Three questions and answers: How to implement Zero Trust with a minimal approach
The article discusses the concept of Zero Trust security and challenges associated with its implementation in enterprise IT environments. It highlights that Zero Trust is often misunderstood as a comprehensive overhaul requiring changes across network infrastructure, identities, devices, applications, and processes, which can lead to sprawling projects. The author argues that this approach frequently overlooks critical risks such as privileged accounts, poor access controls, and unsecured service accounts. As a result, many organizations struggle with unclear objectives and lack of measurable outcomes. To address these issues, the article introduces the Minimum Viable Zero Trust (MVZT) approach, which focuses on implementing core measures within 90 days by prioritizing high-risk areas like privileged access, cloud administration, and central security systems. This method treats Zero Trust as a control mechanism rather than a complete system redesign, emphasizing decisions based on identity, authentication strength, device status, risk signals, and resource protection needs.
A German cybersecurity expert has outlined how organizations can introduce the security framework known as Zero Trust using a minimal viable approach within just 90 days. The method, called Minimum Viable Zero Trust (MVZT), focuses on reducing risk in the most critical areas of an organization’s infrastructure without attempting to overhaul the entire system at once. According to Marcel Küppers, a seasoned cybersecurity professional with over two decades of experience, this strategy avoids the pitfalls of traditional Zero Trust implementations that often expand beyond control and become sprawling, unmanageable projects. Küppers explains that many companies attempt to apply Zero Trust as a comprehensive architecture, aiming to transform networks, identities, endpoints, applications, cloud services, and operational processes simultaneously. This broad scope frequently leads to delays and inefficiencies, especially in large enterprises where legacy systems, multiple identity providers, and complex administrative pathways complicate implementation. Additionally, some organizations mistakenly view Zero Trust as a product, such as a new network solution or firewall upgrade, rather than a conceptual shift in how access is managed. The core issue lies in the lack of clarity regarding measurable outcomes. Without defined metrics for risk reduction and clear benchmarks, Zero Trust initiatives often lose direction. MVZT addresses these challenges by focusing on high-risk areas such as privileged accounts, cloud administration, continuous integration/continuous deployment (CI/CD) pipelines, secrets management, backups, and central security tools. These elements represent the primary attack vectors where unauthorized access could cause the most damage. Instead of redesigning every application or process, MVZT treats Zero Trust as a control mechanism. Access decisions are based on factors including user identity, authentication strength, device status, risk signals, and the sensitivity of the target resource. For example, policies might require stronger authentication for sensitive actions, limit session durations, or block access entirely under certain conditions. This approach ensures that the system remains functional while significantly improving security posture. One of the key advantages of MVZT is its emphasis on demonstrable results. From the outset, the initiative includes features such as audit logs, real-time monitoring, just-in-time activation of access, and revocation capabilities. These elements provide immediate visibility into how well the system is performing and allow for rapid adjustments. By the end of the 90-day period, organizations should have a clear understanding of which risks have been mitigated and how quickly they can respond to potential breaches. The 90-day plan begins with defining the scope, identifying critical assets and administrative paths, and establishing baseline security controls. During the first two weeks, teams inventory privileged roles and identities, define Tier-0 and Tier-1 systems, and pinpoint essential admin pathways. They then implement phishing-resistant authentication and enforce strict device compliance standards. Simultaneously, centralized logging of authentication attempts and administrative activities is established to ensure transparency and traceability. This structured yet flexible approach allows organizations to build a solid foundation for Zero Trust without overwhelming internal resources. It also provides a tangible starting point for further expansion, enabling companies to refine their strategies based on real-world data and evolving threats. As the concept gains traction among IT professionals, MVZT represents a pragmatic alternative to the often impractical goal of implementing Zero Trust comprehensively.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter