Beyond the buzzword
Strip away the vendor noise and zero trust is one idea: stop treating the network as the security boundary. No device, user, or service is trusted because of where it sits every access is verified, every time.
For mid-size companies, the good news is that you don't need a three-year program. Four moves capture most of the value.
Move 1: Identity is the new perimeter
Single sign-on plus enforced MFA across every business system is the highest-leverage security investment available today. Phishing-resistant MFA (hardware keys or passkeys) for admins and finance roles first. If you do nothing else this quarter, do this.
Move 2: Least privilege, enforced by default
Audit who can access what, and cut ruthlessly. Standing admin rights should be rare and time-boxed just-in-time elevation for the moments that need it. In the cloud, this means scoped roles instead of shared root accounts, and service accounts with exactly the permissions they use.
Move 3: Assume the endpoint is hostile
Managed devices with disk encryption, patching, and endpoint detection enforced as a condition of access, not a policy document. Access from unmanaged or non-compliant devices gets stepped-down permissions or blocked.
Move 4: Segment what matters
Full microsegmentation is overkill for most mid-size environments. Segmenting the crown jewels isn't: production databases, financial systems, and backups should live in network segments that ordinary corporate traffic simply cannot reach.
What this buys you
Most breaches at mid-size companies follow the same script: one phished credential, then lateral movement through a flat network to whatever pays. Each move above breaks a link in that chain stolen passwords stop working, compromised accounts hit walls, malware-ridden laptops lose access, and the crown jewels sit behind doors that don't open from the corporate LAN.
Zero trust isn't a product you buy. It's a posture you adopt incrementally and the first increments are neither expensive nor exotic.
Ujen Basi
Full Stack Developer and Head of Engineering
Part of the Converge Solutions team writing about what we learn building technology for ambitious organizations.