Somewhere in the last year, someone told you that you need Zero Trust. Maybe it was an auditor, or a cyber-insurance renewal form with a new checkbox, or an enterprise customer's security questionnaire that ran to forty tabs. So you looked into it, and every quote that came back assumed you were buying a platform. For a company your size, that assumption is the actual problem.
Zero Trust is one of the most oversold ideas in security, and the overselling points in one direction: toward a purchase. This is the version where you spend as close to nothing as the work allows, because for a business somewhere between 25 and 250 people, most of Zero Trust is a configuration project wearing a procurement costume.
It's a strategy, not a SKU
Strip the vendor gloss and Zero Trust is one idea: stop trusting anything just because it sits inside your network. Every request to reach something sensitive gets checked on its own merits, every time, whether it comes from the corner office or a coffee shop in another time zone. NIST's reference architecture lays this out over dozens of pages, and Canada's own Cyber Centre says the same thing in plainer words: no user, device, or application is trusted by default.
None of that is something you can buy or download. What vendors sell you are pieces that help, and some of those pieces are genuinely good, though the strategy itself is really a way of configuring and operating what you already run. That is lucky, because you run more of it than you probably think.
You already bought most of it
The quotes tend to leave out an awkward fact. For a small company, the core Zero Trust controls are usually sitting in the licences you already pay for every month.
If you are on Microsoft 365 Business Premium, you have Entra ID P1 for conditional access, Intune to manage devices, and Defender for Business for endpoint detection. That is identity, device, and endpoint control, in the box, already billed. If you are on Google Workspace, you have two-step verification on every plan, endpoint management, and context-aware access on the higher tiers. A small business on either stack can get most of the way to Zero Trust without a single new subscription.
What is missing almost always isn't a tool. It is that nobody has turned these controls on, in the right order, and kept them on. That is a less exciting sentence than "buy our platform," which is roughly why you don't hear it from the people selling platforms.
The order to switch things on
Zero Trust has a rough map. CISA's maturity model breaks it into five pillars: identity, devices, networks, applications, and data. You don't tackle them all at once, and you don't tackle them in that reading order. You start where the attackers actually are.
Identity comes first, because that is where the break-ins happen. Turn on multi-factor authentication everywhere, and make it phishing-resistant where you can, because the SMS code your bank still texts you can be phished in real time. Switch off the legacy sign-in protocols that skip MFA entirely. Set conditional access so a login from a managed laptop in Toronto is treated differently from one on a brand-new device in a country you have never operated in. Then look at who holds administrator rights and take them away from everyone who does not need them today. Standing admin access is the prize attackers hope to find, and identity sprawl is usually how they find it.
Devices come next. A device should be known and healthy before it reaches your data, which means enrolled in management, disk encrypted, screen locking, and patched. An unmanaged personal laptop with your CRM open on it is a gap that no firewall closes.
Applications come after that. Put single sign-on in front of what you can, so access gets granted and revoked in one place instead of twelve. Turn new access policies on in report-only mode first, watch who they would have blocked for a week or two, and only then enforce them. That one habit prevents the classic Zero Trust rollout where you lock the CEO out of email on a Monday and lose the mandate by Tuesday.
Networks come later than the vendor diagrams suggest. You probably do not need micro-segmentation on day one. You do need to stop running one flat network where the guest wifi can see the accounting server, and to move remote access off a plain VPN toward something that checks identity and device health on the way in.
Data comes last, and it is the hardest, because it forces you to actually know what you have. Find where the sensitive material lives, cut the access nobody is using, and encrypt what remains. This is also, not by coincidence, where you learn how far your mental map has drifted from reality.
Underneath all five, two things run quietly: turn on the logging you are already paying for so you can see what is happening, and write down who can reach what, so "least privilege" is a document you can show someone and not a vibe.
What it actually costs
None of this is free, and pretending otherwise is how these projects lose the room. A handful of things do carry a real bill. Phishing-resistant hardware keys run a few dollars a head, which is cheap without being nothing. If your stack does not already include endpoint detection, you will want to add it. The biggest cost by a wide margin is time, because someone has to configure these controls, test them, and keep them tuned as the business changes. That someone needs to know what they are doing, because a conditional-access rule written badly stops being a control and turns into an outage.
It is worth being precise about the claim here. You are not buying a Zero Trust platform, you are switching on capabilities you already own and paying for the expertise to turn them on without breaking things. For a lot of small companies that works out to a project measured in weeks plus a bit of outside help, rather than a new five-figure line on the budget.
Ninety days, not a weekend
You never really finish Zero Trust, you start it and then you maintain it, the same way you maintain everything else. The first ninety days still do most of the work, and that means MFA everywhere, legacy auth switched off, admin rights trimmed back, devices managed, and the riskiest access policies enforced after a stint in report-only. That stretch closes the attack paths that real breaches actually use. The fully-automated, optimal-maturity version CISA describes is a multi-year road, and most small businesses never need to reach the far end of it. Getting off the starting line is where the risk drops fastest.
Where to actually start
Before you buy anything, and before you start flipping switches, it helps to know where you actually stand. "We have MFA" is not the same as knowing that MFA covers every account, that admin access is scoped, that your devices are managed, and that you could show all of it to an auditor without flinching. Those are specific, checkable things, and they line up almost one to one with the controls in a framework like NIST CSF.
We built NISTForge to give you exactly that: a read of where you stand against NIST CSF, control by control, so you can see which parts are thin before you flip a switch or sign a cheque. It runs on your own infrastructure, so the map of your gaps never leaves your network to get drawn, which for a document that catalogues your soft spots is the entire point. (We have written about why at more length.) The public beta lands this summer and the waitlist is open now, with founder pricing held for the teams who get in early. If you would rather have someone sequence the rollout with you than work from a report, that is what our team is for.
Either way, the core of it holds up. For a small company, Zero Trust is mostly a decision to use what you already own, in the right order and on purpose. The invoice you were quoted for it is optional, and the work that remains is a great deal smaller than it first looked.