Skip to content
BITBRIEF

Institutional research · AI · Cybersecurity · Digital assets

Vol. 01 · No. 13

Zero Trust

A security model that grants no implicit trust from network position, and authenticates and authorises every request as if it came from an untrusted network.

The model it replaces assumed a perimeter: inside was trusted, outside was not. Remote work, cloud services and third-party integrations left that perimeter describing nothing real. Zero Trust drops the assumption rather than trying to redraw the line.

What it means in practice

  • Identity is verified per request, not per session start.
  • Authorisation is evaluated against current context — device, location, behaviour — not a badge issued at login.
  • Access is scoped to the minimum needed and expires.
  • Everything is logged on the assumption it will be needed for an investigation.

Where it concentrates risk instead of removing it

Verifying every request means every service depends on the identity provider. A national identity gateway or a corporate single sign-on becomes the thing whose availability everything else inherits — which is fine until availability is what is under attack. We have covered an outage of exactly that shape.

All 30 terms