Practical Steps and Pitfalls When Moving to Zero Trust

Zero Trust is an approach, not a product. Skipping the theory, we plan phase by phase how a 200-person company can move to a Zero Trust model in 12 months.

Practical Steps and Pitfalls When Moving to Zero Trust

Traditional network security was built like a castle: outside dangerous, inside safe. Anyone on the VPN or office network was "inside" and trusted broadly. Cloud apps, remote work and personal devices made those walls meaningless, and attackers learned to steal one credential and move freely inside.

Zero Trust reverses the assumption: network location is not enough for trust. Every access request is evaluated each time based on who you are, which device you use and what you're trying to do.

We keep the theory short and build a workable roadmap for a typical 200-person hybrid company with office servers and cloud apps.

First, a misconception

Zero Trust isn't a product you buy. Vendors sell pieces of it (identity, access, segmentation). The model described in NIST SP 800-207 is a policy decision system spanning identity, device, network, application and data.

Starting point: Company X

  • 200 employees, half remote at least two days a week,
  • Active Directory, a file server and an ERP in the office,
  • Microsoft 365, a CRM and several SaaS apps,
  • Classic VPN where everyone sees the whole internal network,
  • MFA only on email, and optional.

Phase 1 (months 0–3): Visibility and identity

  1. Asset inventory of users, devices, apps and data stores, surfacing shadow IT.
  2. Single identity provider with SSO for as many apps as possible.
  3. MFA for everyone, no exceptions; phishing-resistant methods (FIDO2 keys, passkeys) for admins and finance.
  4. Disable legacy protocols that bypass MFA.
Quick win

This phase alone neutralises most credential-theft attacks. It's the highest-return step of the journey.

Phase 2 (months 3–6): Device trust

  • Enrol company devices in MDM/UEM.
  • Define minimum device health: disk encryption, current OS, running EDR agent.
  • Introduce conditional access: "Finance apps only from managed, compliant devices."
  • Limited, browser-only access for personal devices.

Phase 3 (months 6–9): From VPN to per-application access

  • Put internal apps behind a ZTNA tool or identity-aware proxy.
  • Users see only the apps they're authorised for; the rest of the network is invisible.
  • Migrate gradually and run the VPN in parallel until the last app moves.

Phase 4 (months 9–12): Segmentation and least privilege

  • Micro-segmentation by business function.
  • Privileged access management with just-in-time admin rights.
  • Quarterly access reviews by team managers.
  • Continuous monitoring of identity and access logs for anomalies.

Common pitfalls

1. Doing everything at once

Big-bang rollouts cause resistance and outages. Go in phases and share the measured benefit of each.

2. Forgetting user experience

MFA on every click pushes users to workarounds. Use risk-based prompts.

3. Ignoring legacy systems

Isolate systems that can't do modern auth and reach them only through a tightly controlled jump host.

4. Set and forget

Unreviewed policies fill with exceptions until you're back to the castle.

5. Not measuring

Track MFA coverage, managed device ratio, apps moved off VPN and standing admin accounts.

Roadmap summary

PeriodFocusSuccess metric
Months 0–3Inventory, SSO, MFA for all100% MFA coverage
Months 3–6Device management, conditional accessCritical apps only from compliant devices
Months 6–9ZTNA, leaving VPNMost internal apps behind ZTNA
Months 9–12Segmentation, PAM, monitoringNear-zero standing admin accounts

Conclusion

Zero Trust isn't a one-year project but a lasting change in security culture, yet with the right sequence you see measurable risk reduction within three months. For an assessment and a tailored roadmap, see our cyber security consulting.

  • #zero trust
  • #sıfır güven
  • #kimlik yönetimi
  • #MFA
  • #mikro segmentasyon

Are your systems truly secure?

Message us today for a free initial consultation. Let's assess your needs together.

Get a Quote

Related posts