Guide · rw/zero-trust

Zero-trust security for regulated industries.

The old model was simple: trust everything inside the office, distrust everything outside. That model is gone. In a world of SaaS, cloud workloads and remote teams, identity and context are the only perimeter that still matters.

IdentityMFADevice trustLeast privilegeMicro-segmentationSIEMSOARDLPNIS2DORA
80%
Of breaches involve compromised credentials
< 1 hr
Target mean time to contain lateral movement
100%
Of access should be authenticated and authorised
Zero
Implicit trust by default
01

Identify

Catalogue users, devices, data classes and the applications that handle regulated information.

02

Segment

Divide the estate into small zones so a breach in one place cannot walk across the network.

03

Enforce

Apply identity, device health and context checks to every access request, every time.

04

Observe

Collect signals, detect anomalies and respond automatically before damage spreads.

Why the perimeter died

Firewalls still matter, but they are no longer the control point. Data lives in Salesforce, Teams, AWS and a hundred SaaS tools. People work from home, airports and partner offices. A device can be inside the corporate network and fully compromised at the same time.

Zero trust does not mean zero access. It means every access request is verified: who is the user, is the device healthy, what are they trying to reach, and is the behaviour normal. Trust is earned continuously, not granted once at the front door.

Identity is the new perimeter

The strongest zero-trust programs start with identity. Single sign-on is only the beginning. Modern access needs multi-factor authentication, phishing-resistant credentials such as FIDO2 keys, risk-based step-up, and lifecycle management that removes access the moment someone changes role or leaves.

For regulated industries, identity must also produce an audit trail. Regulators want to know who accessed what, from where, and whether the access was appropriate. We design identity architectures that answer those questions by default.

Device trust, not just device management

A managed laptop is not the same as a trusted laptop. Device trust checks posture at the moment of access: patch level, encryption, endpoint protection, jailbreak status and known vulnerabilities. If the device fails the check, access is blocked or limited, regardless of who is asking.

We integrate Microsoft Intune, CrowdStrike, SentinelOne and equivalent platforms into conditional access policies so the network does not have to be the enforcement point.

Micro-segmentation and least privilege

Once identity is verified, the next question is what the user or workload is allowed to do. Least privilege means giving the minimum access needed for the role and nothing more. Micro-segmentation applies the same idea to the network: workloads can only talk to the specific peers they need, and default deny is the rule.

In practice this means software-defined perimeters, private connectivity into cloud workloads, and east-west traffic inspection. The goal is to make lateral movement so difficult that an attacker who compromises one account still cannot reach the crown jewels.

Platforms and partners we work with
Identity and access
Microsoft Entra IDOktaPing IdentityCyberArkSailPoint
Endpoint and device trust
CrowdStrikeSentinelOneMicrosoft IntuneVMware Workspace ONEJamf
Network and cloud security
zScalerCloudflarePalo Alto PrismaCisco Secure AccessNetskope
Detection and response
Microsoft SentinelSplunkCrowdStrike FalconElasticIBM QRadar

Data protection and DLP

Regulated data does not stop moving because you wrote a policy. Data loss prevention tools classify, label and monitor sensitive information across endpoints, cloud apps, email and removable media. We design DLP programs that protect without making daily work impossible.

Encryption, tokenisation and strict access logging complete the picture. For financial services and healthcare, we also align controls with DORA, NIS2, GDPR and sector-specific frameworks so security and compliance reinforce each other.

Zero-trust maturity matrix

Basic: SSO and MFA for critical apps
Developing: device trust and conditional access
Advanced: micro-segmentation and least-privilege workloads
Optimised: continuous validation and automated response

Regulatory alignment

Regulators are moving from tick-box compliance to evidence-based resilience. DORA asks financial firms to prove they can withstand ICT disruption. NIS2 expands security obligations across critical sectors. GDPR and sector laws require demonstrable controls and breach notification.

A well-run zero-trust program produces the telemetry, audit trails and incident response capability these regulations expect. Security becomes compliance by design, not a separate workstream.

  • Unified identity directory with lifecycle management
  • Phishing-resistant MFA for privileged and regulated access
  • Device posture checks integrated into conditional access
  • Micro-segmentation with default-deny policies
  • Data classification and DLP across endpoints and cloud
  • Centralised logging and SIEM with automated alerting
  • Incident response runbook tested at least twice a year
  • Quarterly access reviews and privilege recertification
Weeks 1-4

Discovery and risk map

Identify crown jewels, critical flows, shadow SaaS and the gaps that matter most to the regulator.

Weeks 5-12

Identity foundation

Consolidate directories, enforce MFA, deploy conditional access and start device trust integration.

Months 4-6

Network and data controls

Segment workloads, deploy DLP, classify regulated data and enforce least privilege.

Months 7-9

Detection and response

Centralise logs, build detection rules, automate response playbooks and run tabletop exercises.

Ongoing

Optimise and validate

Continuous access review, red-team testing, control tuning and regulatory evidence packs.

Zero trust is not a product you buy. It is a way of deciding what to trust, when, and for how long. The organisations that get this right treat every access request as a security decision.
Redwind security practice
Key takeaways
  1. 01Trust nothing by default. Verify identity, device and context every time.
  2. 02Start with identity and device trust before buying more network boxes.
  3. 03Segment workloads so a single breach cannot move laterally.
  4. 04Align zero trust with DORA, NIS2 and GDPR to make compliance a by-product.
  5. 05Budget for continuous validation: zero trust is a program, not a project.
Frequently asked
Does zero trust slow people down?

Done well, it makes access smoother. Single sign-on, risk-based step-up and trusted-device policies reduce password prompts and help-desk tickets while raising the security bar.

Can zero trust work with legacy systems?

Yes, but legacy often needs a wrapper: a privileged access gateway, jump hosts or application proxy. The goal is to apply zero-trust controls at the access layer even when the legacy application cannot change.

How long does a zero-trust program take?

The first controls can be live in weeks. A full enterprise program typically takes twelve to eighteen months, with continuous improvement after that.

Is zero trust only for large enterprises?

No. Mid-sized regulated firms often benefit most because they have valuable data and limited security staff. A focused zero-trust program gives them enterprise-grade protection without enterprise-scale overhead.

Redwind's operating principle

Security architecture should fit the business, not fight it. We design zero-trust programs that protect regulated data while keeping teams productive, and we prove the controls with evidence regulators and auditors can read.

See our enterprise infrastructure work · Start a project