Zero Trust Architecture
Zero trust architecture aligned to NIST 800-207: identity-first access, least privilege, micro-segmentation and ZTNA, rolled out in stages. Free scoping call.
Zero trust architecture replaces the old idea of a trusted internal network with a simple rule: verify every user, device and request, every time, and grant only the access that specific job needs. We help you design and roll it out in practical stages, so a phished password or a compromised laptop no longer opens your whole environment, it hits a wall of checks and gets almost nothing.
SafetyBis is a European offensive-security team. We design and validate zero trust programs for organisations across Europe and remotely worldwide, and we come at it from the angle that matters: how an attacker moves once they are inside. In most breaches we help investigate, the initial foothold was small. The damage came from lateral movement across a flat network where one set of credentials reached everything. Zero trust is the discipline that closes that door.
What zero trust architecture actually covers
Zero trust is not a product you buy, whatever a vendor tells you. It is an architecture and a set of principles, defined most clearly in NIST SP 800-207, that you apply across identity, devices, networks, applications and data. The core idea is that trust is never granted by location. Being on the corporate LAN or VPN earns you nothing; every access decision is made fresh, based on who you are, what device you are on, and what you are trying to reach.
The policy engine at the centre
Zero trust runs on a decision loop: a policy engine evaluates each request against your rules, a policy administrator issues or denies the access, and a policy enforcement point sits in front of the resource to carry out the verdict. In NIST’s terms that is the PDP and PEP. In plain terms, nothing reaches a resource without a fresh yes based on current context, and that yes can be revoked the moment the context changes.
Why “verify every time” beats a strong perimeter
The traditional model built a hard shell and a soft centre: get past the firewall and you were trusted. Attackers love that, because one phished credential or one vulnerable edge device puts them inside the trusted zone with room to roam. Zero trust removes the soft centre. There is no inside to reach, only a series of individually guarded resources, each asking who you are and why you should be let in.
How we roll out zero trust in practice
The mistake that sinks zero trust programs is trying to do everything at once and disrupting the business. We work in stages, starting where the risk-to-effort ratio is best, and we prove each step before moving on. Zero trust architecture best practices are as much about sequencing as about technology.
Identity and MFA first
Identity is the foundation, so it comes first. We strengthen authentication with phishing-resistant MFA, implement conditional access that factors in device, location and risk, and clean up the accounts and privileges that have accumulated over the years. This alone stops the most common attack, a stolen password, from being enough.
Least privilege and access review
Next we cut standing access down to what each role actually needs, remove the dormant admin rights nobody remembers granting, and move toward just-in-time elevation for privileged tasks. The aim is that a compromised account is worth far less, because it can reach far less.
Segmentation and ZTNA
Then we tackle the network. Micro-segmentation isolates workloads so an attacker who lands in one place cannot pivot freely, and ZTNA replaces broad VPN access with connections brokered per application after verification. A VPN typically drops a user onto the network; ZTNA connects them only to the one app they are cleared for and nothing else.
Continuous verification, not one-and-done
A zero trust decision is not permanent. Sessions are re-evaluated as context changes, and access is pulled when a device falls out of compliance, a login looks risky, or behaviour turns anomalous. This continuous check is what turns zero trust from a login gate into a live control.
Data-centric access and the third stage
The final layer is the data itself. Even with strong identity and a segmented network, access to sensitive information should depend on classification and need, not on having reached the right server. We help you tie access decisions to data sensitivity, so the records that matter most sit behind the tightest checks and every read is attributable. This is the part most rollouts never reach, and it is often where the highest-value data quietly stays over-exposed long after the network work is done.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What zero trust actually prevents
The point of all this is a concrete change in what an attacker can achieve. It helps to be specific about that.
Lateral movement
An attacker who compromises one workstation in a flat network can often reach file shares, servers and eventually a domain controller. Under segmentation and least privilege, that same foothold is boxed in: it can see one segment, hold one role’s permissions, and reach nothing else without passing another verified gate. Most breaches become incidents at the lateral-movement stage, and this is where zero trust bites hardest.
Credential theft and reuse
Phishing-resistant MFA and conditional access mean a stolen password is not enough on its own, and a token lifted from one device does not work from an attacker’s. The single most common breach path gets far narrower, and the value of any one stolen secret drops sharply.
Why an offensive team designs it better
Anyone can draw a zero trust diagram. Building one that actually stops an attacker, and proving it does, is a different job, and it is one we can test.
We attack the design
Because we run authorised red-team and lateral-movement exercises, we know where zero trust rollouts leave gaps: the service account with excessive rights that segmentation forgot, the legacy app that bypasses the policy engine, the emergency access path that undoes the whole model. We design with those failure modes in mind, and we can test the finished architecture by trying to move through it.
Pragmatic, not purist
A textbook zero trust rollout that grinds the business to a halt gets rolled back, and then you have nothing. We sequence the work so each stage delivers real risk reduction on its own, and we make the trade-offs that keep users productive. Security that people route around is not security.
Where SASE fits
For distributed and remote-first organisations, zero trust network access often pairs with a broader secure access service edge approach that folds networking and security into one cloud-delivered layer. We help you decide whether that consolidation is worth it for your size and estate, rather than assuming the biggest platform is the right answer.
Zero trust in regulated and financial services
For regulated firms this is no longer just good practice, it is increasingly expected, and it maps neatly onto the frameworks you already answer to.
Compliance alignment
Zero trust supports ISO 27001 access-control objectives (A.5.15, A.8.2, A.8.3), SOC 2 logical-access criteria, GDPR’s expectation of least-privilege access to personal data, and DORA’s requirements around access management and operational resilience. Zero trust architecture in financial services also answers the supervisory pressure to limit the blast radius of any single compromise. We document the design so it satisfies both the technical bar and the auditor.
Evidence of control
Because every access decision is logged and policy-driven, you can show exactly who could reach what and why, which is precisely the evidence regulators and enterprise customers ask for.
Pricing
Zero trust architecture cost depends on the size of your estate, how many users and applications are in scope, and how much of the design and rollout you want us to run versus advise on. Below is the shape of a typical monthly engagement; larger transformations are scoped as projects. We work with the identity and network tooling you already have wherever possible.
| Plan | What’s covered | Response | Price per month |
|---|---|---|---|
| Starter | Zero trust assessment and roadmap, identity and MFA hardening, conditional access design, quick-win least-privilege cuts | Business-hours advisory | from €250/month |
| Growth | Staged rollout support across identity, access review and initial segmentation, ZTNA design, policy definition, monthly progress reviews | Same-day advisory support | from €450/month |
| Enterprise | Full architecture across micro-segmentation and ZTNA, continuous verification, device posture, adversarial validation of the design | Priority support, hands-on rollout | from €900/month |
| Managed retainer | Ongoing zero trust program with a named architect, policy tuning as you grow and testing that the model still holds | Retained with agreed SLA | from €800/month |
| Custom / large estate | Enterprise transformation or a SASE consolidation, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, so there are no hourly surprises. Get a fixed quote
FAQ
How much does a zero trust architecture cost?
Is zero trust a product we buy?
Where should we start?
What is the difference between ZTNA and a VPN?
Will zero trust disrupt our users?
How does zero trust stop lateral movement?
Does zero trust help with ISO 27001 or DORA?
Can you test that our zero trust design actually works?
Related services
Organisations with remote and hybrid workers, sensitive data, and a network still built on the old trusted-inside model: financial and professional-services firms under DORA, healthcare and SaaS companies protecting regulated data, and any business that has grown into a flat network where one compromised account reaches too much. If a single phished login would be a very bad day, zero trust is the fix.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.