Zero trust in practice: lessons from regulated industries
For decades, enterprise security was built on a simple assumption: the network perimeter defined the trust boundary. Everything inside the firewall was trusted. Everything outside was not. VPNs extended the perimeter to remote workers. Firewalls filtered traffic at the edge. And once you were inside, you could move laterally with relatively few constraints.
That model is broken. Cloud adoption dissolved the perimeter. Remote work distributed endpoints across home networks, coffee shops, and airports. SaaS applications moved critical data outside the corporate network entirely. And adversaries -- from state-sponsored groups to ransomware operators -- have demonstrated repeatedly that perimeter breach is not a matter of if but when. Once inside, lateral movement is trivially easy in a perimeter-trust architecture.
Zero trust is the response: a security model where no user, device, or network location is inherently trusted. Every access request is verified, every session is authenticated, and every action is authorized based on context -- regardless of whether the request originates from inside or outside the network.
Identity as the New Perimeter
In a zero trust architecture, identity replaces the network as the primary security control plane. The fundamental question shifts from "is this request coming from inside the network?" to "who is making this request, from what device, in what context, and are they authorized for this specific action?"
Identity-first security requires several foundational capabilities:
- Strong authentication -- multi-factor authentication (MFA) as a baseline, with phishing-resistant methods (FIDO2, hardware tokens) for high-privilege access
- Continuous authentication -- session validation that does not end at login, with re-authentication triggered by context changes (new device, unusual location, sensitive action)
- Identity governance -- automated provisioning and deprovisioning tied to authoritative HR and organizational systems, eliminating orphaned accounts and excessive privileges
- Privileged access management (PAM) -- just-in-time elevation of privileges for administrative actions, with full session recording and time-limited access
In regulated industries, identity-first security is not optional. Banking regulators, healthcare compliance frameworks (HIPAA), and data protection regulations (GDPR) all mandate strong identity controls. The zero trust model aligns naturally with these requirements because it makes identity verification the precondition for every action, not just initial login.
Micro-Segmentation: Containing the Blast Radius
If identity is the first control, micro-segmentation is the second. Traditional network segmentation divides the network into broad zones -- production, development, DMZ. Micro-segmentation takes this to its logical extreme: every workload, every service, and every data store has its own security boundary.
In practice, micro-segmentation means:
- Workload-level policies -- each application or service has explicit rules defining which other services it can communicate with, on which ports, using which protocols
- East-west traffic control -- lateral movement between services is denied by default and permitted only through explicit policy, eliminating the "flat network" problem that enables attackers to move freely after initial breach
- Dynamic policy enforcement -- segmentation policies adapt based on workload identity and context, not just static IP addresses that change with every deployment
Implementation in Regulated Environments
Banks and healthcare organizations have found that micro-segmentation directly addresses regulatory requirements around data isolation. Patient health records can be segmented from billing systems. Trading systems can be isolated from research systems. Each segment has its own access policies, monitoring, and audit trail.
The implementation challenge is operational: defining and maintaining segmentation policies across thousands of workloads requires automation. Manual policy management does not scale. Organizations that succeed invest in policy-as-code -- defining segmentation rules in version-controlled configuration that is tested, reviewed, and deployed through the same CI/CD pipelines as application code.
Continuous Verification
Traditional security verification is point-in-time: authenticate at login, authorize at resource access, audit periodically. Zero trust replaces point-in-time verification with continuous verification -- constant evaluation of trust signals throughout a session.
Continuous verification evaluates multiple signals simultaneously:
- Device posture -- is the device managed? Is the OS patched? Is disk encryption enabled? Is endpoint detection running?
- Behavioral analytics -- is this user behaving consistently with their historical patterns? Unusual access times, volumes, or resource types trigger additional verification.
- Network context -- is the request originating from a known location? Is the network connection secure?
- Risk scoring -- a composite score combining all available signals, updated in real time, that determines the level of access permitted
When the risk score changes -- a device falls out of compliance, a user accesses a resource they have never accessed before, a session originates from a new geography -- the system responds dynamically. This might mean requiring step-up authentication, restricting access to read-only, or terminating the session entirely.
Compliance Alignment
Continuous verification directly supports regulatory requirements that many organizations struggle with under traditional security models:
- SOX compliance -- continuous monitoring of access to financial systems, with automated evidence of who accessed what, when, and from where
- HIPAA -- real-time enforcement of minimum necessary access to protected health information
- PCI DSS -- continuous validation that only authorized personnel access cardholder data environments
- GDPR -- demonstrable, auditable access controls on personal data, with evidence of ongoing enforcement
The key insight is that zero trust does not add compliance burden -- it automates it. The continuous verification signals that drive security decisions are the same signals that regulators want to see in audit evidence.
Lessons from the Field
Organizations in regulated industries that have implemented zero trust architectures share several hard-won lessons.
Start with Identity, Not Network
The temptation is to begin with network micro-segmentation because it feels like the most visible security improvement. In practice, identity is the more impactful starting point. Strong identity controls reduce risk immediately, do not require application changes, and establish the foundation that micro-segmentation builds upon.
Treat Legacy Systems as First-Class Citizens
Every organization has systems that cannot natively participate in a zero trust architecture -- legacy mainframes, proprietary applications, embedded systems. Rather than excluding these from the zero trust model, successful organizations wrap them in proxy layers that enforce zero trust controls at the boundary. The legacy system does not change; the access path to it does.
Invest in Automation Early
Zero trust generates an enormous volume of security signals. Without automation, security teams are overwhelmed by alerts they cannot investigate and policies they cannot maintain. Invest in automated policy enforcement, automated response to common risk patterns, and automated evidence collection for compliance. Human attention should be reserved for novel threats and strategic decisions.
Communicate the Business Case
Regulated industries often frame zero trust as a compliance initiative. This is a mistake. Zero trust reduces breach impact, accelerates incident response, simplifies audit preparation, and enables secure adoption of cloud and remote work. The compliance alignment is a benefit, not the justification. Framing it as a business enabler rather than a compliance cost changes organizational engagement entirely.
The Path Forward
Zero trust is not a product to buy or a project to complete. It is an architectural philosophy that evolves continuously with the threat landscape, the technology environment, and the regulatory requirements. The organizations that succeed treat it as a journey -- starting with identity, expanding to segmentation, layering in continuous verification, and automating relentlessly.
For regulated industries, the alignment between zero trust principles and compliance requirements makes this an unusually well-justified investment. The security benefits are real. The compliance benefits are substantial. And the alternative -- maintaining a perimeter-based model in a perimeter-less world -- is no longer defensible.
Related articles
Your challenge could be
our next success story.
Tell us what you're solving for, and we'll show you how we'd approach it — no pitch deck, just engineering.
