The challenge
A national organisation needed stronger assurance across distributed sites without halting operations. Legacy perimeter thinking no longer matched how staff worked: remote access, contractor access, and business-managed devices increased the attack surface.
What we did
We aligned leadership on a pragmatic definition of zero trust: continuous verification of identity, device health, and least-privilege access, implemented in phases that could be measured each month.
1. Identity and access segmentation
We modernised conditional access policies for cloud workloads, reduced standing privileges for administrators, and introduced time-bound elevation for break-glass scenarios.
2. Endpoint baselines and patch discipline
We defined a minimum security baseline for corporate devices, prioritised critical vulnerability remediation windows, and introduced reporting that made gaps visible to owners - not buried in tickets.
3. Telemetry and governance
We connected key signals (sign-in risk, device compliance, privileged activity) into monthly governance forums. Decisions were recorded as explicit risk acceptance where required, which reduced “silent drift”.
Outcomes
- Fewer uncontrolled admin pathways into core business systems
- Stronger confidence in device compliance reporting before major change windows
- Clearer prioritisation of remediation work based on business criticality
Lessons learnt
Zero trust is not a product purchase - it is an operational rhythm. The organisation succeeded because security, IT operations, and business stakeholders shared the same scoreboard and iterated monthly.
Pre-travel hardening, secure communications, and rapid response for executives travelling across APAC.
Practical readiness: playbooks, drills, and leadership cadence for credible response.