bypass can undo the security design while no recovery path can stop operations.

An illustrative coverage measure is critical resources with documented access policies divided by all critical resources inventoried, so if 45 of 50 qualify, coverage is 90%, though it does not prove the policies are effective or the inventory complete; test scenarios such as a departed employee, compromised device, third-party contractor and stolen session, check whether access is refused, logged and recoverable for legitimate users, and review the results rather than declaring a vendor deployment finished. Treat zero trust as gradual change, starting with high-value resources and broken access paths, because replacing a VPN label with a new label without narrowing access changes little; for owners, the goal is to reduce the damage a misplaced credential or device can cause while keeping work possible, so prioritise evidence of actual controls over a product badge or maturity score.

In practice

Real-world examples.

1

Example

Payroll access requires both the correct user role and an approved device state.

2

Example

A departing contractor loses access to one project without breaking other users.

3

Example

An integration credential can read only the records its service needs.

Formula

Calculation

Illustrative policy coverage = critical resources with documented enforced access policy / all inventoried critical resources x 100. Forty-five of fifty gives 90%; test effectiveness separately.

Case study

Seen in the real world.

This entirely fictional example follows Vale Group, an invented firm. A contractor account still reached a finance share after a project ended. The team mapped entitlements, limited access by project and tested revocation. It also retained a controlled emergency-access route. The example does not claim the design prevents every attack.

Watch out

Common mistakes.

  • Trusting all traffic merely because it came through a VPN.
  • Applying multifactor authentication to people while leaving broad service credentials untouched.
  • Buying a zero trust product without inventorying resources or testing permissions.

Questions

People also ask.

What is zero trust architecture?

A resource-focused security approach that avoids automatic trust from network location.

Does it mean never trusting employees?

No. It means checking access against identity, device and policy for the requested resource.

Is one product enough?

No. Identity, device, application, network and data controls must work together.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%

Related

Keep reading.

Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.