Zero Trust
No implicit trust from network position; authorise every request.
6 to work through
-
advanced
A board mandate says "implement zero trust in twelve months". What do you actually do, in what order?
2 min answer -
advanced
A digital bank adopts zero trust. What actually changes in the architecture, and what is commonly mistaken for zero trust?
2 min answer -
advanced
A platform replaces network-level trust with per-request authorisation - every call to every internal service is checked against a central policy service. Security is satisfied. What has the platform given up, and when does that bill arrive?
3 min answer -
advanced
An organisation decides to adopt zero trust. What does it actually mean architecturally, what is the realistic implementation order, and where does it fail?
3 min answer -
advanced
An organisation replaces its VPN with an identity-aware access model. What actually has to change beyond the network, and where do these programmes stall?
2 min answer -
advanced
How would you assess your estate's exposure to lateral movement, in a way that produces actionable findings?
2 min answer
3 terms in this topic
Lateral Movement
An attacker's progression from an initial foothold to more valuable systems, which is what turns a minor compromise into a breach.
patternMicrosegmentation
Enforcing fine-grained network policy between individual workloads rather than between broad network zones, so a compromise cannot move laterally.
patternPolicy Decision Point
The component that evaluates an authorisation question and returns a decision, kept separate from the enforcement points that ask, so policy can chan…
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.