A stolen Microsoft 365 password should not be enough to give a criminal access to your finance records, customer data and shared files. Yet for many businesses, once a user has signed in, their account can move around far more freely than it should. Zero trust is a practical way to reduce that exposure without making everyday work unnecessarily difficult.

It is not a single product, and it is not a promise that attacks will never happen. It is a security approach based on a simple principle: do not automatically trust a user, device or connection just because it is inside the network or has logged in before. Verify each request using the right signals, then give only the access required.

What zero trust means in practice

Traditional IT security was often built around a perimeter. The office firewall was the gate, and the corporate network was treated as relatively safe once someone was inside it. That model made more sense when staff worked from one location, applications lived on local servers and company devices rarely left the building.

Most SMEs now work differently. Staff use Microsoft 365 from home, in client offices and on mobile devices. Software is hosted in the cloud. Suppliers may need access to systems, and a laptop can connect through a home broadband service one day and public Wi-Fi the next. The old idea of a clear, protected edge no longer reflects how information moves.

Zero trust replaces broad, assumed access with continuing checks. A successful sign-in may be only the first step. The system can also consider whether multi-factor authentication was completed, whether the device is encrypted and managed, where the request comes from, what application is being accessed and whether the user genuinely needs that information for their role.

The goal is not to interrogate people at every click. The goal is to make access proportionate to risk. A managed laptop used by an employee in the UK may be able to open routine files with little friction. The same account trying to download payroll data from an unfamiliar country on an unmanaged device should face stronger checks or be blocked.

Why zero trust matters to SMEs

Cyber criminals do not only target large enterprises. Smaller organisations are often attractive because they hold valuable data, rely heavily on a small number of people and may have fewer security controls in place. A compromised email account can be used to send convincing invoice fraud messages, reset passwords, access cloud storage or impersonate a director.

Zero trust limits what an attacker can do after gaining an initial foothold. If a password is stolen, multi-factor authentication may stop the sign-in. If an attacker gets past that control, conditional access policies can prevent use of an unmanaged device. If they access one account, least-privilege permissions can stop them reaching every shared folder, finance system or administrative setting.

This is also a business continuity issue. A ransomware incident, accidental data exposure or locked-out cloud account can halt operations just as effectively as a failed server. For organisations working towards Cyber Essentials, handling sensitive client information or meeting contractual security requirements, a more controlled access model can also provide clearer evidence that sensible safeguards are in place.

There is a commercial benefit too. A secure, well-managed environment makes it easier to support hybrid staff, open a new site or bring in a specialist supplier without giving away blanket access. Security becomes part of a workable operating model rather than a series of last-minute exceptions.

The core controls behind a zero trust approach

Strong identity protection

Identity is usually the starting point because email and cloud accounts are central to modern business operations. Every user should have their own account, rather than shared logins. Multi-factor authentication should be enabled across key services, especially Microsoft 365, remote access, finance platforms and administrator accounts.

Not all multi-factor authentication methods offer the same protection. App-based approval, number matching and phishing-resistant methods are generally preferable to SMS where possible. It also helps to apply extra care to privileged accounts. An IT administrator, finance lead or director should not use a highly privileged account for ordinary email and browsing.

Managed, compliant devices

A username and password tell you who is asking for access. Device management helps establish whether the device can be trusted with business data. That may include encryption, supported operating systems, security updates, endpoint protection, screen-lock settings and the ability to remove company data if a device is lost.

This does not mean every employee needs an identical laptop or that personal devices must be banned outright. The right policy depends on the business, the data involved and the level of risk. A bring-your-own-device arrangement can work, but access should be more limited when the organisation cannot manage the device to the same standard.

Least-privilege access

People need access to do their jobs, but broad permissions are easy to overlook and difficult to unwind after an incident. Least privilege means giving staff, suppliers and applications the minimum access necessary, then reviewing it regularly.

For example, a new starter in sales may need the CRM system, specific shared folders and Teams, but not payroll records or the ability to create new global administrator accounts. A temporary external bookkeeper may need access to accounting software for a defined period, rather than a permanent company-wide login.

This can feel painstaking at first, particularly in businesses where permissions have developed informally over years. However, a clear access structure also makes onboarding, offboarding and internal role changes quicker and safer.

Segmented networks and protected data

Not every device on the same network needs to communicate with every other device. Separating guest Wi-Fi, staff devices, servers, voice systems and operational equipment can contain problems when something goes wrong. It is particularly relevant for multi-site businesses, warehouses, practices and organisations with older equipment that cannot be managed like a modern laptop.

Data protection matters as much as network design. Sensitive information should be classified where practical, shared deliberately and backed up properly. A backup is only useful if it is protected from the same compromise, monitored and periodically tested for recovery.

Where to start without disrupting staff

A zero trust programme should be phased. Trying to change every password, device, permission and network rule at once often creates unnecessary disruption and encourages workarounds. Start with the systems that would cause the greatest damage if they were misused.

First, establish a clear picture of user accounts, administrator rights, devices, applications and data locations. Many organisations find dormant accounts, former staff permissions or unsupported machines during this stage. Those are often straightforward risks to remove.

Next, enforce multi-factor authentication and protect administrator accounts. Conditional access can then be introduced carefully, initially using reporting or pilot groups to see who would be affected. This allows the business to spot legitimate exceptions before a policy blocks a critical process.

Device management should follow with agreed minimum standards. Staff need clear communication, particularly if personal mobiles or home computers are involved. Explain what the business is protecting, what will be visible to IT and what support is available. Good security works better when people understand the reason behind it.

Finally, review permissions, network segmentation and incident response. Test what happens if a user reports a suspicious sign-in or a laptop is stolen. The measure of a plan is not whether it looks good on paper, but whether your team can act calmly and quickly when the situation is real.

Avoiding the common mistakes

The biggest mistake is treating zero trust as a purchase rather than an operating discipline. Technology can enforce policies, but it cannot decide which staff member should have access to confidential files or whether a supplier still needs an account. Those decisions need ownership within the business.

Another mistake is applying controls without considering the user experience. If every sign-in challenge feels random, staff will become frustrated and may look for shortcuts. Well-designed policies use context: managed devices, normal locations and low-risk activity should create less friction than unusual or high-risk requests.

It is also worth being realistic about legacy systems. Some older applications do not support modern authentication, and some operational devices cannot accept the latest security software. In those cases, compensating controls such as network isolation, tighter access rules and closely monitored remote connections may be more appropriate than a rushed replacement.

For many SMEs, the most effective route is to build zero trust into wider IT management rather than run it as a one-off project. At Nubis 365, that can mean aligning Microsoft 365 security, endpoint management, network design, backup and user support around the way your organisation actually works.

The next useful step is not to aim for a perfect security architecture by next month. Identify the account, device or system that would hurt most if compromised, improve the controls around it, and keep building from there. Each sensible check makes it harder for a single mistake to become a business-wide incident.

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
Are you human? Please solve:Captcha