Identity

Zero Trust

Zero Trust is a security model in which no access is automatically considered trustworthy.

Zero Trust is a security model where no access is automatically considered trustworthy. Every request is verified based on identity, device, and context, even inside the internal network.

How it works

Traditional networks trust everything inside their internal environment. Zero Trust abandons this assumption. Access is granted per application with the fewest possible privileges and only after verification. The identity provider, device health, and rules like Conditional Access collectively determine access. The network is also divided into small segments, so attackers cannot move freely.

For example, a laptop becomes infected with malware. On a traditional network, the attacker could reach all servers from that device. In a Zero Trust environment, the EDR reports the laptop as compromised. The IdP then denies access to all applications, and segmentation isolates the device.

What to look out for

  • Zero Trust is a journey, not a product. Expect a multi-year project with clear phases.
  • Start with identities: MFA, clean roles, and Conditional Access.
  • Incorporate device health into access decisions.
  • Prioritise the segmentation of critical systems.
  • Plan for monitoring from the very beginning. Every access decision generates valuable logs.

Switzerland and regulation

Zero Trust principles are also gaining importance in public administration. NIST SP 800-207 often serves as a reference. There are no specific obligations for Zero Trust in Switzerland. However, its principles help meet requirements from the revFADP (revised Federal Act on Data Protection) and FINMA circulars.

Relevance for the SOC

Zero Trust reduces the attack surface but does not replace monitoring. The SOC uses signals from the IdP, EDR and network to detect suspicious access. Conversely, insights from the SOC can automatically restrict access.

How we implement it

In our SOC, we combine signals from identity, device and network into a single Case. We are happy to discuss architecture questions as part of our Security Consulting.

How ANOMAL implements this