Zero trust network architecture is a security model that stops treating your network as a trusted place. Every user, every device and every request is authenticated and authorized before it reaches an application, and the access granted is only what that task needs. You implement it in stages, starting with identity and multi-factor authentication, then application-level access, then segmentation, and you can get most of the benefit in the first two.

The reference definition is NIST Special Publication 800-207, published August 2020. The federal maturity roadmap most vendors are quietly working from is the CISA Zero Trust Maturity Model version 2.0, April 2023. Both are free to read, and both are more useful than a vendor deck.

Los Angeles based since 2007 · Channel Futures MSP 501 ranked · CA License #1140088

Zero trust network architecture, defined

Traditional network security was perimeter based: build a wall with antivirus and intrusion protection at the edge, and trust everything inside it. That model assumed the attacker was outside. Cloud applications, remote staff, personal phones and stolen credentials all broke that assumption, because they put untrusted things inside the wall and trusted things outside it.

Zero trust removes location from the trust decision. A laptop on your office network gets no more implicit access than a laptop in a coffee shop. Each request is evaluated against who the user is, what device they are on, what they are asking for, and whether anything about the session looks wrong. The technologies behind that decision are ones you probably already own in part: multi-factor authentication, identity and access management, conditional access policy, device posture checks, encryption, and logging.

Zero trust network access (ZTNA) is the piece that replaces the old flat VPN. Instead of dropping a connected user onto your whole network, ZTNA connects a verified user to one named application, and treats each session as its own auditable event. Lateral movement, which is how a single compromised laptop turns into a company-wide incident, is what this closes.

Is zero trust worth it for a business under 200 employees?

Yes, in the order below, and no if you try to buy it as a single product.

Zero trust is worth doing when any of these is true: you have staff working outside the office; you have a VPN that grants broad network access once someone is on it; you hold regulated data; a client, an insurer or a prime contractor has started asking about access controls; or you have contractors and seasonal staff whose access nobody has reviewed in a year.

It is not worth doing as a rip and replace. Any provider proposing to rebuild your network before touching your identity provider has the order backwards. Identity is where the return is.

How do you implement zero trust, in stages?

  1. Identity first. Multi-factor authentication on everything, single sign-on where possible, and conditional access rules that consider device and location. This is the cheapest stage and it closes the most common way businesses get breached.
  2. Device posture. Only managed, patched, encrypted devices get access. This is where mobile device management and endpoint management stop being paperwork and start being an access control.
  3. Application-level access. Replace or wrap the flat VPN so people connect to applications, not to the network. Each session is verified and logged.
  4. Least privilege. Review who has administrative rights, remove standing access nobody needs, and put the rest behind approval.
  5. Segmentation. Separate the things that do not need to talk to each other: servers, workstations, guest wireless, printers, cameras, building systems.
  6. Monitoring and continuous evaluation. Sessions get reassessed as conditions change, and the logs feed a place where somebody reads them. Periodic penetration testing is how you find out whether the model holds.

Stages one and two are usually weeks, not quarters, and they are where most of the risk reduction sits. Stages three through six follow your budget and your renewal dates.

What changes on day one?

For your staff: a sign-in prompt that asks for a second factor, and, if their laptop is out of date, a message telling them to install updates before they can reach a business application. That is most of what a well-run rollout feels like from a desk.

For your IT team: one place to see who accessed what, from which device, and when. Offboarding becomes a single revocation instead of a checklist across nine systems.

What we plan around: the applications that do not support modern authentication, the legacy line-of-business tool that needs a flat network path, and the executive who travels. These are known problems with known workarounds, and they are the reason a staged rollout beats a flag day.

What zero trust costs, and what it replaces

Most of zero trust is configuration of licenses you already pay for, not new hardware. Microsoft 365 business plans include conditional access and device compliance at the higher tiers, and moving up a tier is often cheaper than the separate products it replaces. Where new spend appears, it is usually a ZTNA service that retires a legacy VPN concentrator, or endpoint management for devices that were never enrolled.

At Be Structured, the access-control half of this work sits inside managed security, priced per device, commonly $50 per device per month for the full stack, which includes multi-factor authentication, Windows Defender hardening and LAPS, EDR with 24/7 SOC monitoring, and dark web monitoring. Managed IT runs $125 to $300 per user per month depending on headcount and coverage. Design and migration work outside the recurring scope is quoted in advance. See our managed IT services cost page for the full breakdown.

How to evaluate a provider that says it does zero trust

  1. Ask which NIST 800-207 components they are actually implementing. A provider who cannot name the policy engine, policy administrator and policy enforcement point is selling a product, not an architecture.
  2. Ask what they would do first in your environment, and why. If the answer is not identity, ask them to defend the order.
  3. Ask what breaks. Every honest rollout has a list of applications that need exceptions. A provider who says nothing will break has not looked.
  4. Ask how access gets reviewed after go-live. Zero trust decays the moment nobody reviews privilege.
  5. Ask what happens to the VPN. Running both indefinitely means you paid for zero trust and kept the hole.
  6. Ask for the logging story. Continuous verification without somebody reading the output is just extra prompts for your staff.

Zero trust work from Be Structured, in Los Angeles

Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA. We design and implement zero trust in the order above, on the licenses you already hold where that is possible, and we keep backup and recovery for remote work in scope while we do it, because access control and recovery fail together when they fail at all.

As one of the cybersecurity companies Los Angeles businesses can evaluate locally, we would rather scope your identity platform first than quote you a network rebuild.

➤ Get Your Free IT Assessment: contact Be Structured to schedule a zero trust readiness assessment, or call (323) 331-9452.

Frequently Asked Questions About Zero Trust

What is zero trust network architecture?

Zero trust network architecture is a security model that removes location from the trust decision. Every user, device and request is authenticated and authorized before reaching an application, and the access granted is limited to what the task needs. The reference definition is NIST Special Publication 800-207, published in August 2020.

What is the difference between zero trust and a VPN?

A traditional VPN authenticates you once and then drops you onto the network, where you can usually reach far more than your job requires. Zero trust network access connects a verified user to one named application instead, and treats each session as its own auditable event. That difference is what closes lateral movement, which is how one compromised laptop becomes a company-wide incident.

Where do you start with zero trust?

Identity. Multi-factor authentication everywhere, single sign-on where possible, and conditional access rules that consider device and location. Stage two is device posture: only managed, patched, encrypted devices get access. Those two stages are usually weeks rather than quarters, and they hold most of the risk reduction. Application-level access, least privilege, segmentation and continuous monitoring follow.

Does a small business need zero trust, or is it an enterprise thing?

It applies at small scale, because the conditions that broke the perimeter model apply at small scale: remote staff, cloud applications, personal phones, contractors, and stolen credentials. What changes with size is the budget and the sequencing, not the model. A ten-person firm can complete the identity and device stages on licensing it already owns.

How much does zero trust cost to implement?

Most of it is configuration of licenses you already pay for rather than new hardware. Microsoft 365 includes conditional access and device compliance at the higher business tiers, and moving up a tier is often cheaper than the separate products it replaces. At Be Structured the access-control half sits inside managed security, priced per device and commonly $50 per device per month for the full stack, on top of managed IT at $125 to $300 per user per month. Design and migration work is quoted in advance.

What will our staff notice after a zero trust rollout?

A sign-in prompt asking for a second factor, and, if their laptop is out of date, a message telling them to install updates before they can reach a business application. That is most of what a well-run rollout feels like from a desk. Your IT team notices more: one place to see who accessed what from which device, and offboarding that becomes a single revocation instead of a checklist across nine systems.

What usually breaks during a zero trust project?

Applications that do not support modern authentication, a legacy line-of-business tool that expects a flat network path, and users who travel. These are known problems with known workarounds, and they are the reason we roll out in stages instead of on a single cutover date. Any provider who tells you nothing will break has not looked at your application list.

How do we evaluate a provider that says it does zero trust?

Ask which NIST 800-207 components they are implementing and have them name the policy engine, policy administrator and policy enforcement point. Ask what they would do first in your environment, and expect identity. Ask what will break. Ask how access gets reviewed after go-live. Ask what happens to the existing VPN, because running both indefinitely means paying for zero trust and keeping the hole. Ask who reads the logs.

Is zero trust required for compliance?

It is not a certification you pass. It is an architecture that makes the access-control requirements in HIPAA, PCI DSS, CMMC and the FTC Safeguards Rule straightforward to evidence, because the logging falls out of the design. Federal agencies work to the CISA Zero Trust Maturity Model version 2.0, published April 2023, and private-sector security questionnaires increasingly borrow its language. We help you meet the requirements; we do not issue the certification itself.