Zero Trust Security: Why It Is Becoming Non-Negotiable
The traditional cybersecurity perimeter is disappearing.
Employees work from anywhere. Applications and data are spread across multiple cloud environments. APIs connect internal and external systems. Third parties need access to business resources. At the same time, AI is introducing a growing number of non-human identities and automated processes.
In this environment, can organisations still afford to trust by default?
Zero Trust security is becoming a fundamental approach to managing identity, access, data and business risk.
The core principle is simple:
Never trust by default. Always verify.
Zero Trust is not about eliminating trust. It is about making trust verifiable, limited and continuously reassessed.
What Is Zero Trust Security?
Zero Trust is a cybersecurity approach that assumes no user, device, application or workload should automatically be trusted simply because it is inside a corporate network or connected to a known environment.
Instead, access decisions are evaluated using factors such as:
- User or workload identity
- Device security
- Application
- Location
- Context
- Requested resource
- Risk level
- Required level of access
The objective is to ensure that access is granted only when it is required and appropriate.
A Zero Trust approach continually asks:
Should this user, device, application or workload have access to this particular resource right now?
This shifts cybersecurity away from simply protecting a network perimeter towards protecting the organisation’s users, identities, applications, data and resources.
Why Is Zero Trust Becoming More Important?
The way organisations operate has changed significantly. Several developments are making traditional perimeter-based security less effective.
Cloud Environments Are Distributed
Businesses increasingly rely on multiple cloud providers, SaaS platforms and externally hosted applications.
Data may move between:
- Public cloud environments
- Private infrastructure
- SaaS applications
- Third-party platforms
- APIs
- Remote devices
- AI services
This makes it difficult to define a single, fixed security perimeter.
Zero Trust helps organisations apply identity and access controls consistently across distributed environments.
Remote Work Has Changed Access Patterns
Employees, contractors and business partners may need access to corporate systems from different locations and devices.
Being connected from a recognised network is no longer sufficient evidence that access should automatically be trusted.
Identity verification, authentication, device security and contextual access controls therefore become increasingly important.
APIs Connect More Systems
APIs allow applications and services to communicate with each other.
While this improves integration and automation, it also creates additional access pathways.
Organisations need to understand:
- Which application is requesting access?
- Which resource is being accessed?
- What permissions are required?
- How long should access remain available?
- What happens if the application or credential is compromised?
Zero Trust principles can help organisations apply more controlled access to these interactions.
AI Is Introducing Non-Human Identities
AI systems, automated workflows and AI agents can increasingly interact with applications, data and business systems.
This introduces a new question:
Who or what is requesting access?
Security teams may need to manage not only employees and administrators, but also:
- Service accounts
- Applications
- APIs
- Cloud workloads
- Automated processes
- AI applications
- AI agents
Identity and access governance therefore needs to expand beyond human users.
Trust Cannot Be Assumed
Traditional security models often focused on protecting the corporate network and controlling who could enter it.
But once an attacker obtains valid credentials or compromises an authorised device, being “inside” the network does not necessarily mean the activity is legitimate.
Zero Trust changes this assumption.
Instead of asking:
“Is this user inside the network?”
organisations need to ask:
“Is this access request legitimate, necessary and appropriate for this specific resource?”
This approach helps reduce excessive access and limits the potential impact of compromised credentials or accounts.
Identity Has Become a Critical Security Boundary
Identity is increasingly becoming one of the most important security boundaries.
Organisations need visibility into different types of identities, including:
- Employees
- Contractors
- Privileged users
- Service accounts
- Applications
- APIs
- Cloud workloads
- Automated processes
- AI agents and other non-human identities
Common identity-related risks include:
- Compromised credentials
- Excessive privileges
- Dormant accounts
- Weak authentication
- Poorly governed service accounts
- Uncontrolled application access
Effective identity governance should answer four fundamental questions:
Who or what is requesting access?
What resource is being requested?
Why is access required?
How much access is actually necessary?
Zero Trust in Cloud Environments
Cloud adoption has created more flexible and distributed technology environments.
An organisation may have employees working remotely, data stored across multiple cloud platforms, third-party applications connected through APIs and AI services processing business information.
This means security controls need to operate across environments rather than relying only on a traditional network boundary.
For organisations moving towards a Zero Trust architecture, cloud identity, application access, workload identity and data protection should therefore be considered together.
Do Not Overlook Outbound Data Access
Zero Trust is not only about controlling who enters an organisation’s environment.
Outbound access also matters.
For example, an employee may upload confidential information to an unauthorised SaaS platform. An internal application may send data to an external service. An AI tool may process sensitive corporate information outside an organisation’s controlled environment.
These activities can create:
- Security risks
- Privacy risks
- Intellectual property risks
- Regulatory concerns
- Third-party risks
Organisations therefore need visibility into both inbound and outbound access and data movement.
AI Is Creating a New Dimension of Shadow IT
Generative AI and low-code/no-code technologies are accelerating technology adoption inside organisations.
Employees may use AI tools to summarise internal documents. Teams may connect customer information to external applications. Business users may create automated workflows without involving traditional IT or security teams.
The objective should not necessarily be to block innovation.
Instead, organisations need to create security and governance boundaries that allow innovation to happen responsibly.
Zero Trust can support this through:
- Strong identity controls
- Least-privilege access
- Monitoring
- Policy enforcement
- Application governance
- Continuous assessment
This is particularly relevant as organisations develop their broader AI governance approach.
Zero Trust Is Not a Product
Zero Trust is not a single software product that an organisation can purchase and install.
It is an organisational security model that requires coordination across multiple functions.
Effective implementation can involve:
- Cybersecurity teams
- Identity and access management
- Cloud and infrastructure teams
- Application owners
- Data owners
- Compliance and risk teams
- Business stakeholders
The goal is to make access decisions more deliberate, measurable and continuously reviewable.
How Can Organisations Start With Zero Trust?
Organisations do not necessarily need to transform their entire environment at once.
A practical approach can begin with high-risk systems and sensitive information.
1. Identify Critical Applications and Data
Determine which applications, systems and data would create the greatest business impact if compromised.
2. Map Human and Non-Human Identities
Identify employees, contractors, privileged accounts, applications, APIs, service accounts, workloads and AI systems that require access.
3. Review Existing Privileges
Identify excessive, outdated or unnecessary permissions.
4. Remove Unnecessary Access
Apply least-privilege principles so users and systems receive only the access required for their legitimate purpose.
5. Strengthen Authentication
Use appropriate authentication and identity controls for sensitive systems and resources.
6. Segment Critical Systems
Segmentation can help limit lateral movement if an account, device or workload is compromised.
7. Monitor Access and Data Movement
Look beyond login events. Monitor unusual access patterns, application activity and movement of sensitive information.
8. Include AI Applications and Agents
AI systems and automated agents should be included in identity, access and security governance rather than treated as exceptions.
9. Review Third-Party Access
Understand what external organisations, applications and service providers can access and whether that access remains necessary.
10. Continuously Review Policies
Zero Trust is not a one-time project. Access requirements, technologies, business processes and risks change continuously.
Zero Trust and Third-Party Risk
Third-party access is another important consideration.
Suppliers, consultants, technology providers and business partners may need access to organisational systems or data.
Instead of granting broad and permanent access, organisations can apply Zero Trust principles by considering:
- Who is the third party?
- What does the third party need to access?
- Why is access required?
- How long should access remain active?
- What level of privilege is required?
- How is the activity monitored?
- When should access be removed?
This approach can help organisations reduce unnecessary exposure across their digital ecosystem.
Zero Trust and Business Resilience
The objective of Zero Trust is not to make compromise impossible.
A more practical objective is to limit the impact of compromise.
If a credential, device, application or workload is compromised, tightly controlled access can help prevent the compromise from automatically becoming unrestricted access to other systems.
This supports a broader approach to cybersecurity resilience by helping organisations contain risk and reduce unnecessary access pathways.
How ISO/IEC 27001 Supports a Zero Trust Approach
Zero Trust and an Information Security Management System (ISMS) can complement each other.
ISO/IEC 27001 provides a structured approach to establishing, implementing, maintaining and continually improving information security management.
A Zero Trust strategy can support practical security objectives around areas such as:
- Access control
- Identity management
- Information protection
- Risk management
- Monitoring
- Security governance
- Continuous improvement
Organisations can therefore consider Zero Trust as part of a broader information security and risk management strategy rather than as an isolated technology initiative.
Zero Trust, AI Governance and Digital Trust
As organisations increasingly adopt AI, the relationship between cybersecurity, data privacy and AI governance becomes more important.
AI systems may interact with sensitive information, external services, applications and automated workflows.
This creates the need to understand:
- Who owns the AI system?
- What data can it access?
- What systems can it interact with?
- What permissions does it have?
- How are its activities monitored?
- What happens when its access is no longer required?
An organisation’s broader AI governance framework can work alongside Zero Trust principles to establish clearer accountability and controls around AI systems.
Organisations implementing ISO/IEC 42001 can also consider identity, access, risk and security as part of their wider AI management approach.
A Practical Zero Trust Checklist
Use the following checklist to review key areas of your organisation’s Zero Trust readiness.
| Area | Check |
|---|---|
| Critical applications and sensitive data | Identified |
| Human and non-human identities | Mapped |
| Privileged access | Reviewed |
| Excessive permissions | Removed |
| Strong authentication | Applied where appropriate |
| Least-privilege access | Implemented |
| Critical systems | Appropriately segmented |
| Access and data movement | Monitored |
| Third-party access | Reviewed regularly |
| AI applications and agents | Included in access governance |
| Access policies | Continuously reassessed |
| Security, privacy and compliance | Considered together |
The Future Is Perimeterless
The traditional idea of a fixed cybersecurity perimeter is becoming increasingly difficult to maintain.
People work remotely. Applications communicate through APIs. Cloud workloads operate across environments. Third parties connect to business systems. AI agents and other machine identities can interact with data and applications.
In this environment, trust needs to be:
Verified. Limited. Monitored. Reassessed.
Zero Trust therefore represents more than a technical framework.
It represents a change in how organisations think about access and trust in a digital environment.
Conclusion
The cybersecurity question is no longer simply:
“Who is inside our network?”
It is:
“Who or what is requesting access, what are they requesting, why do they need it, and should that access be allowed right now?”
As organisations adopt cloud technologies, AI, APIs and third-party services, identity and access governance become increasingly important.
Zero Trust provides a practical security model for this changing environment by moving away from assumed trust and towards continuous verification.
For organisations building stronger digital trust, Zero Trust can complement broader approaches to Digital Trust & Security, information security, AI governance and privacy management.
The future of cybersecurity is increasingly perimeterless.
And in a perimeterless environment, trust must be earned, verified and continuously managed.
Zero Trust security is a cybersecurity approach based on the principle of “never trust by default, always verify.” Access is evaluated based on identity, context, risk and the specific resource being requested.
Cloud environments, remote work, APIs, third-party access and AI have made traditional network-based security boundaries less effective. Zero Trust helps organisations manage access across these distributed environments.
Zero Trust applies identity-based and contextual access controls across cloud applications, workloads, APIs and data rather than relying solely on a traditional network perimeter.
AI agents can be treated as non-human identities that require defined permissions, controlled access, monitoring and continuous review.
No. Zero Trust is an organisational security model. Technology such as identity management, authentication, segmentation and monitoring can support its implementation.
ISO/IEC 27001 provides a structured information security management approach that can complement Zero Trust by supporting risk management, access control, governance and continual improvement.
Zero Trust aims to reduce unnecessary access and limit the potential impact of a compromised account, device, application or workload.
How can we help you?
Please get in touch with our expert team and start your certification journey
Contact us