Skip to content
Back to blogcybersecurity

Zero Trust Security for SMEs: What It Actually Means

Wanzo Team·2026-03-17·4 min read
Zero Trust Security for SMEs: What It Actually Means

Zero Trust treats every request for access as unproven until checks have passed. Sitting on the office network doesn't grant a free pass. The request is inspected against identity, the state of the device and the sensitivity of what is being asked for.

Where traditional network security fails

Older designs drew a line around the office. Users and devices inside that line were treated as safe. Everything outside was not. The firewall marked the line.

That design comes apart when:

  • People work from home or from other sites
  • Data sits in cloud services rather than on an office server
  • Personal phones and laptops reach company files
  • Attackers get past the firewall, which they do more often than most firms plan for

Once they're inside a trusted network, they can often reach neighbouring systems without another check.

The three principles

1. Verify explicitly

Every access request is authenticated and authorised using the evidence to hand: the user's identity, the health of the device, the location, the application involved and how sensitive the resource is.

In practice, this means:

  • Multi-factor authentication on every account
  • Conditional access policies that raise the checks at sign-in if the device is new or the location is unfamiliar
  • Device compliance checks covering encryption, updates and management status

2. Least privilege access

Staff receive only the permissions their job requires. Shared administrator accounts are removed. Permissions handed out for convenience, rather than for the role, are taken back.

In practice:

  • Role-based access control (RBAC) on every system
  • Just-in-time administrator access, raised only for a defined task and only for a limited period
  • Regular reviews of who can reach what, and whether they still need it

3. Assume breach

Build the environment on the basis that an attacker may already have a foothold. Split the network. Watch for unusual behaviour. Keep a response plan that has been tested.

In practice:

  • Network segmentation, with separate VLANs for staff, guests, servers and IoT
  • Endpoint detection and response (EDR) on every machine
  • Log monitoring and alerting
  • An incident response plan that is rehearsed, not filed away

Zero Trust with Microsoft 365

For firms on Microsoft 365 Business Premium, most of the tooling already sits inside the licence:

  • Azure AD Conditional Access for explicit verification
  • Intune for device compliance and management
  • Defender for Endpoint for the assume-breach layer (EDR)
  • Azure AD Privileged Identity Management for least privilege (full features need Azure AD Premium P2)

You don't need a new product for the core controls. You need the ones you already pay for switched on and set correctly.

What this means for automation

Workflow automation and AI agents make access requests too. An agent that processes invoices or answers routine tickets should have its own identity, a narrow set of permissions and the same conditional checks as a person. It should not inherit a global administrator role. If you're putting agents into existing processes, Zero Trust is the access model that keeps those permissions tight.

First steps

  1. Turn on MFA across every account. For most firms, this is the control that cuts the most risk first.
  2. Switch on conditional access. Refuse sign-ins from devices that fail your baseline, and from locations you have not seen before.
  3. Enrol devices in Intune. Every machine that reaches company data should meet the same security baseline.
  4. Cut the admin list. Fewer global administrators. Separate accounts for administrative work.
  5. Split the network. At a minimum, keep corporate devices apart from guest Wi-Fi and IoT.

How Wanzo applies Zero Trust

We set these controls as part of our managed IT service, which includes cybersecurity. On Microsoft 365 Business Premium we turn on conditional access, enforce MFA, enrol devices in Intune and put Defender on every endpoint. Configuration is the work. The licence usually already contains the products.

What to do next

If you want this applied to your Microsoft 365 tenancy, send us a note. We'll look at the licences you already hold and the controls that still need turning on. Monthly plans start from £495, with AI + Managed IT from £1,250 if you want the work bundled with ongoing support.

Twice a month, nothing more

What we automated recently, what it saved, and what didn’t work.

Unsubscribe in one click, any time.

Working on cybersecurity?

Tell us what's slowing your team down and we'll set out what we'd automate first.

No commitment. No sales pressure. Just honest advice.