Zero Trust Security for Modern UK Businesses
Zero trust replaces the outdated 'trust everything inside the network' model with continuous verification of every user, device, and connection — dramatically reducing your attack surface.
Written by Nathan Hill-Haimes, Co-Founder, AMVIA
What is Zero Trust?
Zero trust is a security framework based on the principle 'never trust, always verify'. Rather than assuming devices inside your network are safe, every access request — regardless of origin — is authenticated, authorised, and continuously validated. Microsoft, NCSC, and NIST all recommend zero trust as the foundational architecture for modern businesses.
Read our full cybersecurity guideWhat Is Zero Trust Security?
Zero trust is a security framework built on the principle of "never trust, always verify." Rather than assuming that devices and users inside the corporate network are inherently trustworthy, zero trust requires every access request — regardless of where it originates — to be authenticated, authorised, and continuously validated. As a foundational approach to cybersecurity, zero trust represents a fundamental shift from perimeter-based security to identity-centric security, and it is now recommended by the NCSC, NIST, and Microsoft as the standard architecture for modern businesses.
For UK SMEs, zero trust is not an abstract framework reserved for large enterprises. With 43% of UK businesses experiencing a cybersecurity breach in 2025 (DSIT), and 28% of UK employees working in a hybrid pattern (ONS 2025), the traditional network perimeter has dissolved. Employees access company data from home networks, coffee shops, and mobile hotspots. Data lives in Microsoft 365, Azure, and SaaS applications rather than on-premises servers. Zero trust is the security model designed for this reality.
The Problem with Perimeter-Based Security
Traditional security assumed that everything inside the corporate network was trusted. A firewall protected the boundary, a VPN provided remote access, and once a user was "inside" the network, they could access resources with minimal further verification. This model worked when employees sat in offices, accessed on-premises servers, and threats came exclusively from outside. That world no longer exists.
Stolen or compromised credentials were the initial attack vector in 22% of data breaches in 2024 — the single largest cause of breaches, surpassing phishing at 16% and software vulnerabilities (Verizon DBIR 2025). Once an attacker compromises a single user's credentials — through phishing, credential stuffing, or social engineering — perimeter security offers no resistance to lateral movement. The attacker is "inside" the network and can access anything the compromised user could access.
The shift to cloud computing and hybrid working has made this weakness acute. Today, your data lives in Microsoft 365, Azure, SaaS applications, and on employee devices that travel between home, office, and public Wi-Fi networks. A VPN and a firewall are no longer sufficient to protect this distributed environment. Zero trust addresses this by removing the concept of a trusted perimeter entirely — every access request is verified, regardless of where it comes from.
The Six Zero Trust Pillars
The NCSC's zero trust architecture guidance identifies six pillars that together create a comprehensive security framework. Each pillar addresses a different aspect of the IT environment, and a mature zero trust implementation covers all six:
1. Identity
Identity is the foundation of zero trust. Every user must be verified with strong authentication before accessing any resource. This means multi-factor authentication (MFA) as a minimum, with passwordless authentication (Windows Hello for Business, FIDO2 security keys, or Microsoft Authenticator) as the preferred approach. Phishing-resistant, passwordless authentication grew 63% in one year, rising from 8.6% to 14.0% of authentication events (Okta, 2025), reflecting the rapid adoption of this approach.
Beyond authentication, identity-based zero trust includes risk-based access decisions. Microsoft Entra ID can evaluate the risk level of each sign-in attempt — considering factors such as location, device health, and behavioural patterns — require additional verification or block access entirely for high-risk sign-ins.
2. Devices
Only managed, compliant devices should be permitted to access corporate resources. Microsoft Intune enforces compliance policies on all enrolled devices — requiring encryption, PIN or biometric lock, up-to-date operating systems, and active security agents. Conditional Access policies then verify device compliance before granting access to Microsoft 365 and other applications. A non-compliant device is blocked, regardless of whether the user's credentials are valid.
3. Applications
Zero trust controls access at the application layer, not just the network layer. Rather than granting broad network access through a VPN, zero trust provides access to specific applications based on the user's identity, role, and device compliance status. Microsoft Entra ID application proxy and Conditional Access policies enforce application-level access controls without requiring users to be on the corporate network.
4. Data
Data classification and protection ensure that sensitive information is protected regardless of where it is stored or how it is shared. Microsoft Purview sensitivity labels can be applied to documents and emails, enforcing encryption, access restrictions, and data loss prevention (DLP) policies automatically. This means a confidential document remains protected even if it is shared outside the organisation or downloaded to an unmanaged device.
5. Infrastructure
Infrastructure security in a zero trust model means continuously assessing the health and configuration of servers, cloud resources, and platform services. Least-privilege access is applied to all administrative functions — administrators use standard accounts for daily work and elevate to privileged access only when needed, through tools such as Privileged Identity Management (PIM) in Microsoft Entra ID.
6. Networks
Network microsegmentation limits lateral movement by dividing the network into isolated segments. Even if an attacker compromises one segment, they cannot move freely to others. All traffic — including east-west traffic between internal systems — should be encrypted and monitored. Zero Trust Network Access (ZTNA) solutions can replace or supplement traditional VPN connections, providing application-specific access rather than blanket network access.
Implementing Zero Trust with Microsoft 365
For most UK SMEs, Microsoft 365 Business Premium provides the ideal zero trust foundation. The platform includes the tools needed to implement a strong zero trust posture without requiring specialist hardware or complex on-premises infrastructure:
- Microsoft Entra ID: Manages identity, enforces MFA, and provides Conditional Access policies that evaluate user risk, device compliance, and location before granting access.
- Microsoft Intune: Manages device compliance, enforces encryption and PIN requirements, and reports device health status to Conditional Access.
- Microsoft Defender for Business: Provides endpoint detection and response (EDR) capabilities, with threat signals feeding into device compliance status.
- Microsoft Purview: Enables data classification, sensitivity labels, and DLP policies to protect sensitive data.
- Conditional Access: The policy engine that ties everything together — evaluating identity, device, location, and risk signals to make real-time access decisions.
Together, these tools implement the core zero trust principles without requiring a large IT team or significant capital investment. AMVIA can typically deploy a baseline zero trust configuration for a 50-person business within two to four weeks.
A Practical Zero Trust Roadmap for UK SMEs
Implementing zero trust is a journey, not a single project. AMVIA recommends a phased approach that delivers security improvements at each stage:
Phase 1: Identity Foundation
Enforce MFA for all users — including shared mailboxes, service accounts, and admin accounts. Block legacy authentication protocols that cannot support MFA (these are the vector for 99%+ of password spray attacks). Configure Conditional Access policies to require MFA for all cloud applications.
Phase 2: Device Compliance
Enrol all devices in Microsoft Intune. Define and enforce compliance policies for encryption, PIN requirements, and minimum OS version. Configure Conditional Access to require device compliance as a condition of accessing Microsoft 365.
Phase 3: Application Access Controls
Review and restrict application access based on user roles. Remove unnecessary administrative privileges. Implement Privileged Identity Management for admin accounts requiring just-in-time elevation with approval workflows.
Phase 4: Data Protection
Deploy sensitivity labels on documents and emails. Configure DLP policies to prevent sensitive data from being shared inappropriately. Enable Microsoft Purview to classify and protect data based on its content and sensitivity.
Phase 5: Network Controls
Review network segmentation and implement microsegmentation where appropriate. Evaluate ZTNA solutions as a replacement or supplement for traditional VPN. Monitor east-west traffic for anomalous activity.
Zero Trust and Hybrid Working
Zero trust is specifically designed for the distributed work patterns that have become standard in UK businesses. Unlike perimeter security, which creates a security gap whenever users work outside the office, zero trust applies the same verification requirements regardless of the user's location. Whether an employee is in the office, at home, or in a coffee shop, every access request is evaluated against the same policy — identity verified, device compliance confirmed, risk level assessed.
This location-independent security model eliminates the security compromise that many businesses accepted when they adopted hybrid working. With zero trust properly implemented, remote work is exactly as secure as office-based work, because the security controls are tied to identity and device compliance rather than network location.
How AMVIA Can Help
AMVIA's Microsoft-certified engineers assess your current environment and design a pragmatic zero trust roadmap tailored to your business size, risk profile, and existing Microsoft 365 licensing. AMVIA implements zero trust controls using Microsoft's cloud-native security stack — Entra ID, Intune, Defender, and Purview — provides ongoing management through its managed cybersecurity service.
Whether you are starting from scratch or looking to mature an existing security posture, AMVIA provides the technical implementation and ongoing oversight to ensure your zero trust controls remain effective as your business and the threat landscape evolve. Contact AMVIA on 0333 733 8050 to discuss your zero trust readiness.
Zero Trust Capabilities AMVIA Deploys
We implement all six zero trust pillars using Microsoft's cloud-native security stack, configured and monitored by our certified engineers.
Passwordless Authentication
Deploy Windows Hello for Business, FIDO2 keys, or Microsoft Authenticator to eliminate password-based attack vectors entirely.
Conditional Access Policies
Enforce access rules based on user risk, device compliance, location, and application sensitivity — blocking suspicious sign-ins automatically.
Device Compliance Enforcement
Intune MDM ensures only compliant, managed devices can access corporate data. Non-compliant or personal devices are limited to approved resources only.
Data Classification & DLP
Microsoft Purview automatically classifies sensitive data and enforces policies preventing exfiltration via email, USB, or cloud uploads.
Zero Trust Implementation Checklist
Key milestones for a zero trust migration — use this to track your readiness or share with your IT provider.
MFA enforced for all users
Including shared mailboxes, service accounts, and admin accounts.
Conditional Access policies active
At minimum: block legacy authentication and require compliant devices for sensitive apps.
Device management deployed
All corporate devices enrolled in Microsoft Intune with compliance policies applied.
Privileged Identity Management enabled
Admin roles require just-in-time elevation with approval workflow and audit logging.
Data classification labels applied
Sensitivity labels on emails and documents; DLP policies active in M365.
Network segmentation reviewed
Internal network segmented; East-West traffic monitored; VPN replaced or supplemented with ZTNA.
Zero Trust FAQs
Yes — in fact, cloud-first SMEs are often better positioned to adopt zero trust than large enterprises with legacy infrastructure. Microsoft 365 Business Premium includes most of the tools needed to implement a strong zero trust posture. AMVIA can typically deploy a baseline zero trust configuration for a 50-person business within two to four weeks.
Not necessarily. In the short term, zero trust network access (ZTNA) can coexist with a VPN. However, many businesses do eventually replace their VPN with ZTNA solutions such as Microsoft Entra Private Access, which provide application-level access controls rather than blanket network access. We advise a phased transition rather than a hard cutover.
Zero trust is specifically designed for distributed work patterns. Unlike perimeter security, it doesn't matter whether a user is in the office, at home, or in a coffee shop — every access request is verified the same way. This eliminates the security gap that hybrid working creates in traditional network architectures.
Ready to Modernise Your Security Architecture?
Our Microsoft-certified engineers will assess your current environment and design a pragmatic zero trust roadmap tailored to your business size and risk profile.
Related Guides
The Complete Guide to Cybersecurity for UK SMEs
A comprehensive overview of cyber threats, protective controls, and compliance frameworks for UK businesses.
Microsoft 365 Business Premium vs E5
Comparing the zero trust capabilities included in each licence tier to find the right fit for your business.