Skip to content
cybersecurityZero TrustMFAEDR

Zero Trust for an SMB: where to start without rebuilding everything

Zero Trust is not just for large enterprises. Identity, endpoints, conditional access, segmentation: the five realistic workstreams for an SMB, in order.

12 September 2026 · 2 min read · ALLSAFE SOLUTIONS

Secured server room

Zero Trust fits in one sentence: never trust by default, always verify. Not a user because they are in the office, not a device because it is on the internal network, not an application because it worked yesterday. Born in large enterprises, the principle applies to an SMB through five workstreams, without replacing what you have.

Why the perimeter no longer protects

The classic model, a firewall at the entrance and full trust inside, dates from a time when everything lived within the walls. Today data sits in Microsoft 365, staff work from home, and a single password stolen through phishing opens everything. Almost every ransomware attack we describe in ransomware: 7 measures for an SMB exploits that implicit trust.

Workstream 1. Identity, with MFA everywhere

Identity is the new perimeter. Two-factor authentication on every account, with no exception for leadership, blocks the large majority of account compromises on its own. We detail the rollout in our enterprise MFA guide. Add a business password manager and remove shared accounts.

Workstream 2. Compliant devices, or no access

A device without current antivirus, disk encryption or the latest patches should not reach company data. An EDR replaces classic antivirus and reports each machine’s state. With Microsoft Intune or an equivalent, application access is conditioned on that compliance.

Workstream 3. Conditional access

Once identity and devices are under control, Microsoft 365 conditional access rules decide case by case: sign-in from an unusual country, blocked; unmanaged device, read-only in the browser; sensitive application, MFA asked again. These rules come with Business Premium and are a far better answer than a permanently open VPN.

Workstream 4. Segment the network

The internal network no longer has to be a single trust zone. On a FortiGate firewall, separating endpoints, servers, telephony, printers, cameras and guest WiFi into distinct networks, with explicit rules between them, stops ransomware on one laptop from encrypting the servers. It is the most technical workstream, and the one that limits damage the most on the day it matters.

Workstream 5. Remote access without an open VPN

Traditional VPN grants access to the whole network once connected. ZTNA, available on FortiGate and WatchGuard, opens only the requested application, after checking identity and device. For an SMB it deploys in a few days and removes a classic entry point for attackers.

In what order, and how long

Workstream Typical duration User effort
MFA and password manager 2 weeks Low
EDR and device compliance 1 month None
Conditional access 2 weeks Low
Network segmentation 1 to 2 months None
ZTNA 2 weeks Low

Six months is enough for a 50-seat SMB, with no business interruption, and much of it is funded by licences already paid for. We fold these workstreams into our business cybersecurity offer, starting with a free assessment.

Let’s talk about your project.

Free initial audit, reply within one business day.

Request a call back
← All articles
CallWhatsAppFree audit