
You have probably heard the phrase zero trust, usually from a vendor trying to sell you something. Strip away the marketing and it is one of the clearest ideas in security: trust nothing automatically, and check every request before you grant access. For a small business, zero trust is not a product you buy off the shelf. It is a way of setting up the tools you already have so that a single stolen password does not hand an attacker the run of your business.
The Australian Signals Directorate’s Cyber Security Centre (ACSC) now treats zero trust as a core part of what it calls modern defensible architecture, published in 2025 as a companion to the Essential Eight. This guide explains what the model means in plain English, why it matters for a business of any size, and the practical steps you can take without a large budget or a dedicated IT team.
What zero trust actually means
Traditional security worked a bit like a castle. You built a strong wall around the office network, put a firewall at the gate, and trusted almost anyone inside. Once a person or device was on the network, they could reach most things with little further checking.
Zero trust throws out the idea of a trusted inside. The ACSC sums it up in three phrases: never trust, always verify; assume breach; and verify explicitly. In practice that means every request to reach a system or a file is checked, every time, based on who is asking, what device they are using, and whether the request makes sense. The network is treated as hostile until proven otherwise, so being connected to the office wi-fi no longer counts as permission to do anything.
It helps to think of zero trust as a mindset rather than a single piece of software. Every vendor sells a zero trust product, but no product delivers it on its own. The model is really a set of questions you ask before granting access: who is this, what are they using, where are they, and should they be allowed to do this right now? When those questions are answered automatically, by your identity system rather than by blind trust in the network, you are applying zero trust.
Why the castle and moat model fails
The wall around the office stopped being the boundary years ago. Your email, files and accounting system now live in the cloud. Staff log in from home, from phones and from cafes. Suppliers and contractors have accounts in your systems. There is no single gate left to guard.
Attackers know this. The most common break-in today is not someone smashing through a firewall; it is someone logging in with a password they phished, bought or guessed. Once they are in, a flat network with broad trust lets them move sideways, read inboxes, find more credentials and reach the data that matters. Zero trust is designed to make that first stolen login far less useful, because the login alone no longer unlocks everything.
The core principles
Zero trust rests on a handful of ideas that work together:
- Verify every request. Access is granted on live signals: the user’s identity, the health of their device, their location and the sensitivity of what they are reaching, not on the fact that they are already connected.
- Assume you will be breached. Design systems so that one compromised account or device causes limited damage, rather than hoping no breach ever happens.
- Give the least access needed. People and systems get only the permissions required for the job, and nothing more. This overlaps directly with restricting admin privileges, one of the Essential Eight.
- Check continuously. Trust is not granted once at login and then left alone. It is re-checked as conditions change, so an account that starts behaving oddly can be challenged or cut off.
- Segment the network. Break systems into smaller zones so a problem in one area cannot spread freely to the rest.
What zero trust looks like for a small business
You do not need an enterprise security budget to apply these ideas. Much of zero trust is about using the identity and access controls you may already own, particularly if you run Microsoft 365 or Google Workspace.
The foundation is strong identity. Multi-factor authentication on every account is the single biggest step, because it means a stolen password on its own is not enough to log in. From there, conditional access rules let you add checks such as blocking sign-ins from countries you never operate in, or requiring a managed, up-to-date device before granting access to sensitive data.
Least privilege is the next piece. Review who can reach what, remove access people no longer need, and keep the number of administrator accounts as small as possible. Everyday work should happen on standard accounts, with admin rights used only when they are genuinely required.
Device health is the part many small businesses overlook. A login from a laptop that is patched, running security software and known to your business is far safer than the same login from an unknown personal device. Microsoft 365 and Google Workspace can factor this in, so that reaching sensitive data from an unmanaged device triggers an extra check or is blocked outright. You do not have to enforce every rule on day one. Start with your most sensitive systems and widen the net over time.
Where zero trust meets the Essential Eight
Zero trust and the Essential Eight are not competing frameworks. The ACSC positions zero trust architecture alongside the Essential Eight and the Information Security Manual, and several of the Essential Eight controls are really zero trust ideas in practice.
Multi-factor authentication is a zero trust control: it verifies the person, not just the password. Restricting administrative privileges is least privilege in action. Application control, which only lets approved software run, applies the “never trust” idea to programs rather than people. If you are already working through the Essential Eight, you are further along the zero trust path than you might think.
How to start without a big budget
You can make meaningful progress in a few focused steps:
- Turn on multi-factor authentication everywhere, starting with email, remote access and any account that holds admin rights.
- Write down who has access to your key systems, then remove anything that is not needed and cut the number of admin accounts.
- Use the conditional access or security defaults built into Microsoft 365 or Google Workspace to require MFA and block risky sign-ins.
- Keep staff devices patched and up to date, and prefer access from managed devices for your most sensitive data.
- Separate your most sensitive systems from everyday ones, so trouble in one place does not reach the rest.
- Review access whenever someone changes role or leaves, so old permissions do not quietly linger.
None of these needs a rip-and-replace project. Zero trust is a direction of travel, not a switch you flip, and every step shrinks the damage a single stolen login can do.
Find out where you stand
Not sure how much of this your business already has in place? Our free self-assessment walks you through 27 plain-English questions and maps your answers to the ACSC Essential Eight, ISO 27001 and SOC 2. It takes about five to ten minutes and gives you an instant, personalised PDF report that shows where you are strong and where to focus next. Take the free assessment at securityscore.com.au and see exactly where your business stands.