Zero Trust Security definition
Zero trust security is a security model based on the principle of never trust, always verify. Instead of trusting users and devices because they are inside the corporate network, every access request is authenticated, authorized and continuously evaluated based on identity, device health and context, and users receive only the minimum access they need.
Why zero trust replaced perimeter security
Traditional security assumed a trusted internal network protected by a firewall, with a VPN for remote workers. Once inside, users and devices could often reach many systems. That model broke down as applications moved to the cloud and SaaS, employees worked from anywhere, and attackers learned that one stolen password or infected laptop could let them move freely inside the network. Zero trust, described by Forrester and later formalized in NIST SP 800-207, removes the idea of a trusted network location.
Core principles of zero trust
Zero trust is a strategy rather than a single product, and vendors describe it in different ways. Most definitions share a few principles that guide how access decisions are made and how systems are designed. Applying them consistently matters more than buying any particular tool marketed under the zero trust label. Each principle can be applied incrementally.
- Verify explicitly: authenticate and authorize every request using identity, device and context.
- Least privilege: grant only the access needed, for the shortest time needed.
- Assume breach: limit blast radius with segmentation and monitor continuously.
- Device trust: check device health, management status and patch level.
- Encrypt everywhere: protect traffic inside networks as well as across the internet.
How does zero trust architecture work?
A policy engine evaluates each access request against rules: who the user is, whether they passed multi-factor authentication, whether their device is managed and healthy, where they are connecting from, and how sensitive the resource is. A policy enforcement point, such as an identity-aware proxy or zero trust network access service, then allows, blocks or limits the connection. Users reach specific applications rather than whole networks.
Inside data centers and clusters, microsegmentation and service-to-service authentication, for example mutual TLS through a service mesh, prevent an attacker who compromises one workload from freely reaching others. Logging every decision supports detection and investigation. Over time, these logs also show which permissions are never used and can be removed.
Zero trust vs VPN
A VPN connects a device to a network, after which the user can often reach many systems. Zero trust network access connects a verified user on a verified device to a specific application, checking context continuously. Services such as Cloudflare Access, Zscaler Private Access, Google's Chrome Enterprise Premium (formerly BeyondCorp Enterprise) and Microsoft Entra Private Access deliver this model. Many organizations run both during a transition, moving applications behind zero trust access over time. Legacy applications that cannot sit behind a proxy are often the last to move.
How to start with zero trust
Begin with identity: a single identity provider, strong multi-factor authentication and removal of shared accounts. Inventory applications and data, classify sensitivity, then put the most critical applications behind identity-aware access. Add device management and health checks, segment networks and workloads, and tighten privileges based on actual usage. Nexzem's security team helps clients plan zero trust roadmaps that deliver risk reduction in stages rather than as one large project.