Zero trust network architecture is a security model that stops treating your network as a trusted place. Every user, every device and every request is authenticated and authorized before it reaches an application, and the access granted is only what that task needs. You implement it in stages, starting with identity and multi-factor authentication, then application-level access, then segmentation, and you can get most of the benefit in the first two.
The reference definition is NIST Special Publication 800-207, published August 2020. The federal maturity roadmap most vendors are quietly working from is the CISA Zero Trust Maturity Model version 2.0, April 2023. Both are free to read, and both are more useful than a vendor deck.
Los Angeles based since 2007 · Channel Futures MSP 501 ranked · CA License #1140088
Zero trust network architecture, defined
Traditional network security was perimeter based: build a wall with antivirus and intrusion protection at the edge, and trust everything inside it. That model assumed the attacker was outside. Cloud applications, remote staff, personal phones and stolen credentials all broke that assumption, because they put untrusted things inside the wall and trusted things outside it.
Zero trust removes location from the trust decision. A laptop on your office network gets no more implicit access than a laptop in a coffee shop. Each request is evaluated against who the user is, what device they are on, what they are asking for, and whether anything about the session looks wrong. The technologies behind that decision are ones you probably already own in part: multi-factor authentication, identity and access management, conditional access policy, device posture checks, encryption, and logging.
Zero trust network access (ZTNA) is the piece that replaces the old flat VPN. Instead of dropping a connected user onto your whole network, ZTNA connects a verified user to one named application, and treats each session as its own auditable event. Lateral movement, which is how a single compromised laptop turns into a company-wide incident, is what this closes.
Is zero trust worth it for a business under 200 employees?
Yes, in the order below, and no if you try to buy it as a single product.
Zero trust is worth doing when any of these is true: you have staff working outside the office; you have a VPN that grants broad network access once someone is on it; you hold regulated data; a client, an insurer or a prime contractor has started asking about access controls; or you have contractors and seasonal staff whose access nobody has reviewed in a year.
It is not worth doing as a rip and replace. Any provider proposing to rebuild your network before touching your identity provider has the order backwards. Identity is where the return is.
How do you implement zero trust, in stages?
- Identity first. Multi-factor authentication on everything, single sign-on where possible, and conditional access rules that consider device and location. This is the cheapest stage and it closes the most common way businesses get breached.
- Device posture. Only managed, patched, encrypted devices get access. This is where mobile device management and endpoint management stop being paperwork and start being an access control.
- Application-level access. Replace or wrap the flat VPN so people connect to applications, not to the network. Each session is verified and logged.
- Least privilege. Review who has administrative rights, remove standing access nobody needs, and put the rest behind approval.
- Segmentation. Separate the things that do not need to talk to each other: servers, workstations, guest wireless, printers, cameras, building systems.
- Monitoring and continuous evaluation. Sessions get reassessed as conditions change, and the logs feed a place where somebody reads them. Periodic penetration testing is how you find out whether the model holds.
Stages one and two are usually weeks, not quarters, and they are where most of the risk reduction sits. Stages three through six follow your budget and your renewal dates.
What changes on day one?
For your staff: a sign-in prompt that asks for a second factor, and, if their laptop is out of date, a message telling them to install updates before they can reach a business application. That is most of what a well-run rollout feels like from a desk.
For your IT team: one place to see who accessed what, from which device, and when. Offboarding becomes a single revocation instead of a checklist across nine systems.
What we plan around: the applications that do not support modern authentication, the legacy line-of-business tool that needs a flat network path, and the executive who travels. These are known problems with known workarounds, and they are the reason a staged rollout beats a flag day.
What zero trust costs, and what it replaces
Most of zero trust is configuration of licenses you already pay for, not new hardware. Microsoft 365 business plans include conditional access and device compliance at the higher tiers, and moving up a tier is often cheaper than the separate products it replaces. Where new spend appears, it is usually a ZTNA service that retires a legacy VPN concentrator, or endpoint management for devices that were never enrolled.
At Be Structured, the access-control half of this work sits inside managed security, priced per device, commonly $50 per device per month for the full stack, which includes multi-factor authentication, Windows Defender hardening and LAPS, EDR with 24/7 SOC monitoring, and dark web monitoring. Managed IT runs $125 to $300 per user per month depending on headcount and coverage. Design and migration work outside the recurring scope is quoted in advance. See our managed IT services cost page for the full breakdown.
How to evaluate a provider that says it does zero trust
- Ask which NIST 800-207 components they are actually implementing. A provider who cannot name the policy engine, policy administrator and policy enforcement point is selling a product, not an architecture.
- Ask what they would do first in your environment, and why. If the answer is not identity, ask them to defend the order.
- Ask what breaks. Every honest rollout has a list of applications that need exceptions. A provider who says nothing will break has not looked.
- Ask how access gets reviewed after go-live. Zero trust decays the moment nobody reviews privilege.
- Ask what happens to the VPN. Running both indefinitely means you paid for zero trust and kept the hole.
- Ask for the logging story. Continuous verification without somebody reading the output is just extra prompts for your staff.
Zero trust work from Be Structured, in Los Angeles
Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA. We design and implement zero trust in the order above, on the licenses you already hold where that is possible, and we keep backup and recovery for remote work in scope while we do it, because access control and recovery fail together when they fail at all.
As one of the cybersecurity companies Los Angeles businesses can evaluate locally, we would rather scope your identity platform first than quote you a network rebuild.
➤ Get Your Free IT Assessment: contact Be Structured to schedule a zero trust readiness assessment, or call (323) 331-9452.
